Skip to main content
Planet Money

Can computer hackers get inside your mind?

29 min episode · 2 min read
·
Juan Andres Guerrero Sade

Episode

29 min

Read time

2 min

Topics

Fundraising & VC, Design & UX, Artificial Intelligence

AI-Generated Summary

Key Takeaways

  • Cyber Paleontology as Intelligence Method: Reverse engineering archived malware fragments from public repositories can reconstruct classified offensive cyber operations years after deployment. JAGS located FAST 16 using only its six-word NSA listing, then found the full code in a public malware library, demonstrating that declassified breadcrumbs can expose entire covert programs to civilian researchers.
  • AI-Assisted Reverse Engineering: When human analysis stalls on complex legacy code, deploying multiple AI models to independently verify findings accelerates breakthroughs. Researcher Vitaly Kamluk used AI models to double and triple-check his reverse engineering of FAST 16 after two weeks of isolated analysis, confirming conclusions he would not trust without machine corroboration.
  • Floating-Point Corruption as Sabotage Vector: FAST 16 targeted high-precision floating-point mathematics — a previously unseen malware category. Rather than stealing data or destroying hardware like Stuxnet, it silently altered specific six-byte values inside LS-DYNA physics simulations, producing consistently wrong pressure calculations while leaving all system diagnostics appearing completely normal.
  • Epistemological Warfare via Consistent Wrong Answers: FAST 16 was designed to spread across networked computers and return identical incorrect results on every machine, ensuring scientists who cross-checked their work encountered the same errors everywhere. This approach shifts suspicion from the computers to the scientists themselves, eroding institutional confidence in personnel rather than triggering technical investigations.
  • Stuxnet-Era Cyber Weapons Shared Architecture Without Shared Code: FAST 16 and Stuxnet originate from the same mid-2000s period and share similar structural architecture despite containing no overlapping code. Recognizing architectural fingerprints — not just code signatures — is a more reliable method for attributing cyber weapons to the same state-level development program or intelligence community.

What It Covers

Cybersecurity researcher Juan Andres Guerrero-Saade (JAGS) of SentinelOne uncovers FAST 16, a mid-2000s piece of malware buried in a leaked NSA list, and uses AI-assisted reverse engineering to reveal its likely mission: sabotaging Iranian nuclear weapons calculations by corrupting high-precision physics simulations.

Key Questions Answered

  • Cyber Paleontology as Intelligence Method: Reverse engineering archived malware fragments from public repositories can reconstruct classified offensive cyber operations years after deployment. JAGS located FAST 16 using only its six-word NSA listing, then found the full code in a public malware library, demonstrating that declassified breadcrumbs can expose entire covert programs to civilian researchers.
  • AI-Assisted Reverse Engineering: When human analysis stalls on complex legacy code, deploying multiple AI models to independently verify findings accelerates breakthroughs. Researcher Vitaly Kamluk used AI models to double and triple-check his reverse engineering of FAST 16 after two weeks of isolated analysis, confirming conclusions he would not trust without machine corroboration.
  • Floating-Point Corruption as Sabotage Vector: FAST 16 targeted high-precision floating-point mathematics — a previously unseen malware category. Rather than stealing data or destroying hardware like Stuxnet, it silently altered specific six-byte values inside LS-DYNA physics simulations, producing consistently wrong pressure calculations while leaving all system diagnostics appearing completely normal.
  • Epistemological Warfare via Consistent Wrong Answers: FAST 16 was designed to spread across networked computers and return identical incorrect results on every machine, ensuring scientists who cross-checked their work encountered the same errors everywhere. This approach shifts suspicion from the computers to the scientists themselves, eroding institutional confidence in personnel rather than triggering technical investigations.
  • Stuxnet-Era Cyber Weapons Shared Architecture Without Shared Code: FAST 16 and Stuxnet originate from the same mid-2000s period and share similar structural architecture despite containing no overlapping code. Recognizing architectural fingerprints — not just code signatures — is a more reliable method for attributing cyber weapons to the same state-level development program or intelligence community.

Notable Moment

When Kamluk and JAGS rode a driverless train in Singapore while discussing FAST 16, Kamluk noted that exactly this type of system could be degraded by such an attack. Both researchers paused, then acknowledged they could only say the infrastructure was safe "as far as we know."

Know someone who'd find this useful?

Episode Transcript

This message comes from Insperity, providing HR services and technology from payroll, benefits, and HR compliance to talent development. Learn more at insperity.com/hrmatters. This is Planet Money from NPR. On Friday, if all goes according to plan, representatives from The US and Iran will meet in Geneva to sign another sixty day ceasefire agreement. But the two sides still have not come to an agreement on what's been at the heart of this war and decades of conflict, Iran's development of nuclear weapons. Right. This conflict has been on again, off again for years. And while the most recent iteration has been very violent with bombs and blockades, there is a whole other almost entirely invisible war that The US and allies have been waging with Iran using cyber espionage or more accurately cyber sabotage, you know, computer viruses, malware. Recently, we heard a story about a piece of malware that might have been used in this invisible war that was diabolically cunning because it exploited weaknesses in computers, yes, but also maybe in the human psyche. The more I think about it, the more I think this must have driven people insane. But it also might have saved the world from nuclear destruction. We heard about this hack from someone whose job it is to identify computer hacks that could be a threat to all of us. What's your name? What do you do? My name is Juan Andres Guerrero Sade, which is why everybody calls me Jags. J a g s, Jags. His initials are shorter and cooler. Yeah. Actually, he is a pretty cool guy. He's got a faux hawk, sleeves of tattoos. He was on track to go get a PhD in philosophy, but now? I'm a security researcher, who I think would be the simplest term. I think some folks would say cyberpaleontologist. Cyber paleontologist. Like, he digs for the remnants of cyberattacks. JAGS works for a cybersecurity company called SentinelOne. It helps big companies like Samsung and the Golden State Warriors and the government protect their computers and networks. Yeah. Hacking is a whole industry. And defending against hacks is this whole other industry. JAGS just so happens to have the raddest job of all, which is dusting off old malware files buried deep on servers and reverse engineering how hackers got into systems in the first place and what they did when they got there so we can figure out how to defend against similar attacks in the future. And JAGS is kind of a big deal. There are actually a couple of pieces in the International Spy Museum in DC based on his cyber paleontology work. This is a little crude, but in the Jurassic Park movie, which paleontologist are you? As long as you you don't immediately default to Jeff Goldblum, and then you I was gonna go Jeff Goldblum. I But I think that he is like a chaos theory mathematician, which I I I think fits the bill. Right? …

Get the full transcript (5,193 words) + summary by email — free

One-time email with the complete transcript and AI summary of this episode. No account needed.

One email, no spam. We’ll also show you what SignalCast does.

Browse all Planet Money transcripts →

You just read a 3-minute summary of a 26-minute episode.

Get Planet Money summarized like this every Monday — plus up to 2 more podcasts, free.

Pick Your Podcasts — Free

Keep Reading

Books, tools, and gear mentioned in this episode

SignalCast may earn commission on purchases via these links.

Tools

  • it silently altered specific six-byte values inside LS-DYNA physics simulations, producing consistently wrong pressure calculations while leaving all system diagnostics appearing completely normal.

More from Planet Money

We summarize every new episode. Want them in your inbox?

Similar Episodes

Related episodes from other podcasts

Explore Related Topics

This podcast is featured in Best Finance Podcasts (2026) — ranked and reviewed with AI summaries.

Read this week's AI & Machine Learning Podcast Insights — cross-podcast analysis updated weekly.

You're clearly into Planet Money.

Every Monday, we deliver AI summaries of the latest episodes from Planet Money and 192+ other podcasts. Free for one show.

Start My Monday Digest

No credit card · Unsubscribe anytime