Symantec Confirms Fast16 Malware Sabotaged Iran Nuclear Weapons Simulations
SentinelOne researchers Juan Andres Guerrero-Saade and Vitaly Kamluk published their analysis on April 23, 2026, tracing Fast16's name to the April 2017
Ten distinct hook-rule groups confirm operators maintained sustained access and adapted tooling as targets upgraded platforms, closing the conceptual gap between Fast16 and Stuxnet, corroborated across three independent technical analyses. The 30 g/cm³ density threshold in the hook engine marks uranium implosion-device simulation as the explicit design objective. Authorship is thereby restricted to the small set of state programs holding nuclear-weapons physics knowledge in 2005. A live deconfliction entry, rather than a proof-of-concept flag, places both tools in a coordinated two-track campaign. North Korea or Syria cannot be excluded as the primary target; both programs were active in the period and the malware carries no geographic indicators.
2 sources
- Experts Confirm the Fast16 Malware Was Sabotaging Nuclear Weapons Tests, Likely in Iran -
Zetter Zero Day - Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations -
Symantec (security.com)