Briefing

Fast16 State‑Sponsored Malware Targeting Iran

security
by Bruce Schneier ·

Check for Fast16 signatures, isolate affected networks, and patch any vulnerable software that could be targeted by silent manipulation of high‑precision calculations.

What to do now

Patch any software that performs high‑precision calculations, isolate affected networks, and monitor logs for silent manipulation of computation processes.

Summary

Fast16 is a state‑sponsored malware that researchers have reverse‑engineered. It is believed to be US‑originated and was deployed against Iran years before Stuxnet. Fast16 spreads automatically across networks and silently manipulates computation processes in software that performs high‑precision mathematical calculations and physical simulations. By altering the results of those programs, it can cause failures ranging from faulty research data to catastrophic damage to real‑world equipment. The malware’s sabotage is subtle, making it hard to detect. The researchers highlighted Fast16’s ability to silently sabotage critical calculations. The discovery underscores the need for heightened vigilance against state‑sponsored sabotage tools. Fast16’s deployment demonstrates that sophisticated sabotage can target specialized scientific software, posing a serious threat to research institutions and industrial control systems.

Key changes

  • Fast16 is state‑sponsored malware believed to be US‑originated.
  • It was deployed against Iran before Stuxnet.
  • Fast16 spreads automatically across networks.
  • It silently manipulates computation processes in high‑precision math and simulation software.
  • The sabotage can cause failures from faulty research results to catastrophic equipment damage.

Affects

none

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting