Pre-Stuxnet Fast16 Malware Was Built to Sabotage Nuclear Weapons Simulations

New analysis by Symantec and Carbon Black confirms Fast16 was engineered to corrupt uranium-compression simulations inside LS-DYNA and AUTODYN, making it the earliest known nuclear sabotage malware predating Stuxnet by two years.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region3 min read
Engineering workstation displaying nuclear compression simulation software targeted by Fast16 malware

Engineering workstation displaying nuclear compression simulation software targeted by Fast16 malware

A new technical analysis has confirmed that Fast16, a Lua-based malware framework, was deliberately engineered to sabotage nuclear weapons testing simulations, making it one of the most sophisticated cyber sabotage tools ever identified and a precursor to the better-known Stuxnet.

The findings, published by Symantec and Carbon Black, both operating under Broadcom, establish that Fast16 was designed to corrupt uranium-compression simulations that are central to nuclear weapon design. The malware specifically targeted two widely used engineering applications: LS-DYNA and AUTODYN, both of which are used to model real-world physical processes including material behaviour and explosive detonation.

According to Symantec's Threat Hunter Team, the malware's hook engine was programmed to activate only when the density of a simulated material exceeded 30 grams per cubic centimetre, a threshold only reachable under the shock-compression conditions of an implosion device. This level of domain specificity indicates that the malware was written by individuals with a deep understanding of nuclear physics and simulation engineering.

Fast16 contains 101 hook rules that can be grouped into nine or ten categories, each targeting a different build of LS-DYNA or AUTODYN. The consistent addition of rules for updated software versions points to a sustained and methodical operation rather than a one-off attack.

The malware was also built to spread automatically across endpoints on the same network, ensuring that any machine used to run simulations would produce the same corrupted outputs. It also checks for the presence of certain security products before executing, avoiding detection by avoiding installation on protected systems.

Earlier research by SentinelOne placed Fast16's development as early as 2005, predating the earliest confirmed version of Stuxnet by two years. Evidence pointing to Fast16's origins came from a text file included in a large cache of hacking tools and exploits leaked by the anonymous group known as The Shadow Brokers in 2017. That tranche was reportedly linked to the Equation Group, a state-sponsored threat actor with suspected ties to the United States National Security Agency.

Vikram Thakur, Technical Director at Symantec, described the level of expertise required to build such a tool in 2005 as extraordinary, noting that the malware's authors had to understand which equations of state were relevant, which compiler calling conventions applied, and which simulation types would or would not trigger the payload.

The analysis draws a clear conceptual line between Fast16 and Stuxnet, the malware that was later used to physically damage uranium-enrichment centrifuges at Iran's Natanz nuclear facility by injecting malicious code into Siemens programmable logic controllers. Both tools were tailored not just to a vendor's product but to a specific physical process being simulated or controlled by that product.

For organisations across the GCC and MENA region operating in energy, defence, or industrial sectors, the Fast16 revelations carry direct relevance. The region's growing investment in critical infrastructure, including nuclear energy programmes in the UAE and Saudi Arabia, makes the lessons of pre-Stuxnet sabotage frameworks critically important for operational technology security teams.

Security professionals working in industrial control systems and simulation environments should treat this research as a reminder that nation-state actors have long been capable of embedding subtle, physics-aware sabotage into engineering software, and that the threat model for such environments extends well beyond conventional intrusion detection.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

ICS and OT SecurityNation-State Threat IntelligenceCritical Infrastructure ProtectionIndustrial Malware AnalysisMENA Cyber ThreatsGulf CybersecurityCyber Sabotage CampaignsNuclear Sector Security