Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software
ID: 4bdf2ded-4d6e-5c24-8c71-42b043dcc7c8
STIX ID: report--4bdf2ded-4d6e-5c24-8c71-42b043dcc7c8
Feed Name: The Hacker News
SentinelOne researchers discovered fast16, a previously undocumented Lua‑powered Windows sabotage framework dating to 2005 that predates Stuxnet. fast16 comprises a flexible carrier (svcmgmt.exe), an auxiliary ConnotifyDLL (svcmgmt.dll), and a kernel driver (fast16.sys) that intercepts and patches executables—targeting high‑precision engineering and simulation software (e.g., LS‑DYNA, PKPM, MOHID) to introduce subtle calculation errors. The tool includes propagation logic for legacy Windows (2000/XP), environment checks for security products, and forensic links to a 2017 leak of Equation Group artifacts, suggesting a state‑level, long‑running capability for covert cyber‑physical sabotage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
