
Researcher Uncovers 'Fast16,' a Pre-Stuxnet Cyber-Physical Attack Tool from the Mid-2000s
Cybersecurity researcher Vitaly Kamluk presented findings on 'Fast16,' a previously undocumented cyberattack tool discovered in a Windows executable file dating back to the mid-2000s. The malware, embedded with Lua bytecode and a kernel driver, targeted specific engineering and scientific software—including PKPM (civil engineering), Mohid Hydrodynamic (water modeling), and LS-DYNA (finite element analysis)—by subtly altering mathematical calculations to introduce hidden flaws in designs. Fast16 predates Stuxnet by five years and shares similarities in methodology, such as network propagation and precision sabotage, but focuses on corrupting computational results rather than physical infrastructure. The driver required a uniprocessor Windows XP system and early boot-stage execution, with static analysis revealing FPU instructions for floating-point manipulation and 101 embedded patterns to identify target applications. Kamluk’s team tested AI models (including Claude, Gemini, and DeepSeek) to evaluate their reverse-engineering capabilities, finding they could replicate technical analysis but failed to grasp the historical significance of Fast16. The research, published by SentinelOne, includes YARA signatures for further investigation and suggests Fast16 represents one of the earliest documented cyber-physical attack tools. Indicators like SCCS version control fingerprints and obsolete security software checks corroborated the file’s age.