A 2017 experiment showed that malicious code could, in principle, arrive through DNA itself. Iliya Fayans went looking for the more practical attack path and found it inside the software that laboratories already trusted to run their sequencing machines.
In 2017, computer scientists at the University of Washington set out to build a computer virus out of DNA. They wrote a piece of malware, rewrote it in the four letters of the genetic code, and had the physical strand synthesized.
Nearly all of their attempts fell apart, but eventually one strand survived. When a sequencer processed the strand and fed the output to its analysis software, the malware executed and handed the team control of the computer: the first hack, as far as anyone knew, pulled off by a molecule.
The research team was candid about the caveats. They had planted the software flaw themselves, and a real attack would be much harder than a controlled test.
But the experiment showed that DNA entering a sequencing pipeline could expose a previously overlooked attack path.
Sequencing systems, designed for the interpretation and analysis of molecules, were now pathways through which malicious actors might reach hospitals, laboratories, and medical workspaces.
For Iliya Fayans, then a master’s student at Ben-Gurion University of the Negev, the experiment was inspiring.
Serving in the IDF’s elite Unit 8200 while completing his master’s degree, he wanted to dive into something that sat between his own work and that of his partner, whose biological research made extensive use of next-generation sequencing (NGS).
“At the time, it was a new and revolutionary way to do genetic sequencing,” Fayans recalled. “However, when you introduce novel technology, it’s really interesting (from a cybersecurity perspective) to gauge whether it has any cyber vulnerabilities and whether it introduces some new attack surface.”
Rather than try to reproduce the DNA attack, Fayans turned his attention to the machine itself. He wanted to understand the sequencing system as an attacker would: as a collection of controllers, interfaces, and layers of software.
Inside, Fayans mapped the circuit boards, identified the systems running on them, and extracted their firmware.
The primary system used an ARM processor the same broad family of processors found in smartphones and ran software of its own. Following those connections led Fayans beyond the sequencer itself.
To operate the machine, a laboratory had to install software supplied by the manufacturer onto an ordinary computer, some of it running with substantial privileges so it could communicate directly with the hardware.
Buying a biological instrument, in other words, also meant introducing a new body of highly trusted code into the laboratory’s existing computer systems.
“You have very high-privileged software,” Fayans said, “which is not very well audited because it’s written by a biology firm whose core business is creating [a] gene sequencer.”
When Fayans began examining that software, the concern became concrete. He found network interfaces exposed far more broadly than necessary, allowing the software to accept communications from places its designers had seemingly never expected an attacker to reach.
The weakness mattered because the software sat between two worlds: an ordinary computer on one side and specialized medical equipment on the other.
Finding the opening, however, was only the beginning. Fayans wanted to know whether an attacker with very little access could actually traverse that boundary and take control of the device.
In one proof of concept, he showed that an attack could begin with code running inside the tightly restricted sandbox of a web advertisement.
Even from that low-privilege environment, the weaknesses in the sequencing software allowed the attack to travel through successive layers until it reached the machine itself.
Once there, Fayans found he could interfere directly with its operation. “You can manipulate its results,” he recalled. “You can stop it, you can edit the results it reports… basically, you can control it however you like.”
That was ultimately the scenario Fayans cared about. The DNA-borne malware that first caught his attention was ingenious, but it required an attacker to manufacture a highly specialized biological payload.
His research suggested that the more dangerous path might be far more ordinary: exploit the software already trusted to control the device.
“For me, it was very interesting to show, you know, a malicious actor that wants to disable your whole health system,” Fayans said. “How far can they get if they decide that their entry point is this new device?”
Quite far, and from almost nothing. A sequencer bought to read genomes and the manufacturer’s software behind it were enough. The hospital’s guarded systems and its patient records stayed out of it.
The DNA experiment that first inspired Fayans had needed a lab, a synthesized strand, and a flaw its authors had planted. What he found in its place asked for none of that.
The weakness was ordinary, just high-privileged software a manufacturer had written and a lab had trusted on sight.
The device was new. The way in was old, and it arrives with every device a hospital wheels through its doors, each carrying its own trusted software.
Fayans followed one of them in. The next one is already on its way.
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…