Fast16
Malware
From Wikipedia, the free encyclopedia
Fast16 is a cyber sabotage framework and malware platform. Core components of the framework date back to approximately 2005, making it one of the earliest known examples of precision industrial sabotage, predating the public discovery of the Stuxnet worm by five years. The malware was identified by researchers from SentinelOne, who linked it to the signatures found in the 2017 Shadow Brokers leak of tools allegedly belonging to the National Security Agency.[1][2][3][4]
- By Microsoft
- Trojan:WinNT/FastSixteen.A!dha
- By Sophos
- Mal/Generic-S
- By Kaspersky
- Trojan.Win32.Fast16.a
- By Trend Micro
- Mal_Strat-3
| Fast16 | |
|---|---|
| Malware details | |
| Technical name | As Fast16
|
| Type | Rootkit |
| Classification | Computer worm |
| Origin | United States |
| Author | Equation Group[1] |
| Cyberattack event | |
| Target |
|
| Technical details | |
| Size | ~43kB (fast16.sys), ~308 KB (svcmgmt.exe) |
| Written in | Lua, C, C++ |
The framework is characterized by its use of an embedded Lua virtual machine for modularity and a kernel-mode filesystem driver designed for "adversary-in-the-simulation" attacks. Unlike traditional malware designed for data exfiltration or system destruction, Fast16 targets high-precision engineering and simulation software, specifically suites such as LS-DYNA, AUTODYN, PKPM, and MOHID. It utilizes a rule-based engine to intercept executable files in memory and subtly patch floating-point arithmetic routines. These systematic manipulations are intended to produce inaccurate mathematical results in physical modeling, which could lead to inexplicable engineering failures or the sabotage of sensitive research, such as nuclear weapons simulations.[5]