# Fast16: a cyberweapon that targeted numerical calculations

**URL:** <https://discourse.julialang.org/t/fast16-a-cyberweapon-that-targeted-numerical-calculations/136911>\
**Category:** Offtopic\
**Created:** [April 28, 2026, 4:39pm UTC](https://discourse.julialang.org/t/fast16-a-cyberweapon-that-targeted-numerical-calculations/136911 "2026-04-28T16:39:33Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [April 28, 2026, 4:39pm UTC](https://discourse.julialang.org/t/fast16-a-cyberweapon-that-targeted-numerical-calculations/136911/1 "2026-04-28T16:39:33Z")

</div>

> **[Fast16: The Cyberweapon That Predates Stuxnet by Five Years](https://hackingpassion.com/fast16-pre-stuxnet-cyber-sabotage/)**
>
> For 21 years, fast16 corrupted nuclear research calculations without anyone noticing. It predates Stuxnet by five years. The math was always wrong.

---

<div class="post-metadata">

**Author:** ![mbauman](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/mbauman/32/31082_2.png) [@mbauman](https://discourse.julialang.org/u/mbauman)\
**Post date:** [April 28, 2026, 5:05pm UTC](https://discourse.julialang.org/t/fast16-a-cyberweapon-that-targeted-numerical-calculations/136911/2 "2026-04-28T17:05:42Z")

</div>

Fascinating. I found the original source easier to read:

> **[fast16 | Mystery ShadowBrokers Reference Reveals High-Precision Software...](https://www.sentinelone.com/labs/fast16-mystery-shadowbrokers-reference-reveals-high-precision-software-sabotage-5-years-before-stuxnet/)**
>
> A previously unknown 2005 cyber sabotage framework patches high-precision calculation software in memory to silently corrupt results.

---

<div class="post-metadata">

**Author:** ![BioTurboNick](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/bioturbonick/32/6380_2.png) [@BioTurboNick](https://discourse.julialang.org/u/BioTurboNick)\
**Post date:** [April 28, 2026, 5:39pm UTC](https://discourse.julialang.org/t/fast16-a-cyberweapon-that-targeted-numerical-calculations/136911/3 "2026-04-28T17:39:19Z")

</div>

Somehow I find both to be impenetrable. They both seem to talk around things and avoid getting straight to the point. I can’t tell if that’s an AI thing or not.

Like, in the SentinelOne writeup, the Executive Summary doesn’t even contain information on what it does, and neither does the Overview section.

---

<div class="post-metadata">

**Author:** ![mbauman](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/mbauman/32/31082_2.png) [@mbauman](https://discourse.julialang.org/u/mbauman)\
**Post date:** [April 28, 2026, 5:45pm UTC](https://discourse.julialang.org/t/fast16-a-cyberweapon-that-targeted-numerical-calculations/136911/4 "2026-04-28T17:45:06Z")

</div>

Both are definitely AI-y. In short, it’s a 2005 self-propagating worm that edited a small set of programs on the fly to change a few specific FPU routines in memory.

> The patching engine is a minimalist, performance‑optimised, stateful scanning and modification tool. It is configured with a set of 101 rules, each containing pattern matching and replacement logic.

It only patched very specific executables based on a few exact bit patterns. So they only found a handful of matches against some very specific commercial engineering tools.

> Without knowing the exact binaries and workloads being patched, we can’t fully resolve what those arrays represent, only that the goal is to tamper with numerical results, not unauthorized access, malware propagation or other common malware objectives.

---

<div class="post-metadata">

**Author:** ![BioTurboNick](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/bioturbonick/32/6380_2.png) [@BioTurboNick](https://discourse.julialang.org/u/BioTurboNick)\
**Post date:** [April 28, 2026, 5:49pm UTC](https://discourse.julialang.org/t/fast16-a-cyberweapon-that-targeted-numerical-calculations/136911/5 "2026-04-28T17:49:01Z")

</div>

Oh god thank you, that’s so much clearer.

---

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [April 30, 2026, 10:38am UTC](https://discourse.julialang.org/t/fast16-a-cyberweapon-that-targeted-numerical-calculations/136911/6 "2026-04-30T10:38:43Z")

</div>

Two more articles which are better written, though essentially the same information.

> **[Newly Deciphered Sabotage Malware May Have Targeted Iran’s Nuclear...](https://www.wired.com/story/fast16-malware-stuxnet-precursor-iran-nuclear-attack/?_sp=72d58355-e351-43ad-ba73-bc2b546a30a0.1777128353268)**
>
> Researchers have finally cracked Fast16, mysterious code capable of silently tampering with calculation and simulation software. It was created in 2005—and likely deployed by the US or an ally.

> **[Pre-Stuxnet Sabotage Malware 'Fast16' Linked to US-Iran Cyber Tensions](https://www.securityweek.com/pre-stuxnet-sabotage-malware-fast16-linked-to-us-iran-cyber-tensions/)**
>
> The Fast16 sabotage malware targeted high-precision computing workloads and could propagate through entire facilities.

---

<div class="post-metadata">

**Author:** ![franckgaga](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/franckgaga/32/218241_2.png) [@franckgaga](https://discourse.julialang.org/u/franckgaga)\
**Post date:** [May 1, 2026, 5:22am UTC](https://discourse.julialang.org/t/fast16-a-cyberweapon-that-targeted-numerical-calculations/136911/7 "2026-05-01T05:22:49Z")

</div>

It was a fascinating read, thanks ! 😁
