Hacker is targeting DNA sequencer applications from Iranian IP address
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-5638 | Unauthenticated RCE in Apache Struts Jakarta Multipart parser CVE-2017-5638 is an improper input validation flaw (CWE-20) in the Jakarta Multipart parser of Apache Struts, in which the parser mishandles the Content-Type value of a file upload and allows malicious upload leading to remote code execution. It is triggered remotely without authentication by sending a crafted Content-Type header in a multipart request to a Struts endpoint; no valid upload or credentials are required. A successful attacker gains code execution in the security context of the application server, which typically enables host compromise, data theft, or ransomware deployment. Any organization running Apache Struts applications that use the Jakarta Multipart parser is affected; the provided data specifies only "Apache Struts" and gives no version ranges. Exploitation is confirmed in the wild: the flaw is listed in CISA KEV (added 2021-11-03) with known ransomware use, EPSS assigns it roughly a 100% exploitation probability (100th percentile), and no public PoC is catalogued in the source data. Do: Apply updates per vendor instructions: upgrade Apache Struts to the releases that fix this flaw (2.3.32 / 2.5.10.1 or later, per Apache advisory S2-045), and check for Struts jars bundled inside application packages and vendor appliances. Prioritize internet-facing apps, and as an interim mitigation validate or filter the Content-Type header on multipart requests. Because exploitation is in the wild and ransomware use is known, also review web and application server logs for evidence of successful compromise. | 9.8 | 100% | KEV ransomware PoC ×10 |
| masslikely hundreds of thousands of deployments (tens of thousands of Struts hosts were internet-exposed in public scans) | |
| CVE-2017-6526 | An issue was discovered in dnaTools dnaLIMS 4-2015s13. An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to unauthenticated command execution through an improperly protected administrative web shell (cgi-bin/dna/sysAdmin.cgi POST requests). NVD description · AI analysis pending | 9.8 | 57% | PoC |
| — | |
| CVE-2017-6884 | Command Injection in Zyxel EMG2926 Router Diagnostics CVE-2017-6884 is an OS command injection flaw (CWE-78) in the diagnostic tools of Zyxel EMG2926 routers, located in the nslookup function. An attacker can trigger it through multiple vectors, notably by supplying a malicious ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI, causing attacker-controlled commands to execute on the router. Successful exploitation yields arbitrary command execution on the gateway, providing a foothold that can be used for further network compromise, including by ransomware operators. Any operator of a Zyxel EMG2926 router is affected, and many of these gateways were deployed through internet service providers. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-18 with known ransomware use, and EPSS estimates a 36.8% probability of exploitation within 30 days (98th percentile). Do: Per CISA's required action, apply mitigations per Zyxel's instructions or discontinue use of the product if mitigations are unavailable. Check whether the router's management interface, including the expert/maintenance/diagnostic/nslookup endpoint, is reachable from the WAN or untrusted networks and restrict access to it; monitor devices for signs of command execution or ransomware-related activity. Fixed firmware versions were not specified in the available data, so consult Zyxel's advisory for the appropriate upgrade path. | 8.8 | 37% | KEV ransomware PoC |
| largetens of thousands of deployed EMG2926 gateways, plausibly 10,000-100,000 affected systems; exact count unknown |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 2.176.78.42 | the research industry. The attacks were originated from the 2.176.78.42 IP address that is located in Iran. “From June 12 – 14, we |
Full article470 words · extracted from securityaffairs.com · click to collapse

Threat actors are targeting Web-based DNA sequencer applications leveraging a still-unpatched zero-day to take over the targeted systems.
Starting from June 12, 2019, the researcher Ankit Anubhav from NewSky Security, observed threat actors targeting Web-based DNA sequencer applications. The attackers are leveraging a still-unpatched zero-day vulnerability, tracked as CVE-2017-6526, to gain full control over the targeted systems.
The vulnerability in dnaLIMS was reported to the vendor in 2017, but it is still unpatched.
The attackers are scanning the Internet for dnaLIMS, a web-based application to handle DNA sequencing operations, these devices are used in the research industry. The attacks were originated from the 2.176.78.42 IP address that is located in Iran.
“From June 12 – 14, we saw regular attacks from 2.176.78.42 , an IP located in Iran, utilizing CVE-2017-6526, an issue in dnaTools dnaLIMS 4-2015s13. According to dnatools.com, dnaLIMS™ is a Web based bioinformatics LIMS that provides scientists and researches with hardware independent software tools for processing and managing DNA sequencing requests.” reads a blog post published by the expert.
The hackers leverage the vulnerability to bind a shell and take control of the web server.
Why DNA sequencing apps?
Attackers could be interested in stealing hashes of DNA sequences from the application’s database to resell them on the dark web or compromising servers to add to their botnet.
We cannot exclude that threat actor behind these attacks are using exploit available online at random in the attempt of compromise the large number of systems.
It is still unclear why attackers are targeting DNA sequencing apps, the number of these devices is limited (only a few tens of devices exposed online) and it is unlike that hackers want to use compromise systems to carry out DDoS attacks.
“The exact motives of the attacker(s) is unknown. Unlike an IPCamera or Router based IoT device, these are very unique devices installed in scientific ,academic and medical institutions. As a result,the number of such devices is not very high and might not help greatly in DDoS.” concludes the expert.
“However, successful exploitation and DNA theft in specific cases can be fruitful. Either it can be sold in black market, or a high profile attacker can actually be looking for a specific persons’ data.
We are not aware of a patch for this bug. In fact, when we had a look at the original disclosure by ShoreBreakSecurity, we saw a funny disclosure response by the vendor,indicating they don’t take DNA theft seriously.”
The expert also analyzed historical activity related to the attacker’s IP address and discovered that it was also associated with nmap scans and with the use of two other exploits for Zyxel routers (CVE-2017-6884) and for Apache Struts flaw (CVE-2017-5638).
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – DNA sequencer applications, hacking)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/87188/hacking/dna-sequencer-applications-attacks.html