• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
pre stuxnet fast16 malware tampered with nuclear weapons simulations

Pre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations

You are here: Home / General Cyber Security News / Pre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations
May 18, 2026

A new analysis of the Lua-based fast16 malware has confirmed that it was a cyber sabotage tool designed to tamper with nuclear weapons testing simulations.

According to Broadcom-owned Symantec and Carbon Black teams, the pre-Stuxnet tool was engineered to corrupt uranium-compression simulations that are central to nuclear weapon design.

“Fast16’s hook engine is selectively interested in high-explosive simulations inside LS-DYNA and AUTODYN,” the Threat Hunter Team said. “The malware checks for the density of the material being simulated and only acts when that value passes 30 g/cm³, the threshold uranium can only be reached under the shock compression of an implosion device.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


The development comes weeks after SentinelOne presented an analysis of fast16, describing it as the first sabotage framework whose components may have developed as early as 2005, predating the earliest known version of Stuxnet (aka Stuxnet 0.5) by two years.

Evidence unearthed by the cybersecurity company included a reference to the string “fast16” in a text file that was leaked by an anonymous hacking group called The Shadow Brokers in 2017. The file was part of a huge tranche of hacking tools and exploits allegedly used by the Equation Group, a state-sponsored threat actor with suspected ties to the U.S. National Security Agency (NSA).

Cybersecurity

At its core, the industrial sabotage malware features a set of 101 rules to tamper with mathematical calculations carried out by certain engineering and simulation programs that were prevalent at the time. Although the exact binaries that are patched by the malware is unclear, SentinelOne identified three probable candidates: LS-DYNA version 970, Practical Structural Design and Construction Software (PKPM), and Modelo Hidrodinâmico (MOHID).

Symantec’s latest analysis has now confirmed that LS-DYNA and AUTODYN are the two applications targeted by fast16, adding it was designed explicitly to interfere with simulations of high-explosive detonations, almost certainly to facilitate sabotage against nuclear weapons research.

“Both are software applications used to simulate real-world problems such as vehicle crashworthiness, material modelling, and explosive simulation,” Symantec and Carbon Black said. “The hooks fast16 places inside of the simulation program consist of three attack strategies. The tampering only activates during full-scale transient blast and detonation runs.”

The 101 hook rules can be categorized further into 9-10 hook groups, each targeting different builds of LS-DYNA or AUTODYN, suggesting that the developers of the malware were keeping track of software updates and adding support for different versions over time. This points to a methodical and sustained operation.

“If hook rule groups were added sequentially as needed, we see a hook group added for a previous version of the software after a newer version,” researchers explained.

“One may imagine, the simulation user reverted to an older version when faced with the anomaly, before that version was also targeted. Secondly, the hook groups represent up to 10 different versions of simulation software, meaning the simulation user updates versions semi-frequently. 

Fast16 is crafted such that it will not infect computers that have certain security products installed. It also automatically spreads to other endpoints on the same network, so that any machine that’s used to run the simulations will generate the same tampered outputs.

Cybersecurity

The findings indicate that strategic industrial sabotage using malware was being conducted by nation-state actors as far back as 20 years ago, well before Stuxnet was used to damage uranium enrichment centrifuges at Iran’s nuclear plant in Natanz by injecting malicious code into Siemens programmable logic controllers.

Speaking to cybersecurity journalist Kim Zetter, Vikram Thakur, technical director for Symantec, said the level of expertise of understanding required to design such a malware in 2005 is “mind-blowing.” That said, it’s not known if a modern-day version of fast16 exists in the wild.

“That degree of domain knowledge, such as understanding which EOS forms matter, which calling conventions are produced by which compilers, and which classes of simulation will or will not trip the gate, is unusual in any era and was very unusual in 2005,” Symantec and Carbon Black said.

“The framework belongs to the same conceptual lineage as Stuxnet, in which malware was tailored not just to a vendor’s product but to a specific physical process being simulated or controlled by that product.”

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «miniplasma windows 0 day enables system privilege escalation on fully patched MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Pre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations
  • MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems
  • NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
  • Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt
  • Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming
  • Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access
  • Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence
  • What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface
  • TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates
  • On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email

Copyright © TheCyberSecurity.News, All Rights Reserved.