Adversary Intelligence — 2026-05-03

Chinese Firm Antiy Accuses SentinelOne of Psychological Warfare Over Fast16 Malware Report

SentinelOne researchers Vitaly Kamluk and Juan Andres Guerrero-Saade presented Fast16 at Black Hat Asia in April as a kernel-mode driver, timestamped July 2005, that silently corrupts floating-point arithmetic in LS-DYNA, PKPM, and MOHID, simulation packages tied to Iran's nuclear and civil engineering programs. The malware spreads via a companion worm built for air-gapped networks with no command-and-control infrastructure. Chinese firm Antiy Labs published a rebuttal on April 27, characterizing the report as "psychological warfare" and contesting the five-years-before-Stuxnet timeline by arguing Stuxnet operations began as early as 2007. Participants in the Security Conversations podcast on May 1, including Guerrero-Saade and WIRED's Andy Greenberg, reported that attribution to NSA, Israel, or another actor remains unresolved.

Analysis
Antiy's three-day turnaround on SentinelOne's Black Hat Asia presentation signals institutional coordination rather than organic commentary. The 'psychological warfare' framing redirects scrutiny from Fast16's technical specifics to geopolitical intent, a posture unfalsifiable on forensic terms. Antiy's counter-timeline claim implies operational familiarity with Stuxnet beyond what open sources support. Across two primary sources and a lead-researcher podcast, with no independent technical validation, actor attribution remains open. The rebuttal may instead reflect genuine technical disagreement within China's research community, but the structural pattern of PRC-linked firms matching Western attribution publications makes at least one comparable counter-attribution very likely within the next 60 days.
2 sources
  1. A Psychological Warfare to Show Off Cyber Capabilities - Antiy
  2. Three Buddy Problem: Cracking the Fast16 sabotage malware mystery - Security Conversations (Three Buddy Problem)

View in full brief →

UNCLASSIFIED // OPEN SOURCE