Counterintelligence & Tradecraft — 2026-05-16

Symantec Confirms Fast16 Malware Sabotaged Iran Nuclear Weapons Simulations

BLUFConfirmation of Fast16 as a state-grade sabotage tool means commercial simulation software now constitutes a strategic vulnerability for every nuclear weapons program, inviting both copycat operations and hardened countermeasures by adversary states.

SentinelOne researchers Juan Andres Guerrero-Saade and Vitaly Kamluk published their analysis on April 23, 2026, tracing Fast16's name to the April 2017 Shadow Brokers leak where it appeared in NSA Territorial Dispute deconfliction signatures labeled 'Nothing to see here - carry on,' directly linking the malware to US intelligence operations. SentinelOne's binary analysis identified PKPM (Chinese structural engineering CAD) and MOHID (hydrodynamic modeling platform) as additional apparent targets alongside LS-DYNA, though Symantec's subsequent hook engine analysis confirmed AUTODYN rather than those two as the second verified target. Fast16 is the first Windows malware known to embed a Lua scripting engine, with a precise compilation timestamp of August 30, 2005. David Albright of the Institute for Science and International Security connected the malware's behavior to Iranian implosion-device design documents obtained by Israeli intelligence in 2018.

Analysis
Ten distinct hook-rule groups confirm operators maintained sustained access and adapted tooling as targets upgraded platforms, closing the conceptual gap between Fast16 and Stuxnet, corroborated across three independent technical analyses. The 30 g/cm³ density threshold in the hook engine marks uranium implosion-device simulation as the explicit design objective. Authorship is thereby restricted to the small set of state programs holding nuclear-weapons physics knowledge in 2005. A live deconfliction entry, rather than a proof-of-concept flag, places both tools in a coordinated two-track campaign. North Korea or Syria cannot be excluded as the primary target; both programs were active in the period and the malware carries no geographic indicators.
2 sources
  1. Experts Confirm the Fast16 Malware Was Sabotaging Nuclear Weapons Tests, Likely in Iran - Zetter Zero Day
  2. Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations - Symantec (security.com)

View in full brief →

UNCLASSIFIED // OPEN SOURCE