Sign in

Jimmy Wylie

@mayahustle.com
818 followers 213 following 117 posts

I look for ICS threats, and spend a lot of time reverse engineering. Distinguished Malware Analyst @ Dragos. Lead Analyst on TRISIS and PIPEDREAM. He/Him

PostsRepliesMedia
Reposted by Jimmy Wylie
tmp0ut @tmpout.sh · 23/08/2026
We are pleased to release tmp.0ut 5 Volume! Get your viruses, rootkits, strange ELFs, weird machines, tiny files, cool art, and phresh beats here!! tmpout.sh/5/
tmp.0ut 5 Table of Contents - ANSI art featuring a list of 21 papers
19845
Jimmy Wylie @mayahustle.com · 07/08/2026
Dragos has a Vulnerability Analyst position open! job-boards.greenhouse.io/dragos/jobs/...
job-boards.greenhouse.io
Principal Vulnerability Analyst
United States
000
Jimmy Wylie @mayahustle.com · 05/08/2026
We have two malware analyst openings at Dragos! In many malware jobs, your work disappears into the void. But at Dragos, it's easy to see the impact of your work across the company and community. And you get to work on interesting cases across OT verticals. job-boards.greenhouse.io/dragos/jobs/...
job-boards.greenhouse.io
Associate Principal Malware Analyst
United States
035
Jimmy Wylie @mayahustle.com · 15/07/2026
I used to spend hours finding wrong answers to Linux issues on Reddit before giving up and figuring it out myself. Now, an LLM gives me the wrong answers instantly, boils the ocean, and forces me to manually solve the problem sooner. I feel so productive!
030
Jimmy Wylie @mayahustle.com · 27/05/2026
“The AI wrote it, so it must be good” is a trap, and a poor excuse to ignore a human edit. At the very least: - Rewrite the headings - Remove useless adverbs (AI loves “actually”) - Check that the flow of ideas is coherent. - Check for accuracy. (1/2)
110
Jimmy Wylie @mayahustle.com · 04/05/2026
My "Introduction to ICS Malware Analysis" workshop was accepted at the SANS ICS Security Summit. You'll learn about ICS malware by analyzing samples modeled on FrostyGoop and CRASHOVERRIDE. No prior RE experience needed. It's running twice: June 8 and June 10.
sans.org
SANS ICS Security Summit & Training 2026
Obtain hands-on, practical skills from the world's best instructors by taking a SANS course at SANS ICS Security Summit 2026.
030
Jimmy Wylie @mayahustle.com · 30/04/2026
Quoted in Dark Reading on the latest LotusWiper release by Kaspersky. I'm always glad when our team's expertise can reach a wide audience. We've seen an uptick in Wiper use since 2022, which makes sense. They're cheap to develop and effective at turning access into damage.
darkreading.com
Lotus Wiper Attack Targets Venezuelan Energy Firms, Utilities
An analysis of the destructive malware reveals extensive living-off-the-land (LotL) techniques and detailed strategies for the widespread data deletion.
010
Jimmy Wylie @mayahustle.com · 23/04/2026
ZionSiphon is an AI-generated, non-functional attempt at ICS malware. Malicious intent doesn't imply ability, and broken malware like this is a distraction when we have proven threats like VOLTZITE/Volt Typhoon out there hitting water utilities.: www.dragos.com/blog/zionsip...
dragos.com
ZionSiphon: Why This Malware Isn't A Credible ICS Threat
Dragos analyzed ZionSiphon and assessed it as non-functional OT malware. Here's why it poses no credible threat to dam desalination or critical infrastructure
195
Jimmy Wylie @mayahustle.com · 17/04/2026
Ironically, S4 dropped my talk on vibe coding ICS malware on the same day that non-functional AI-slop OT "malware" is making headlines. It’s hype “malware” distracting us from real threats. More to say, but it's Friday :) In the meantime, I hope you enjoy the talk.
youtube.com
Building FrostyGoop With The Help Of AI
How easy or hard is it for an attacker to build an OT attack platform such as FrostyGoop? Jimmy Wylie answered this question by developing, with the help of AI, a FrostyGoop attack platform. There were two caveats to this effort: 1. He built this from scratch without reusing any of the FrostyGoop
290
Jimmy Wylie @mayahustle.com · 08/04/2026
This blog nails some real problems with bringing AI into an organization in any industry, not just cybersecurity. The article brings up a human training issue that I've been pondering a lot. What does it look like to train a new reverse engineer with AI tools available?
sentinelone.com
The Implementation Blind Spot | Why Organizations Are Confusing Temporary Friction with Permanent Safety
Our new blog post explores the ‘cognitive rust belt’ — how AI friction masks skill loss and why organizations must act now.
210
Jimmy Wylie @mayahustle.com · 01/04/2026
TIL FLARE distributes educational content for free on GitHub. github.com/mandiant/fla...
github.com
GitHub - mandiant/flare-learning-hub: Free educational content on reverse engineering and malware analysis from the FLARE team · GitHub
Free educational content on reverse engineering and malware analysis from the FLARE team - mandiant/flare-learning-hub
043
Jimmy Wylie @mayahustle.com · 23/03/2026
"Claude hacks government" is as silly as saying "Metasploit hacked a hospital!" Blaming AI shifts responsibility away from the humans who orchestrate it, and confuses defenders into thinking they're up against some vague AI supervillain. AI hasn't changed the fundamental problem. 1/2
173
Jimmy Wylie @mayahustle.com · 11/03/2026
I had a great time on Jim's podcast discussing malware analysis, reverse engineering, working at Dragos, and a little bit of my personal history. www.youtube.com/watc...
021
Jimmy Wylie @mayahustle.com · 10/03/2026
If you're trying to run Remnux on KVM by loading the OVA: For network access: KVM changes the network adapter name, so change the config in /etc/netplan, replacing the old adapter (like enss0) with the new one and reboot. Use networkctl to find the non-loopback adapter name (like en1ps0) 1/3
100
Jimmy Wylie @mayahustle.com · 19/02/2026
I earned my first CVE credit (CVE-2025-7676) for helping with a Windows ARM vuln. So, to commemorate the credit, my coworker, Reid, presented me last week with a Trophy of Perpetual Futility, because there’s always more work to do. raw.githubusercontent.com/reidmefirst/...
Photo of smiling Jimmy holding a gold and red trophy in right hand. The top of the trophy is a gold statue of a king holding a sceptre. The king is standing on a red column, with a white base and a gold plaque.Hand holding a trophy of king standing on a column. At the base of the column is the text:
‘MY NAME IS OZYMANDIAS, KING
OF KINGS; LOOK ON MY WORKS, 
YE MIGHTY, AND DESPAIR
1120
Jimmy Wylie @mayahustle.com · 17/02/2026
The Dragos 2026 Year In Review Report is live: 3 new threat groups, updates from 3 of our more active threat groups, and (my personal favorite) coverage of a subset ICS-related capabilities that we found last year.
dragos.com
Dragos 2026 OT Cybersecurity Report: a Year in Review
Get the latest OT threats, vulnerabilities, and lessons learned from real-world incidents in this year’s 2026 OT Cybersecurity Report.
042
Jimmy Wylie @mayahustle.com · 10/02/2026
I've spent a lot of time reversing ICS malware. Recently, I've been building it with AI tools. While there's been plenty of commentary and news about AI and malware, I'm excited to share what I learned actually trying to build some at S4x26. Stage 2, Feb 24, 12pm.
021
Jimmy Wylie @mayahustle.com · 30/01/2026
CERT.PL's report on the attacks against Polish infrastructure. A full destructive playbook enabled by default credentials: firmware corruption, wipers, factory resets, even booted Tiny Core Linux on KVM to DD-wipe servers. The report is excellent work.
cert.pl
Energy Sector Incident Report - 29 December 2025
CERT Polska presents a report on the analysis of an incident in the energy sector that occurred on 29 December 2025. The attacks were destructive in nature and targeted wind and photovoltaic farms, a large combined heat and power plant, and a company from the manufacturing sector. The publication aims to raise awareness of the risks associated with sabotage in cyberspace.
010
Jimmy Wylie @mayahustle.com · 29/01/2026
I know I'm feeling stressed out when I go back to reading Thich Nhat Hahn. His teachings calm me, and I need that reminder that happiness is available in any moment despite circumstance. I'm not even Buddhist. or maybe I am? He'd probably say the distinction isn't important.
041
Jimmy Wylie @mayahustle.com · 27/01/2026
This is the first known attack on DERs. Attackers compromised RTUs at 30 different sites. The report has an overview, defensive guidance, and a comparison to past ELECTRUM ops. Hats off to CERT Polska for leading the charge, and kudos to our Intel team for the hard work.
hubs.la
Intel Report | ELECTRUM: Cyber Attack on Poland's Electric System 2025 | Dragos
A 2025 cyber attack on Poland’s electric system highlights both risk and resilience in modern power grids. Download the report →
052
Jimmy Wylie @mayahustle.com · 16/12/2025
I spent a couple months arguing with Claude and Copilot while building FrostyGoop variants for DNP3 (and Modbus), keeping detailed notes on what worked and what didn't. At S4, I’ll share my honest assessment of these tools and how they might lower barriers to ICS malware dev. See you in Miami!
031
Reposted by Jimmy Wylie
Iceman @iceman1001.bsky.social · 11/11/2025
Finally sharing what’s been under wraps for months. Adam Foster and I tore into HID SEOS to build the first open-source implementation for Proxmark3. This is our Black Hat Asia 2025 story → www.youtube.com/watch?v=mnhG... #RFIDHacking #SEOS #CyberSecurity
youtube.com
Dismantling the SEOS Protocol
YouTube video by Black Hat
051
Jimmy Wylie @mayahustle.com · 17/11/2025
We have a job opening in our Community Defense Program (CDP) which gives small utilities free access to the Dragos Platform. This opening is a chance to do some truly meaningful work for the community. Job Description: job-boards.greenhous... CDP Description: www.dragos.com/commu...
job-boards.greenhouse.io
Associate Project Manager
Hanover, MD
091
Jimmy Wylie @mayahustle.com · 14/11/2025
Had a great time presenting at LSU this week on hunting and analyzing Go and Python malware samples while hunting for ICS malware. For those who couldn't make it, you can catch a recording of this talk from Hou.Sec.Con last month with @sam-hans0n.bsky.social www.youtube.com/watc...
021
Jimmy Wylie @mayahustle.com · 11/11/2025
A lot of folks have reached out about Socket’s recent report on a supply chain attack using malicious NuGet packages to target Siemens S7 protocol and other PLCs. This is not a supply chain attack in the traditional sense. 1/6
132
Jimmy Wylie @mayahustle.com · 31/10/2025
Learning Modbus is basically this conversation: “I live at 502 Westport Ave.” “Sweet, I’m sending you a package.” “Wait! If you talk to the mail carrier, my address is 501 Westport Ave.” “Oh. So, you live at 501 Westport?” (1/2)
121
Jimmy Wylie @mayahustle.com · 27/10/2025
I'm speaking at S4x26 on creating a FrostyGoop-style tool using AI. This experiment has been a good avenue for tackling a few questions I've had about AI-enabled software development. Most importantly, just how easy is it? I'm excited to share what I learn come February! 1/2
140
Jimmy Wylie @mayahustle.com · 24/10/2025
I had a great experience at #FTSCon on Monday. Both the speakers and the audience are such high caliber that an interesting discussion can be had at any point during the day. The information presented is useful for folks in any technical aspect of cybersecurity, not just DFIR folks. 1/3
121
Jimmy Wylie @mayahustle.com · 21/10/2025
MacOS 26 really kills the T2 Intel Macs. It's technically compatible, but the experience is a drag, especially just after boot with all the indexing. I'm going to put a T2 Linux distro on this thing, and hope it improves the experience. I refuse to throw away a computer that's barely 5 years old.
100
Jimmy Wylie @mayahustle.com · 18/10/2025
My cousin is raising money to go to the MLS Next Youth Showcase. You buy tasty popcorn, and the money funds the trip with an option to donate to teachers. Check it out and support a good cause! I just bought a bunch for our weekly board game meetup :) s.dgpopup.com/0o409evs/rp
s.dgpopup.com
Giovanni’s Pop-Up Store - Double Good Online Fundraising
Click here to buy our delicious popcorn and 50% of your purchase benefits this fundraiser. #doublegood #dgpopup
000
Jimmy Wylie @mayahustle.com · 16/10/2025
Our DEF CON33 ICS Village talk is now on YouTube! @sam-hans0n.bsky.social and I share stories of malware we discovered while searching for ICS threats, and discuss our approach to assessing their reputation. Don't Cry Wolf: Evidence-Based Assessment of ICS Threats
youtube.com
DEF CON 33 - Don’t Cry Wolf: Evidence based assessments of ICS Threats - Jimmy Wylie & Sam Hanson
CS Malware is rare. Yet, ICS Malware like FrostyGoop and TRISIS, and related discoveries like COSMICENERGY, were all found on VirusTotal, so analysts still hunt for novel ICS Malware in public malware repositories. In the process, they discover all kinds of tools: research, CTFs, obfuscated nonsense
065
Jimmy Wylie @mayahustle.com · 10/10/2025
In ICS, malware analysis can feel like archaeology. I started the week with a 13 year old sample and ended the week with @sam-hans0n.bsky.social pinging about an 18 years old sample. So, save your old Windows ISOs and VMs, you might need them!
141
Jimmy Wylie @mayahustle.com · 08/10/2025
Thanks to @cybrseccon.bsky.social / HOU.SEC.CON for having us last week. (and for a really unique speaker gift!) The conference has grown into a valuable industry event, and I'm looking forward to the next one! ICYMI, we posted resources from our talk here: gist.github.com/maya...
Selfie of Jimmy holding a belt buckle. The belt buckle is a western style buckle. The buckle has Speaker along the top, an image of the HOUSECCON flying saucer logo below it, and an astronaut riding a horse. The bottom of the buckle has the year, 2025. The rest of the buckle is decorated with filigree.
040
Jimmy Wylie @mayahustle.com · 07/10/2025
Well.. I can’t help but listen to this. 🤘It’s weird, and I like it. deathmeta.bandcamp.com/album/malware
deathmeta.bandcamp.com
MALWARE | DEATH META
10 track album
110
Jimmy Wylie @mayahustle.com · 03/10/2025
The Difference Maker Awards are about contributions to the community, so they let the community decide. Voting ends on Wednesday, October 8. If you haven’t voted yet, please consider it! (I’m a finalist in the ICS category alongside some amazing industry leaders) www.sans.org/about/awards...
sans.org
SANS Difference Makers Awards
These are the people and organizations acknowledged by the SANS Institute for their oustanding contributions to cyber security each year.
030
Jimmy Wylie @mayahustle.com · 02/10/2025
@xorhex.bsky.social Good work on this BinaryNinja plugin! It really came in handy the other day when I was trying to type and label some dynamic api resolution code. Someone in Binja’s slack recommended it. Rock on! github.com/xorhex/binja...
github.com
GitHub - xorhex/binjaextras
Contribute to xorhex/binjaextras development by creating an account on GitHub.
140
Jimmy Wylie @mayahustle.com · 23/09/2025
I was nominated for a SANS DMA - ICS/OT Practitioner of the Year, along with some impressive folks. Reverse engineering ICS malware is hard, but communicating the results is harder. Grateful to SANS for recognizing my work in this area. Link below. Voting ends on Oct. 8.
sans.org
SANS Difference Makers Awards | SANS Institute
These are the people and organizations acknowledged by the SANS Institute for their oustanding contributions to cyber security each year.
030
Jimmy Wylie @mayahustle.com · 19/09/2025
Earlier this year, I complained about how many hyphens there were in Unicode. It turns out a Soft Hyphen was abused last year in a creative PHP exploit. CVE-2024-4577 exploits Windows’ Best Fit character conversion feature that auto-converts certain Unicode characters to ASCII equivalents. 1/3
131
Jimmy Wylie @mayahustle.com · 09/09/2025
Oh hey, Hex-Rays released IDA 9.2. There are new Go features like support for multiple return values to annotate Go function calls correctly. Jump Anywhere is a nice usability improvement supplanting the need to remember 5 keyboard shortcuts. hex-rays.com/blog/id... #idapro #reverseengineering
hex-rays.com
IDA 9.2 Release: Golang Improvements, New UI Widgets, Types Parsing and More
IDA 9.2: Smarter Go decompilation, new UI widgets, Xref Graph/Tree, LLVM-based type parser, debugger upgrades, and expanded processor support.
011
Jimmy Wylie @mayahustle.com · 04/09/2025
This is a great story about Donald Knuth and Doug McIlroy participating in a literate programming exercise and a hilarious example of different perspectives in problem solving from godfathers of Computer Science. Original post: hachyderm.io/@mweagle/115...
010
Jimmy Wylie @mayahustle.com · 03/09/2025
Sam Hanson and I are speaking at @hou-sec-con.bsky.social on hunting for Python and Go ICS-related malware. You'll learn playbooks for these cases and hear stories about malware targeting ICS in the past year. The talk is on October 1st, at 1 p.m., Track 1. I hope you can make it! #ICS #OTSecurity
040
Jimmy Wylie @mayahustle.com · 26/08/2025
Just read up on the IDA Domain API updates from Hex Rays. This on top of idalib is a nice step forward in usability. Def recommend checking out the All Things IDA video. Looking forward to seeing the use case spotlights that they’ll be publishing. youtu.be/IaOucXb033Q #idapro #reverseengineering
youtu.be
An introduction to the IDA Domain API
011
Jimmy Wylie @mayahustle.com · 25/08/2025
My reading list for the rest of the year, inspired by DEFCON 33 and the starting chapters of the first book: - Microcontroller Exploits - Goodspeed - Hack to the Future - Crose - Hardware Hacker - bunnie - Hardware Hacking Handbook - Van Woudenberg + O’Flynn - Art of Mac Malware (Vol 1+2) - Wardle
051
Jimmy Wylie @mayahustle.com · 24/08/2025
Eesh.. I know #ArchLinux can be difficult for folks, but this seems uncalled for. I hope they figure out who’s behind it. www.zdnet.com/article/arch...
zdnet.com
Arch Linux remains under attack as DDoS enters week 2 - here's a workaround | ZDNET
Something mysterious is happening to the popular Linux distro's website. Here's what we know so far.
011
Jimmy Wylie @mayahustle.com · 18/08/2025
You want @hermit.sh on your team. If you know of anything, send it their way.
020
Jimmy Wylie @mayahustle.com · 15/08/2025
Poland stopped a cyberattack that could have cut water supply to a major city yesterday. Cyberattacks against water is a troubling trend. Access to clean water is fundamental, and these types of attacks are direct threats to public health and safety. #ICS #OTsecurity www.reuters.com/en/p...
13216
Jimmy Wylie @mayahustle.com · 15/08/2025
Played “In the Footsteps of Marie Curie” tonight. More of a family game, light on the strategy, easy playing. Good one for folks just getting into independent #boardgames
060
Jimmy Wylie @mayahustle.com · 14/08/2025
I’m forcing myself to learn #BinaryNinja, and using an LLM to search through the user manual and learn the basics is a game changer. Questions about fonts, theming, basic shortcuts, and considerations coming from IDA all answered easily.
120
Jimmy Wylie @mayahustle.com · 13/08/2025
Like every other industry, criminals and state-backed groups have jumped on the AI bandwagon. I spent some time reading threat reports from Anthropic, Google, and Open AI. Here's some of what they found: - Malware and software dev in Python, C/C++, Go, Android (lang unspecified), and others. 1/3
100
Jimmy Wylie @mayahustle.com · 12/08/2025
GoResolver was already awesome. Now, they added string extraction and definition in IDA/Ghidra and RTTI parsing and application — two big Golang reversing pain paints. I can’t wait to try it out this week. Original post: infosec.exchange/@volexity/11...
032