SINGAPORE — Researchers from the cybersecurity firm SentinelOne disclosed in Singapore that they had reverse-engineered a 21-year-old piece of malware known as Fast16, a self-spreading program capable of covertly tampering with scientific and engineering software to subtly alter their outputs. Vitaly Kamluk and Juan Andrés Guerrero-Saade said the 2005-era code can manipulate computations inside applications used for high-precision mathematics and physical simulation, producing failures that range from flawed research results to equipment damage.

The existence of Fast16 was first revealed in April 2017 in a leak of National Security Agency materials, and the malware has been described as likely created by the U.S. government or one of its allies. Fast16 automatically spreads across networks, using what the researchers described as "wormlet" functionality to copy itself to other computers through Windows network shares.

"It focuses on making slight alterations to these calculations so that they lead to failures—very subtle ones, perhaps not immediately apparent. Systems might wear out faster, collapse, or crash, and scientific research could yield incorrect conclusions, potentially causing serious harm." Kamluk said.

Kamluk and Guerrero-Saade identified three applications as potential targets: Modelo Hidrodinâmico, a water-systems modeling program built by Portuguese developers; the Chinese construction engineering suite PKPM; and LS-DYNA, a physical simulation tool. Iranian scientists used LS-DYNA in research that may have contributed to Iran's nuclear weapons program, according to the Institute for Science and International Security, which also reported that the software can model the interactions of metals in a nuclear weapon and the impact of a ballistic missile's atmospheric reentry on a warhead.

In 2019, Guerrero-Saade found a sample of Fast16 in the archives of VirusTotal, a Google-owned malware repository, while searching for files containing a Lua programming language engine. He identified an application called svcmgmt.exe that carried a kernel driver named Fast16.sys, which appeared to have been compiled in 2005.

Three months before SentinelOne's presentation, Kamluk began reverse-engineering the code to compare his work against AI tools, five of which incorrectly classified the sample as a rootkit. Two weeks before the presentation, he concluded that Fast16 was not a rootkit.

"It's not beyond the pale that what we're looking at is an early predecessor to Olympic Games. It fits the bill, right? We want to be good, objective researchers, but this is really not a stretch." Guerrero-Saade said, referring to the covert program under which Stuxnet was deployed.

Thomas Rid, director of the Alperovitch Institute for Cybersecurity Studies at Johns Hopkins University, said the analysis rewrites the history of state-sponsored hacking. "It means that deceptive sabotage operations have been part of the cyber playbook from much earlier than we thought, perhaps even from the beginning. And it also looks like they were much stealthier than we understood." Rid said.