A piece of malicious code disclosed in a 2017 NSA leak appears to predate Stuxnet by years and may have been used to sabotage Iranian engineering work, SentinelOne researchers say. The company reverse‑engineered Fast16 and dated it to about 2005 — a tool that can spread across networks and subtly alter high‑precision simulation outputs so designs or tests produce flawed outcomes.

What Fast16 is and how it works

SentinelOne researchers Vitaly Kamluk and Juan Andrés Guerrero-Saade published a detailed reverse-engineering of Fast16, a piece of malicious code first disclosed in an NSA leak in 2017. Their analysis, unveiled ahead of a Black Hat Asia presentation, dates the malware to roughly 2005 and finds it was built for a specific form of sabotage.

Rather than wiping data or locking systems, Fast16 moves through networks and quietly changes numeric outputs inside programs that run high-precision mathematical models. Those programs are used for tasks ranging from modelling water flows to testing structural strength. By nudging calculations by tiny amounts, the malware can create conditions that make equipment wear out faster or fail in ways that look like engineering mistakes.

"It focuses on making slight alterations to these calculations so that they lead to failures—very subtle ones, perhaps not immediately apparent," Kamluk said in an interview summarised in the researchers' write-up. "Systems might wear out faster, collapse, or crash, and scientific research could yield incorrect conclusions, potentially causing serious harm."

Targets: MOHID, PKPM and LS-DYNA

In their analysis, the researchers identified three types of simulation packages Fast16 seemed capable of altering:

  • MOHID — a hydrodynamic modelling tool used for water systems.
  • PKPM — a Chinese construction-engineering suite.
  • LS-DYNA — a widely used physical-simulation program originally developed by scientists who worked at Lawrence Livermore National Laboratory.

Kamluk and Guerrero-Saade found traces suggesting Fast16 could detect when those applications were running and then modify specific calculations to change the simulated output. That differs from Stuxnet, which directly targeted programmable logic controllers to physically damage centrifuges; Fast16 appears engineered to corrupt the design and testing pipeline so flaws are built in long before systems are manufactured or operated.

Why this matters now

Fast16 rewrites part of the timeline for cyber-sabotage. Stuxnet, first identified in 2010 and later publicly tied to a US-Israeli programme against Iran, was widely seen as the opening of a new era in offensive cyber operations against industrial targets. SentinelOne's analysis suggests similarly sophisticated techniques were under development, or possibly in use, years earlier.

If adversaries can hide tiny errors in the software tools engineers use, downstream effects can be extensive and hard to detect: research projects can publish misleading results, manufacturers can produce components that fail in the field, and safety margins can quietly erode.

Political and diplomatic implications

Kamluk and Guerrero-Saade say the provenance of Fast16 points to a creator with access to detailed knowledge about the targeted simulation tools and their users. Their public notes state the malware was "likely created by either the US government or one of its allies."

Related Articles

Kamluk and Guerrero-Saade date Fast16 to about 2005; they plan to present their full technical findings at Black Hat Asia in Singapore.

This article was created with AI assistance.