<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/malware-from-2005-may-be-the-oldest-known-cyberweapon-predating-stuxnet-by-five-years-zkq1sjq9c" -->

---
title: Malware from 2005 may be the oldest known cyberweapon,...
description: SentinelOne researchers have uncovered FAST16, a malware framework dating to around 2005 that may predate Stuxnet as the first known cyberweapon deployed...
canonical: https://daily.dev/posts/malware-from-2005-may-be-the-oldest-known-cyberweapon-predating-stuxnet-by-five-years-zkq1sjq9c
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Malware from 2005 may be the oldest known cyberweapon, predating Stuxnet by five years | daily.dev
og:description: SentinelOne researchers have uncovered FAST16, a malware framework dating to around 2005 that may predate Stuxnet as the first known cyberweapon deployed...
og:url: https://daily.dev/posts/malware-from-2005-may-be-the-oldest-known-cyberweapon-predating-stuxnet-by-five-years-zkq1sjq9c
og:image: https://api.daily.dev/og/posts/ZkQ1Sjq9C.png
og:image:alt: Malware from 2005 may be the oldest known cyberweapon, predating Stuxnet by five years
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Malware from 2005 may be the oldest known cyberweapon, predating Stuxnet by five years

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

SentinelOne researchers have uncovered FAST16, a malware framework dating to around 2005 that may predate Stuxnet as the first known cyberweapon deployed against physical infrastructure. Found in a VirusTotal sample uploaded in 2016 and cross-referenced with ShadowBrokers-leaked NSA documents, FAST16 targeted engineering simulation software (LS-DYNA 970, PKPM, MOHID) by injecting near-imperceptible errors into floating-point calculations — a subtler approach than Stuxnet's direct hardware destruction. It spread via a 'cluster munition' worm mechanism and embedded Lua scripting. While FAST16 only runs on Windows XP with single-core CPUs and poses no modern direct threat, the attack vector of corrupting high-precision numerical computations remains viable in domains like financial trading and AI training. Attribution points toward a nation-state actor with NSA ties, though no formal attribution has been made. If confirmed operational in 2005, it rewrites the history of state-sponsored cyber sabotage.

## Content

# FAST16: The 2005 malware that may have beaten Stuxnet to cyber sabotage

SentinelOne researchers have uncovered a malware framework called FAST16 that appears to predate Stuxnet by roughly five years — potentially making it the first known cyberweapon deployed against physical infrastructure.

The discovery came from a VirusTotal sample uploaded in 2016 that had sat largely undetected for years. Cross-referencing it with documents leaked by the ShadowBrokers — the group that dumped NSA tools in 2016 — researchers traced FAST16's origins to around 2005. Vitaly Kamluk presented the findings at Black Hat Asia.

## What it actually does

Where Stuxnet physically destroyed Iranian centrifuges by sending them incorrect speed commands, FAST16 took a subtler approach: it corrupted floating-point calculations inside engineering simulation software. The targets were specific — LS-DYNA 970, PKPM, and MOHID, tools used in civil engineering, nuclear physics modeling, and environmental simulation. Iran reportedly used LS-DYNA in its nuclear weapons program.

The malware injected near-imperceptible errors into high-precision mathematical computations. Depending on the context, those errors could produce faulty research results or, in a worst case, cause real-world equipment to fail catastrophically. The kind of sabotage that's hard to trace because the software appears to be running fine.

To spread, FAST16 used what researchers describe as a "cluster munition" delivery mechanism — deploying small wormlets across target networks — along with an embedded Lua scripting engine.

## The catch

FAST16 only runs on Windows XP with a single-core CPU. It cannot execute on any modern hardware. So as a direct threat, it's inert.

But the attack vector it pioneered isn't. Corrupting high-precision calculations is still a viable sabotage strategy in domains like financial trading systems and AI model training, where subtle numerical errors can compound in ways that aren't immediately obvious.

## Attribution

Researchers assess this as likely nation-state work, and the NSA document references point in a clear direction. But formal attribution hasn't been made. What's harder to dispute is the timeline: if FAST16 was operational in 2005, it rewrites the history of state-sponsored cyber sabotage — Stuxnet, discovered in 2010, was long considered the starting point.

## Similar posts on daily.dev

- [Researchers unearth industrial sabotage malware that predated Stuxnet by 5 years](https://daily.dev/posts/researchers-unearth-industrial-sabotage-malware-that-predated-stuxnet-by-5-years-wcwfomcmb) · CSO Online · 0 upvotes · 0 comments
- [fast16 \| Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet](https://daily.dev/posts/fast16-mystery-shadowbrokers-reference-reveals-high-precision-software-sabotage-5-years-before-stu-lwjq7xgor) · Hacker News · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/malware-from-2005-may-be-the-oldest-known-cyberweapon-predating-stuxnet-by-five-years-zkq1sjq9c)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Malware from 2005 may be the oldest known cyberweapon, predating Stuxnet by five years","url":"https://daily.dev/posts/malware-from-2005-may-be-the-oldest-known-cyberweapon-predating-stuxnet-by-five-years-zkq1sjq9c","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/malware-from-2005-may-be-the-oldest-known-cyberweapon-predating-stuxnet-by-five-years-zkq1sjq9c"},"datePublished":"2026-04-27T13:44:42.191Z","dateModified":"2026-04-30T10:25:58.444Z","description":"SentinelOne researchers have uncovered FAST16, a malware framework dating to around 2005 that may predate Stuxnet as the first known cyberweapon deployed...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/0a9661c217e828d87580c542c0e82285?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/0a9661c217e828d87580c542c0e82285?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/malware-from-2005-may-be-the-oldest-known-cyberweapon-predating-stuxnet-by-five-years-zkq1sjq9c","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cyber,malware","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Malware from 2005 may be the oldest known cyberweapon, predating Stuxnet by five years"}]}
```

