Relevance: supporting · Type: background
Confidence90%
Stuxnet is a piece of malware that US and Israeli operators first deployed in Iran in 2007 to accelerate the spinning of nuclear enrichment centrifuges until they destroyed themselves.
Relevance: primary · Type: event
Confidence90%
Researchers discovered a 21-year-old malware specimen capable of tampering with research and engineering software to undetectably alter their operations.
Relevance: supporting · Type: background
Confidence70%
The newly discovered malware may have been used in Iran before Stuxnet.
Relevance: supporting · Type: background
Confidence90%
Vitaly Kamluk is a researcher from the cybersecurity firm SentinelOne.
Relevance: supporting · Type: background
Confidence90%
Juan Andrés Guerrero-Saade is a researcher from the cybersecurity firm SentinelOne.
Relevance: primary · Type: event
Confidence90%
Kamluk and Guerrero-Saade revealed a breakthrough in deciphering the purpose of Fast16 malware.
Relevance: supporting · Type: background
Confidence90%
The existence of Fast16 malware was first revealed in an NSA leak in 2017.
Relevance: primary · Type: event
Confidence90%
SentinelOne researchers reverse-engineered the Fast16 code.
Relevance: primary · Type: background
Confidence90%
Fast16 dates back to 2005.
Relevance: primary · Type: background
Confidence90%
Fast16 was likely created by either the US government or one of its allies.
Relevance: primary · Type: background
Confidence90%
Fast16 malware automatically spreads across networks.
Relevance: primary · Type: background
Confidence90%
Fast16 malware silently manipulates computation processes in software applications that perform high-precision mathematical calculations and simulate physical phenomena.
Relevance: primary · Type: background
Confidence90%
Fast16 malware can alter program results to cause failures ranging from faulty research results to equipment damage.
Vitaly Kamluk, SentinelOne researcher
Relevance: primary · Type: quote
Confidence100%
"It focuses on making slight alterations to these calculations so that they lead to failures—very subtle ones, perhaps not immediately apparent. Systems might wear out faster, collapse, or crash, and scientific research could yield incorrect conclusions, potentially causing serious harm."
Relevance: supporting · Type: background
Confidence90%
Kamluk and Guerrero-Saade identified Modelo Hidrodinâmico (MOHID) software as a potential target of Fast16 malware.
Relevance: supporting · Type: background
Confidence90%
MOHID software was created by Portuguese developers for modeling water systems.
Relevance: supporting · Type: background
Confidence90%
Kamluk and Guerrero-Saade identified Chinese construction engineering software PKPM as a potential target of Fast16.
Relevance: supporting · Type: background
Confidence90%
Kamluk and Guerrero-Saade identified LS-DYNA physical simulation software as a potential target of Fast16.
Relevance: supporting · Type: background
Confidence90%
LS-DYNA was originally created by scientists who had worked at the US Lawrence Livermore National Laboratory.
Relevance: supporting · Type: background
Confidence90%
LS-DYNA is used in modeling collisions between birds and airplanes and the tensile strength of crane components.
Relevance: supporting · Type: background
Confidence90%
Iranian scientists used LS-DYNA in research that may have contributed to Iran’s nuclear weapons program.
Relevance: supporting · Type: background
Confidence90%
LS-DYNA can model interactions of metals in a nuclear weapon.
Relevance: supporting · Type: background
Confidence90%
LS-DYNA can model the impact of a ballistic missile's reentry into Earth's atmosphere on a nuclear warhead.
Relevance: supporting · Type: background
Confidence70%
Fast16 might have been used in the mid-2000s to subvert Iran’s attempt to develop nuclear weapons.
Relevance: supporting · Type: background
Confidence90%
The Olympic Games program was carried out jointly by the NSA and Israel’s Unit 8200 hackers.
Relevance: supporting · Type: background
Confidence90%
Stuxnet was deployed as part of the Olympic Games program.
Juan Andrés Guerrero-Saade, SentinelOne researcher
Relevance: supporting · Type: quote
Confidence100%
"It's not beyond the pale that what we're looking at is an early predecessor to Olympic Games. It fits the bill, right? We want to be good, objective researchers, but this is really not a stretch."
Relevance: supporting · Type: background
Confidence90%
Thomas Rid is the director of the Alperovitch Institute for Cybersecurity Studies at Johns Hopkins University.
Relevance: supporting · Type: background
Confidence90%
Thomas Rid said that the analysis of Fast16 rewrites the history of state-sponsored hacking.
Thomas Rid, director of the Alperovitch Institute for Cybersecurity Studies at Johns Hopkins University
Relevance: supporting · Type: quote
Confidence100%
"It means that deceptive sabotage operations have been part of the cyber playbook from much earlier than we thought, perhaps even from the beginning. And it also looks like they were much stealthier than we understood."
Relevance: supporting · Type: background
Confidence90%
The Shadow Brokers hacker group obtained and leaked a collection of NSA tools onto the open internet in April 2017.
Relevance: supporting · Type: background
Confidence90%
The existence of Fast16 first came to light in April 2017.
Relevance: supporting · Type: background
Confidence90%
The Territorial Dispute tool was designed to help NSA operators avoid conflicts with other hacking operations.
Relevance: supporting · Type: background
Confidence90%
Hungarian researcher Boldizsár Bencsáth first analyzed the Territorial Dispute tool in depth.
Relevance: supporting · Type: background
Confidence90%
The Territorial Dispute tool included instructions on when to 'pull back' to avoid detection by an adversary's intrusion operation.
Relevance: supporting · Type: background
Confidence90%
The Territorial Dispute tool contained a list of malware specimens used by the NSA and other allied agencies.
Relevance: supporting · Type: background
Confidence90%
Within the Territorial Dispute tool, a malware sample labeled 'fast16' was accompanied by the instruction 'NOTHING TO SEE HERE—CARRY ON.'
Relevance: supporting · Type: background
Confidence80%
Researchers have speculated that the instruction 'NOTHING TO SEE HERE—CARRY ON' implies that Fast16 was developed by the NSA, another US intelligence community entity, or an allied intelligence agency.
Relevance: supporting · Type: background
Confidence90%
The Shadow Brokers leak did not include any software file named Fast16.
Relevance: primary · Type: event
Confidence90%
In 2019, Juan Andrés Guerrero-Saade found a sample of Fast16 in the archives of VirusTotal.
Relevance: supporting · Type: background
Confidence90%
VirusTotal is a Google-owned repository of malware code.
Relevance: supporting · Type: event
Confidence90%
Guerrero-Saade searched for malware samples containing a Lua programming language engine in their code.
Relevance: supporting · Type: event
Confidence90%
Guerrero-Saade found an application called svcmgmt.exe that contained a Lua engine.
Relevance: supporting · Type: background
Confidence90%
The svcmgmt.exe application contained a kernel driver called Fast16.sys.
Relevance: supporting · Type: background
Confidence90%
Fast16.sys appeared to have been compiled in 2005.
Relevance: supporting · Type: background
Confidence90%
VirusTotal discourages users from trying to identify uploaders of malware samples.
Relevance: supporting · Type: background
Confidence90%
It took seven years after Guerrero-Saade's discovery for anyone to determine Fast16's functionality.
Relevance: supporting · Type: background
Confidence90%
Some cybersecurity researchers initially assumed Fast16.sys was a rootkit.
Relevance: primary · Type: event
Confidence90%
Three months before the article, Vitaly Kamluk decided to reverse-engineer Fast16 malware to compare his skills to AI tools.
Relevance: primary · Type: event
Confidence90%
Two weeks before the article, Kamluk discovered that Fast16 is not a rootkit.
Relevance: supporting · Type: background
Confidence90%
Five top AI tools incorrectly identified Fast16 as a rootkit.
Relevance: primary · Type: background
Confidence90%
Fast16 is a self-spreading piece of code.
Relevance: primary · Type: background
Confidence90%
Fast16 uses 'wormlet' functionality to copy itself to other computers via Windows network share.
forum Comments (0)
No comments yet. Be the first to comment.