Kaspersky finds 2005 cyberweapon aimed at nuclear models

Kaspersky's industrial security team has published its quarterly review of targeted attacks on industrial organizations, and the strangest thing in it is more than twenty years old. Researchers say they have found malware written in 2005 whose job was to quietly corrupt the mathematics behind nuclear detonation modelling.

The sample, dubbed fast16, is described in the Kaspersky ICS CERT report for the second quarter of 2026 as a genuine cyberweapon that almost reaches the level of domain immersion of Stuxnet, the sabotage tool that damaged Iranian centrifuges. Its target was not a plant or a pipeline. It went after the sophisticated mathematical packages engineers use to model complex physical processes such as detonation, and specifically at calculations simulating the conditions that trigger an uncontrolled nuclear reaction. Rather than break those calculations outright, Kaspersky says, it made subtle adjustments to them and disrupted the simulation.

The team assesses that the malware was used in practice, because its developers kept refining it and added support for further versions of the simulation software they were targeting. Kaspersky does not attribute fast16 to any country or group, and does not name the organizations affected. It frames the discovery as cyber archaeology and asks the obvious follow-up question: how many other tools of that calibre are still quietly running today.

An unusually loud quarter for OT attacks

Kaspersky calls the second quarter "unprecedentedly dense" with publications about targeted attacks on industrial control systems. Among the cases it summarizes:

The report also tracks Geo Likho, also known as Batavia, a group that has been spear-phishing organizations in Russia and Belarus since at least July 2024. Kaspersky says the group still leans on a malicious VBE script that starts a three-stage infection, but has begun building individual tools tailored to each victim's infrastructure.

AI reaches for the plant floor

The other notable entry concerns attacks on Mexican government agencies and industrial enterprises in which the operators leaned on machine learning agents and cloud models including Claude and GPT-4.1. Kaspersky describes it as a still extremely rare case of AI being used at most stages of the kill chain inside the victim network, covering reconnaissance, finding and prioritizing new targets, and lateral movement. In one case the AI pointed the attackers at an interface into the organization's OT segment and suggested a way to reach it. That attempt was tentative and unsuccessful, but Kaspersky flags it as the first documented attempt by AI to reach OT.

The team's warning is about the direction of travel rather than this one campaign: industrial firms are increasingly using large public models for OT work, which means those models keep accumulating exactly the domain knowledge that has historically separated ordinary intruders from people capable of cyber-physical sabotage. IntelFusions has covered a parallel case in which an operator let an AI agent choose and attack its own targets.

What you should do

The recurring thread across the Rockwell, Modbus and water treatment cases is industrial equipment that answers to the open internet. Inventory anything in the OT estate that is directly reachable, put remote access behind a broker with multi-factor authentication, and treat engineering project files as sensitive intellectual property rather than build artifacts. Operators should also be sceptical of clean HMI screens during an incident, because spoofed process data is now an observed technique and not a theoretical one. For context on the wider trend, Kaspersky's earlier data showed attacks on industrial control systems falling to a three-year low even as targeted operations grew more capable.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions