Go back

Can computer hackers get inside your mind?

29m 42s

Can computer hackers get inside your mind?

A hidden cyber conflict between the U.S. and Iran has been unfolding for years, with cyber attacks like Fast 16 serving as a stealthy, high-stakes weapon in the broader nuclear standoff. Unlike traditional attacks, Fast 16 did not steal data or destroy systems—it manipulated complex mathematical calculations used in scientific simulations, particularly in software like LS Dyna, which Iranian scientists used to model nuclear explosives. The malware remained undetected for decades, only recently uncovered by cyber paleontologist Juan Andres Guerrero Sade (Jags) and researcher Vitaly Kamluk, who identified its unique targeting of precision math. Their investigation revealed that Fast 16 was designed to subtly corrupt results, causing scientists to question their own work and potentially destabilize key research. This represents a new form of "epistemological warfare"—an attack not on infrastructure but on the foundations of knowledge and trust. While the malware likely targeted Iran’s nuclear program, definitive proof remains elusive, and the creators—possibly U.S. or Israeli intelligence—have not confirmed or denied involvement. Despite the uncertainty, experts believe Fast 16 was a significant, if covert, intervention in the nuclear arms race. Its existence and sophistication underscore how digital tools can be used to disrupt scientific progress and instill doubt, reshaping how we understand modern warfare. The case highlights the enduring power of cyber espionage to influence global security long after the initial attack.

Transcription

4600 Words, 25333 Characters

English
This is Planet Money from NPR. On Friday, if all goes according to plan, representatives from the U.S. and Iran will meet in Geneva to sign another 60-day ceasefire agreement. But the two sides still have not come to an agreement on what's been at the heart of this war. And decades of conflict. Iran's development of nuclear weapons. Right. The conflict has been on again, off again, for years. And while the most recent iteration has been very violent with bombs and blockades, there is a whole other almost entirely invisible war that the U.S. and allies have been waging with Iran using cyber espionage or more accurately cyber sabotage, you know, computer viruses, malware. Recently, we heard a story about a piece of malware that might have been used in this invisible war that was diabolically cunning. Because it exploited weaknesses in computers, yes, but also maybe in the human psyche. The more I think about it, the more I think this must have driven people insane. But it also might have saved the world from nuclear destruction. We heard about this hack from someone whose job it is to identify computer hacks that could be a threat to all of us. What's your name? What do you do? This is Juan Andres Guerrero Sade, which is why everybody calls me Jags. J-A-G-S, Jags, his initials are shorter and cooler. Yeah, actually, he is a pretty cool guy. He's got a foe hawk, sleaze of tattoos. He was on track to go get a PhD in philosophy, but now I'm a security researcher, well, I think would be the simplest term. I think some folks would say cyber paleontologist. Like he digs for the remnants of cyber attacks. Jags works for a cyber security company called Sentinel One. It helps big companies like Samsung and the Golden State Warriors and the government protect their computers and networks. Hacking is a whole industry and defending against hacks is this whole other industry. Jags just so happens to have the radish job of all, which is dusting off old malware files buried deep on servers and reverse engineering how hackers got into systems in the first place. And what they did when they got there. So he can figure out how to defend against similar attacks in the future. And Jags is kind of a big deal. There are actually a couple of pieces in the International Spy Museum in DC based on his cyber paleontology work. This is a little crude, but in the Jurassic Park movie, which paleontologists are you? As long as you don't immediately default to Jeff Goldblum and that I was going to go Jeff Goldblum. But I think that he is like a chaos theory mathematicians, which I think fits the bill, right? What the hell do I actually know about paleontology, right? We met up with Jags because we wanted to get a peek into the invisible war because Jags has made a stunning discovery of a highly specialized, highly sophisticated cyber weapon. Justin, these weapons don't even get detected. If they do, it's not usually until years later when someone like Jags comes across an old fragment and tries to reconstruct what top secret mission the weapon was designed to carry out. For Jags, the fragment he found wasn't even a piece of code. It was just six words. It came from a leaked list of malware from the NSA. Yeah, the list came from this tool, the NSA had. To help NSA operators, while they were hacking into some computer in enemy territory, figure out whether some other hacker was already there. And if so, whether they were friends or foes, essentially, it'll run all these checks and it's going to give the operator, it's going to give a list of instructions of saying, hey, look, suspicious thing here. We don't know what that is. Known malware, pull back. Like little warning signs. And this was a budding cyber paleontologists dream. Each piece of malware on that list had the potential to teach you so much about how the world's top hackers were getting the job done. And maybe one would turn out to be an incredibly sophisticated cyber weapon. Jags, with great excitement, got a hold of this list and started scouring it for something he should start digging into and one item screamed, look here. There's one just one line that's like completely different to all the other ones. Okay. And it's, it just says, fast 16, nothing to see here carry on in all caps. That's it. There's nothing else like it. Fast 16 was what the NSA was calling the malware. And the cryptic instruction the agency was giving its operators not seek help or pull back simply nothing to see here carry on. You can't put that there like it's it was like catnet, right? It felt like bait. We couldn't let it go. I couldn't let it go. He didn't let it go. He had to know what this thing was. What did it do? What was its target? The NSA seemed to know about it, but who made it? And what was so top, top, top secret that the NSA was resorting to Jedi mind tricks to try to keep its own people in the dark? At this point, Jags just had the name of this malware, fast 16, just a tibia. But he was able to use that to dig up the rest of the bones. Basically, he rummaged around this like public library of suspected malware until he found it. Naturally, he was able to put together the pieces of the skeleton that is fast 16. But still, when you try to reverse engineer it to understand what its secret mission was, he couldn't. I worked these like cracked out nights and very often I'll run into something. I'm like, oh my god, I found this amazing thing. And then by the morning, you're like, no, this doesn't work. We call this the Valley of Despair. Oh yes, I have built a home in the Valley of Despair. I'm in the process of gentrifying the Valley of Despair, if any of you would like to join me there. After many, many fruitless nights, weeks, months, Jags had to turn to other projects and had to put fast 16 down. But to remind him of what was not solved, he inked fast 16 on his skin forever. Fast 16 has been on the back of my arm for a moment. You got a tattooed? Oh yeah. Where is fast 16? It's here. You can see fast 16 and nothing to see here. Nothing to see here. Carry on. Hello and welcome to PlatinumMoney. I'm Nick Fountain. And I'm Erica Barres. Today on the show, nothing to see here. Carry on. Yeah. Jags sets out to solve the mystery of fast 16 and finds a cyber weapon with the potential to chip away at our very grasp of reality. What was this mysterious piece of malware that was so secret that the NSA was using Jedi mind tricks to try to keep their people away from it? And so enticing that security researchers, or at least one over caffeinated keyboard wielding security researcher, got a tattooed on his tricep, theoretical tricep, yes. Jags said researcher was pretty blocked, but he knew he had to keep at it because he had a hunch that fast 16 might reveal important details about that invisible side of the conflicts we read about every day, like back when security researchers discovered a cyber sabotage operation that blew everyone's mind. It was called Stuxnet. Stuxnet is kind of the mother of all cyber sabotage operations. In many ways, my industry is birthed by the discovery of Stuxnet. For those not familiar, Stuxnet was this absolutely bonkers hacking operation that reportedly slowed down Iran's nuclear program back in the mid 2000s. And to hear Jags describe it, it totally redefined what was possible. So before Stuxnet, if you went to these antivirus conferences with a lot of fun gals and guides, the possibility of cyber espionage was discussed as that as a possibility. It was theoretical. It was theoretical. It would be cool. This might be happening. Yeah. You're like, there's no way people won't. There's value there. Of course. And then, you know, Stuxnet is discovered and you realize not only has this been happening and at a scale and capacity way above anything we'd ever found before, but it's been happening for years. What had been happening was that Israel and the U.S. allegedly had used cyber weapons to destroy real world physical things. They did this by managing to get a thumb drive into Iran and inserting malware into the computer network at the heart of their uranium enrichment program, the system that controlled the centrifuges. And Stuxnet was very, very clever. It spread throughout the network and carefully noted how everything looked when it was working normally, saved that, and then gave the centrifuges instructions to go haywire. up and slowing down and breaking. All while making everything in the computer system look okay, look normal. So the operators are hearing that these things are like making these weird noises, they're spinning up, they sound like it sounds like things aren't going well in this room next door, but I'm looking at the computer and the computer tells me everything's normal. All in all, Stuxnet reportedly destroyed a fifth of all the centrifuges that Iran was using. It led to nuclear scientists getting fired, and most importantly, it is widely believed to have slowed down Iran's nuclear program. And to the cyber paleontologists of the world, like Jags, when the bones of Stuxnet were dug up, they revealed this whole new age of cyber warfare. But Jags always believed that Stuxnet was just a hint of what was out there. Just a tibia. Clearly, we didn't even know about all the different things they were doing. So, year after year, Jags remained committed to figuring out his white whale, figuring out the puzzle of Fast 16, who made it, who were they targeting, what exactly were they doing to that target, and how. But he didn't make much progress until, earlier this year, for a very, this year reason, AI. Yeah, here's why, Jags heads a big team of researchers at his cyber security firm. And like everyone else these days, he was wondering, could these new AI tools help us in our jobs? Could they do our jobs? Could they do a job that was so hard even I, Jags, couldn't do it. Could they solve the puzzle that is Fast 16? There is no public guide to solving it. If it's going to figure it out, it's going to have to figure it out just in this little sandbox with a few tools and go, alright, kid, like what can you do? Jags sent a colleague to oversee these AI tests. That colleague was Vitaly Kamluk, a Belarusian cyber security researcher, who also has a foe hawk. He lives in Singapore, and according to Jags is very zen like. And Jags has Vitaly, like any self-respecting human, he decided to, John Henry style, try to beat the machines. I, being put in that position would have said, cool, let's go make the AI sweat. And Vitaly being a much more patient, zen master style, dude, he said, well, if I'm going to know if it's doing well, I need to know what this thing does. And Vitaly spent like two weeks in a black dark hole somewhere, not answering messages, nothing, I was like, is this guy okay? What happened to Vitaly? And all of a sudden I get a message from Vitaly, super late, I guess for him. Yeah, yeah, it was like about 1 a.m. or so. He's like, hey man, like I need to talk. Jax, yeah, we need to talk. This of course is Vitaly Kamluk, reverse engineering legend. He describes you as zen like. Do you think that's fair? Zen like. Yeah, just make me more peaceful and simple, I hope so. But on this call, he was not very zen like. Vitaly said he'd done the reverse engineering. And he'd had the AI models double and triple check his work. And now Jax says, he seemed pretty disturbed. He's like, look, I need you to test me here. But like all the models at least agree with me. So I now need to talk to a human being. This is Stuxnet like. And I hear that kind of nonsense from students. Right. Like, you know, I hear this kind of, I'm like a lightning rod. Anybody in the industry is a lightning rod for like DMs from people clearly having like schizophrenia episodes about like the government spying on me. So you hear this kind of stuff all the time. When you hear it from Vitaly, who's a very measured person, it makes you take pause. You go, okay, what are you talking about? What do you mean? Vitaly explained they're from the same era, the mid 2000s. And even though they don't share any code, they seem to share similar architecture. But Vitaly couldn't figure out what exactly fast 16's mission was only that it targeted the part of a computer that did complex math. Think of it as like floating point math, like the really, really, details, base, hard calculation stuff that most of the time you never deal with. And I've never run into a piece of malware that does that. Jax says he's never seen malware that messed with high precision math. Most spy malware is designed to steal data or like in Stuxnet, make things go haywire. But this one was basically telling the computer to plus two equals five. So at this point, Jax had found fast 16 buried in a cyber library based on a hunch that it was something to pay attention to. And Vitaly had confirmed it was because who messes with math? And maybe more importantly, whose math were they messing with? Who is running high precision calculations back in 2005 doing something so interesting that it got somebody to build a super specific custom piece of malware to modify and mess with their workloads? Talking about this thing, screams special. Like it screams unique, it screams groundbreaking. And I think what's most excruciating about it is that the mystery won't yield. Like you're just kind of have to keep pushing and say, okay, why? After the break? Okay. I guess we're back to the trenches of like, okay, how do we nail this thing? Jax puts all the pieces together. So, Jax and Vitaly still separated by a 12 hour time difference set out to answer their next question. Whose math was fast 16 designed to target? And pretty quickly, they come upon a major clue by looking at a rules engine embedded in fast 16's code. Like a list of instructions, basically if then rules. If fast 16 see something happen on the computer, then it goes, Oh, I've recognized this thing. What does my rule engine say? Oh, if I find this thing, then I need to change these six bytes into these six other bytes. If I find this thing, then I need to set this thing back into whatever the old value was. If I find this thing, right? But what the hell do those six bytes represent? So this start scanning old systems and software from way back in the day looking for those strings of bytes. Jax says it was like looking through a mathematicians notebook of scribbles for a particular string of numbers, which is not easy. And it's not like old code just exists out in the wild. But eventually they do find a few pieces of software that contains some of those same strings of six bytes, which all had to do with complex physics modeling. Like how to design a car that'll crumple safely when it crashes or a bridge that will withstand an earthquake. For Vitaly, the idea that someone was targeting calculations that were supposed to keep us safe was incredibly disturbing. Like do they have limits reading? It's just a new type of kind of evil ideas. I felt that the target was scientists, civil engineers, corrupt their calculation results, and that would eventually produce risks for lives of others. So I was terrified. Like why would people do that? Very soon they had a breakthrough that kind of answered the question. Jax was searching around for one of those pieces of software. It's called LS Dyna. It's short for liver more software dynamic analysis. Something that I run into right away, as I'm looking up LS Dyna, is this report by the good ISIS. That's what they call themselves. I don't know what ISIS stands for. It's some kind of think tank. The good ISIS. Institute for some something or other. And the good ISIS has this report saying, if you look back at this research that Iranian scientists have been publicly putting out, you can see that they were using software that they shouldn't have been using. They knew that these guys had this piece of software LS Dyna. Yeah, and what's interesting is the example they put for LS Dyna is trying to figure out the right explosive materials for nuclear payloads. In other words, this documentation from the Institute of Science and International Security seemed to suggest that the software Fast 16 was supposed to mess with was being used by Iranian nuclear scientists to maybe design nuclear bombs. So that was the software that the Fast 16 malware was likely targeting. Telling it, if you find these bites, change them to these other ones. But why change those specific bites? What would changing the math in the software achieve? To solve that part of the puzzle, they had to get their hands on that software the Iranian scientists were using. A very bespoke piece of physics modeling software released decades ago. Very much not on the app. story. Did you pay for it? No, you can't buy it. You can't just buy it. And moreover, people don't love it when you're like, hey, uh, do you happen to have a copy of your software from 21 years ago? I'm like, why? Don't worry about it. Just, uh, you know, so you've got to get your hands on this thing somehow. And Jackson Patali did. What they found was that fast 16 was designed to hide and sign to his computers and do nothing. Basically, to keep watch, to wait for L. S. Dina to get installed. At that point, it would stay low-key. Until it saw the computer doing these very specific tests that only someone developing a nuclear warhead would be doing. Had to do with the pressure calculations to simulate a nuclear explosion. And that is when fast 16 would do its mayhem. At the point when the engineer has got near the pressure they needed, fast 16 would throw those calculations off by changing the math. The old two plus two equals five trick. And furthermore, it was designed to spread from computer to computer. The idea being that if you, if I come to this computer and I run this simulation workload and go, hey, those results don't look right. Let's go try this other computer and you go and you run it in the other one. That too will give you the, the right wrong answer. The exact same wrong answer. Exactly. And so the idea was to drive these people nuts, right? Like you go and like, it's right math, wrong answer, right formula, wrong answer over and over everywhere you go. And you probably don't know that it's wrong until you then go and try to do another thing with it and you go, dammit, this thing is not working, right? Like it's devious in the cunning of this attack. It's truly fascinating because at some point I think before you ever consider that the computers are wrong. Yeah. You almost certainly look at these scientists and go, maybe you guys are clowns. Maybe you guys don't know what the hell you're doing. Jags and Vitaly were flabbergasted by the sophistication and the technical prowess of this malware from decades ago. Not just the Cody parts, but also the deep knowledge of nuclear physics. And after so many late nights of being haunted by Fast 16, Jags and Vitaly were finally able to announce in April of this year that Fast 16, which they'd started looking to on a hunch, was indeed a major cyber weapon whose mission seemed like it was to sabotage Iran's nuclear development program. Was it worth the wait? Oh, absolutely. I mean, walking around with this like bag of open questions, right? Yeah, there are still some unknowns. Number one, we don't know definitively that this was targeting Iran. For example, North Korea also had nuclear ambitions at that time. You look back, you go, well, North Korea was having a whole lot of problems with their missile program back then. We don't know where all these things were being used. We just know of one target that they definitely use this kind of stuff against, which is Iran. You're that confident? Uh, look, let's, let's put it a different way, right? We've never, ever, ever, ever, ever, ever heard of anybody doing this kind of cyber sabotage anywhere for anything, other than the Iranian nuclear program in the same era as when Fast 16 is developed. Thing number two, we don't know who did this. It has echoes of Stuxnet, which is widely reported to have been deployed by the US and Israel. But when we reached out to the NSA and the CIA and the Israeli defense forces and asked them, was Fast 16 you? They didn't deny it. They didn't confirm it either. Yeah, that's true too. The IDF never got back to us and the other said basically, sorry, but we have nothing to offer you on this. Jags for his part. Also checked in with them. Before you publish, do you reach out to the US and Israeli intelligence community and ask them, are we going to blow your cover? Yeah, um, yeah, but I won't go too far into that, right? Like most of the time, we are good collaborators and good friends. Do these meetings happen in person? Was there any pushback this time? No, meaning we're not worried about you blowing our cover. You weird paleontologist. This stuff is 20 years old. Right. And the third thing we don't know is why the NSA wrote in reference to Fast 16, the instructions, nothing to see here. Carry on. Was that like with a wink? One day when this stuff is declassified, we might get an answer to all three of those questions. But we're much less likely to figure out did Fast 16 change history? Jack says he sure was deployed because he couldn't have found it otherwise. But like, did it slow down Iran's or someone's nuclear program? Did it bring them to the bargaining table? Yeah, did it prevent nuclear war and the last enduring mystery? How did Fast 16 mess with the minds of the scientists who encountered it? Like I have this picture in my head of the nuclear scientists in Iran working on this project of intense national significance. Presumably, their boss's boss was constantly giving updates to Iran's president or the Ayatollah. And these scientists would have been doing their experiments, right? And then infuriatingly, getting the wrong answer is epistemological warfare. What you would call this? If I had called it that, they would have said I was just being pretentious. I wouldn't have allowed myself that as a repentant philosopher. Yeah, but as a repentant philosopher. Yeah, sure. I think epistemological warfare is a fascinating way to frame it. Break that out a little before me. Well, I think we take for granted how much we take for granted. Certainty, people think that certainty is a matter of coherent deduction that somehow you're sitting here and you have this perfect cohesive worldview. That's not actually how it works. That's not how anything works. If you questioned everything in your life, you would be paralyzed, right? If you question that when you get out of bed, you don't know if the floor is going to hold you, right? You wouldn't be able to function. Jags told us about an interaction he recently had with Vitaly that kind of brings this home. They were in Singapore where Vitaly lives on their way to a hacker conference to present their fast 16 research. He gets us on a train and he goes, "Oh, look, it's a driverless train." The train just, you know, and I can't remember. We were talking about something to do with fast 16. He stops and he goes, "I mean, this is precisely the kind of system that you would degrade with this kind of attack." You know, there was a collision and they said there was no cyber attack involved and then we look at each other and we go, "You know, you kind of shrug and you go, "Well, as far as we know," right? What I find fascinating is that these experts who spend their lives staring at computers, who know their capabilities more than anyone, are also some of the most skeptical people when it comes to trusting computers. Does that ever get to you? No. No, I don't know. I'm telling you, man, I'm not wired quite the right way. To me, questioning everything does seem paralyzing, but they seem well attuned to life in the computer age, life in the time of epistemological warfare. If you are an intelligence operative who has info on a clandestine operation and want to tell me about it, you can reach me at you know. Who am I kidding? You know how to find me. And if you live outside the United States, we also need your help. For Planet Money Summer School, we are scouring the world for the most interesting, surprising economic ideas that should spread. Think like a different way to do taxes, a mega project that came in under budget. Somehow rent is cheap. Get in touch and tell us about an idea the world should know about. Email us at planet money at mpr.org and put summer school in the subject. We might use your idea on the podcast. This episode was produced by Willa Rubin and edited by Marian McEun with editing help from the great Jess Jank. It was fact checked by Charlotte Isador, an engineer by Quacy Lee. Alex Goldmark is our executive producer. Special thanks to the research team at Semantic who also dug into Fast 16, Andy Greenberg from Wired who broke the story, Kim Zetter who wrote the definitive book about Stuxnet and David Albright of, and I can't believe I'm saying this, the good ISIS. Which now I know stands for the Institute for Science and International Security. Jack's has a podcast with also a funny name. It's called the Three Buddy Problem. I'm Nick Fountain and I'm Erica Barris. This is NPR. Thanks for listening.

Podcast Summary

Key Points:

  1. A hidden cyber war between the U.S. and Iran, centered on sophisticated malware like Fast 16, has been ongoing for decades, with cyber sabotage playing a key role in undermining nuclear development.
  2. Fast 16, a highly specialized piece of malware, was designed to manipulate high-precision mathematical calculations in physics modeling software—specifically targeting Iranian nuclear scientists using tools like LS Dyna to simulate explosive materials.
  3. The malware operated silently, spreading across systems to corrupt simulation results, creating a pervasive illusion of error that could drive scientists into confusion and distrust, representing a form of epistemological warfare aimed at destabilizing scientific confidence.

Summary:

S. and Iran has been unfolding for years, with cyber attacks like Fast 16 serving as a stealthy, high-stakes weapon in the broader nuclear standoff. Unlike traditional attacks, Fast 16 did not steal data or destroy systems—it manipulated complex mathematical calculations used in scientific simulations, particularly in software like LS Dyna, which Iranian scientists used to model nuclear explosives.

The malware remained undetected for decades, only recently uncovered by cyber paleontologist Juan Andres Guerrero Sade (Jags) and researcher Vitaly Kamluk, who identified its unique targeting of precision math. Their investigation revealed that Fast 16 was designed to subtly corrupt results, causing scientists to question their own work and potentially destabilize key research. This represents a new form of "epistemological warfare"—an attack not on infrastructure but on the foundations of knowledge and trust.

S. or Israeli intelligence—have not confirmed or denied involvement. Despite the uncertainty, experts believe Fast 16 was a significant, if covert, intervention in the nuclear arms race.

Its existence and sophistication underscore how digital tools can be used to disrupt scientific progress and instill doubt, reshaping how we understand modern warfare. The case highlights the enduring power of cyber espionage to influence global security long after the initial attack.

FAQs

Fast 16 is a highly sophisticated, obscure cyber weapon from the mid-2000s designed to sabotage complex mathematical calculations in software. It is significant because it was likely targeting Iran's nuclear program by corrupting critical physics simulations used to design nuclear warheads.

Researchers found Fast 16 in a leaked NSA malware list, where it stood out due to a cryptic instruction: 'nothing to see here, carry on.' Unlike other malware, it didn't steal data or cause visible damage; instead, it manipulated high-precision math, suggesting a targeted and devious attack on scientific calculations.

Fast 16 targeted software like LS-Dyna, used for complex physics modeling in engineering—such as simulating car crashes or earthquake-resistant bridges. Its targeting of such software suggests it was aimed at scientists working on nuclear weapon design, as those simulations could involve explosive pressure calculations.

It is believed that Fast 16 was designed to sabotage Iran’s nuclear research by producing consistent, incorrect results in simulations. While we can’t confirm it changed history, its existence and sophistication suggest it could have contributed to confusion and delays in their nuclear program.

No definitive attribution exists, but the malware shows echoes of Stuxnet and is believed to have been developed by a nation with nuclear ambitions—likely the U.S. or Israel. However, the U.S. and Israel have neither confirmed nor denied involvement, leaving the origin uncertain.

Fast 16 caused scientists to receive repeated, incorrect results, creating a state of epistemological warfare—doubt in the reliability of their own tools and results. This could have destabilized scientific confidence, leading researchers to question their work or methods, even when no real error existed.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.