logo

Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software

ID: 4bdf2ded-4d6e-5c24-8c71-42b043dcc7c8

STIX ID: report--4bdf2ded-4d6e-5c24-8c71-42b043dcc7c8

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-04-25

Date Updated: 2026-04-25

Author: [email protected] (The Hacker News)

...
...

SentinelOne researchers discovered fast16, a previously undocumented Lua‑powered Windows sabotage framework dating to 2005 that predates Stuxnet. fast16 comprises a flexible carrier (svcmgmt.exe), an auxiliary ConnotifyDLL (svcmgmt.dll), and a kernel driver (fast16.sys) that intercepts and patches executables—targeting high‑precision engineering and simulation software (e.g., LS‑DYNA, PKPM, MOHID) to introduce subtle calculation errors. The tool includes propagation logic for legacy Windows (2000/XP), environment checks for security products, and forensic links to a 2017 leak of Equation Group artifacts, suggesting a state‑level, long‑running capability for covert cyber‑physical sabotage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.