Before Stuxnet, there was fast16: a state-grade sabotage framework that didn’t steal data or crash systems. It silently altered engineering simulations and calculations—poisoning digital twins while everything appeared normal. Now imagine AI giving attackers the power to find such weaknesses in hours.
As Singapore and other countries in the region expand protections beyond core CII, fast16 is a warning: tomorrow’s breach won’t hold your data hostage. It will corrupt the simulations and AI models you trust to run your plant, bridge, or refinery. And you won’t know until something breaks.
The invisible sabotage that redefines “breach”
For two decades, cybersecurity has been shaped by visible threats: ransomware locking files, data breaches exposing records, DDoS attacks taking websites offline. But fast16—a malware framework compiled in 2005 and only fully understood in 2026—reveals a far more insidious category of attack.
This is malware that doesn’t announce itself. It doesn’t steal, encrypt, or destroy. Instead, it manipulates the mathematical truth upon which engineering, physics, and now AI systems depend.
Vitaly Kamluk, cybersecurity researcher at SentinelOne Labs, describes fast16 as "unique, I think, one-of-a-kind malware that didn’t do all that. Instead, it just manipulated mathematical calculations, which seems like a benign thing, but applied to, let’s say, civil engineering or maybe military research, it may have profoundly serious and big consequences."
The malware was designed to target high-precision simulation software—specifically LS-DYNA and AUTODYN, tools used for modelling high-explosive compression and nuclear weapon physics.
Its logic was surgically precise: it would wait until a simulation approached supercriticality, then "selectively replace real outputs in memory with slightly reduced pressure and related values before they appeared on engineers’ graphs."
The manipulation was subtle—perhaps only 1 to 5 per cent—enough to make successful designs appear to fail, but not so obvious as to raise suspicion.
"The core sabotage logic only activated under narrow conditions," researchers found. “Fast16 first verified that a supported simulator was running and that a scenario matched high-explosive implosion tests consistent with a spherical uranium core design."
This was not spray-and-pray cybercrime. This was a precision instrument of strategic deception.
The AI accelerant: From decades to hours
Kamluk’s research took an unexpected turn when he tested five frontier AI models against the fast16 binary. The results were startling—and deeply concerning for anyone responsible for defending critical systems.
"Not all of them were the same," Kamluk notes. "I have to report that, so far, Anthropic Claude has been the most successful. With a bit of guidance, it managed to identify how important this malware is and even connected it to Stuxnet. I never mentioned Stuxnet to it, but it correctly recognised that this isn’t just a close relative—it is Stuxnet itself."
This is the new reality. Where it took security researchers nearly two decades to understand fast16’s significance fully, AI can now draw those connections in hours. But the same capability that accelerates defence also accelerates attack.
As IBM’s X-Force Red team observes, "Threat actors aren’t writing spear phishing emails by hand anymore. They’re using AI to scale, personalise, and accelerate every stage of the attack lifecycle."
The frontier has already been crossed. Anthropic’s Claude Mythos Preview model recently demonstrated the ability to autonomously surface thousands of zero-day vulnerabilities across every major operating system and popular web browser—some undetected for up to 27 years.
Under controlled conditions, it achieved complete success in three out of ten independent runs, making it "the first AI model to solve the entire attack chain end-to-end."
For a CISO in Southeast Asia, this means the threat landscape has fundamentally shifted. Kamluk warns: "If a change like that silently slips into the process, your model can effectively get a malicious injection of knowledge, of commands, of behaviour. It can sit there and later be activated on demand."
Why Singapore and Southeast Asia are in the crosshairs
Singapore has emerged as a critical hub for AI infrastructure and advanced technology—and consequently, a prime target for sophisticated adversaries. The city-state’s proactive regulatory stance reflects this reality. In March 2026, Senior Minister of StateTan Kiat How told Parliament that "threat actors—especially Advanced Persistent Threats, or APTs—will only get more sophisticated."
But fast16-type attacks render traditional perimeter thinking obsolete. The malware spread laterally across internal networks, planting its corruption on every machine that might be used to verify calculations. "It did this in a way that was very invisible to the end user," Kamluk explains.
Vitaly Kamluk
"At the same time, it’s spread through not just one system, but through the organisation network and, in fact, all other possible computers where these calculations would also be tampered with, so that if you try to get a second opinion, it will also be already modified and altered by the malware." Vitaly Kamluk
The implications for Southeast Asian economies—heavily reliant on manufacturing, infrastructure development, and increasingly AI-driven decision-making—are profound. As one CII owner told Singapore’s government, defending against state-backed adversaries feels like “bringing a knife to a gun fight”.
The detection blind spot: When "noise" is actually the warning
One of the most troubling aspects of the fast16 discovery is how long it remained hidden—not just from defenders, but from the entire cybersecurity industry. The file was leaked by Shadow Brokers in 2017 and uploaded to VirusTotal, where it sat for years, examined by countless researchers and AI systems, yet its true purpose went unrecognised.
"For many years, it remained kind of unexplored fully," Kamluk acknowledges. "Researchers and reverse engineers understood that there was a value. It was a self-propagated malware. It was a network worm. But nobody really managed to grasp the true value and the true kind of risk that such malware creates to all of us. And it was discovered just this year because, you know, we got lucky in a way."
Why? Because fast16 didn’t fit the known patterns. It wasn’t a rootkit hiding files. It wasn’t a backdoor stealing credentials. It didn’t match any technique in the MITRE ATT&CK framework. When Kamluk tested AI models against the binary, they initially classified it as a rootkit because "it moves like a rootkit. It speaks like a rootkit. This is a rootkit." But when pressed on what it hid, the AI couldn’t answer.
"Everything that does not fit into a known attack category or malware—it is often considered to be just noise, simply because it is not known," Kamluk warns. "What we don’t know is probably irrelevant, maybe a false positive, maybe just something not worth attention.
"This case showed us that our models, although they are already mature, they’ve been maturing for maybe over a decade now with understanding of tools, techniques, and procedures, they’re still not perfect," he elaborates.
Building defences against the invisible
For CISOs in Southeast Asia, the fast16 discovery demands a fundamental rethinking of security architecture. Traditional incident response plans—optimised for ransomware and data breaches—are inadequate for attacks that corrupt truth rather than steal assets.
Kamluk’s recommendation is stark: "We probably should assume that our systems will be compromised at some point. We need to prepare mechanisms to make sure that the data these systems produce is, at least, somewhat reliable. Correlate results from different systems that are physically disconnected, completely independent, and have their integrity controlled. Only when that data matches—and when it’s critical data—can we really trust it."
This is not theoretical. Singapore’s CSA is already moving to mandate Cyber Trust Mark certification for CII owners, auditors, and licensed cybersecurity service providers, with CII owners required to achieve Level 5 by the end of 2027. The framework now includes AI security and operational technology security—recognition that the threat landscape has evolved.
But compliance alone won’t stop a fast16-style attack. The malware’s design was specifically intended to defeat standard verification: it would corrupt the simulation output on every machine an engineer might use for cross-checking.
"You need independent validation for systems that are air-gapped and not connected, even if they come from a trusted, integrity-controlled environment," Kamluk insists.
The challenge is determining which systems and calculations warrant such rigorous protection. "That applies, of course, not to all of our calculations, only to those that are most critical and most sensitive that may have very serious effects in case of even a tiny little mistake seeping in," Kamluk says.
"We need to identify critically important assets and computational processes, separate them, and treat them differently, not like everything else. That’s key to tackling this problem." Vitaly Kamluk
The new frontier: AI poisoning and epistemological warfare
Kamluk’s research has broader implications for the AI systems being rapidly deployed across Southeast Asian economies. The same manipulation technique that corrupted engineering simulations in 2005 can now be applied to AI training pipelines.
"Now put that into today’s world, where we’re constantly training and retraining AI models, optimising them, expanding their understanding for all kinds of AI-powered systems," Kamluk warns. "If a change like that silently slips into the process, your model can effectively get a malicious injection of knowledge, of commands, of behaviour."
The analogy is chilling: just as fast16 convinced nuclear weapons engineers that their designs were failing, a well-placed corruption in an AI training pipeline could produce a model that appears functional but contains hidden behaviours.
"Most of the time it will look and behave exactly as you expect, but an attacker can trigger specific conditions where the model suddenly flips and starts acting like an ally of the attacker—almost like an insider in your system. That’s the real risk and real threat of fast16-like malware in the modern world." Vitaly Kamluk
Some researchers have proposed a new classification for this category of threat: epistemological malware—attacks that target "your understanding, your knowledge, and the process of understanding rather than the computer systems."
Expecting the unknown
For CISOs and heads of cybersecurity in Southeast Asia and Hong Kong, the lesson of fast16 is both sobering and actionable. The threat that matters most may not look like a threat at all. It may not fit established frameworks. It may not trigger alarms. It may simply make your systems produce slightly wrong answers—until something breaks.
"We should always assume that what is noise may not necessarily be benign or unrelated," Kamluk advises. "We sometimes should look into what is outside of the known metrics so that we don’t miss such an important event. And maybe discoveries as fast as this will not take decades to be made. If we change our approach, if we change our paradigm, we should expect the unknown. If you include that into our formula, then such cases as fast16 will not hurt us."
The threat is not theoretical. The malware exists. The AI to weaponise it is already here. And the organisations most dependent on simulation, engineering, and AI—the very engines of Southeast Asian economic growth—are the most vulnerable. The question is not whether an attack like this will happen again. The question is whether you will know it when it does.
Click on the PodChats player to hear details from Kamluk about atypical threats that have proven to be just as dangerous as currently known malware.
What is the role of a researcher in the cybersecurity space?
In a nutshell, what is fast16 and what makes it different from other categories of cyber threats?
How do we identify which of our engineering simulations, digital twins, and AI training pipelines are most vulnerable to silent output manipulation—and do we have any validation layer that checks results against physical or independent models?
How do we detect an attack that changes calculations but leaves systems running normally?
What stops an AI-powered attacker from finding a hidden weakness in our simulation software?
Our incident plan covers ransomware. Do they cover a scenario where a state-grade actor has been quietly corrupting our engineering decisions for six months? How do we roll back trust in our own data?
If an attacker manipulates a supporting system’s simulation to cause a real-world failure, will current cyber insurance or legal framework treat that as a “breach” or as a “design error”?
How do we differentiate between adversarial attacks on the AI’s availability (denial) vs subtle corruption of its reasoning or output distribution—and which defensive architectures apply?
Given what we now understand about fast16, what is your recommendation for moving forward?