Sign in

Jimmy Wylie

@mayahustle.com
818 followers 213 following 117 posts

I look for ICS threats, and spend a lot of time reverse engineering. Distinguished Malware Analyst @ Dragos. Lead Analyst on TRISIS and PIPEDREAM. He/Him

PostsRepliesMedia
Reposted by Jimmy Wylie
tmp0ut @tmpout.sh · 23/08/2026
We are pleased to release tmp.0ut 5 Volume! Get your viruses, rootkits, strange ELFs, weird machines, tiny files, cool art, and phresh beats here!! tmpout.sh/5/
tmp.0ut 5 Table of Contents - ANSI art featuring a list of 21 papers
19845
Jimmy Wylie @mayahustle.com · 07/08/2026
Dragos has a Vulnerability Analyst position open! job-boards.greenhouse.io/dragos/jobs/...
job-boards.greenhouse.io
Principal Vulnerability Analyst
United States
000
Jimmy Wylie @mayahustle.com · 05/08/2026
We have two malware analyst openings at Dragos! In many malware jobs, your work disappears into the void. But at Dragos, it's easy to see the impact of your work across the company and community. And you get to work on interesting cases across OT verticals. job-boards.greenhouse.io/dragos/jobs/...
job-boards.greenhouse.io
Associate Principal Malware Analyst
United States
035
Jimmy Wylie @mayahustle.com · 15/07/2026
I used to spend hours finding wrong answers to Linux issues on Reddit before giving up and figuring it out myself. Now, an LLM gives me the wrong answers instantly, boils the ocean, and forces me to manually solve the problem sooner. I feel so productive!
030
Jimmy Wylie @mayahustle.com · 27/05/2026
- Ask yourself “Does this sound like me?” (Or whatever voice is required) Otherwise, your writing will sound the same as all the other copy-pasted AI slop, and you risk having your work ignored. (2/2)
000
Jimmy Wylie @mayahustle.com · 27/05/2026
“The AI wrote it, so it must be good” is a trap, and a poor excuse to ignore a human edit. At the very least: - Rewrite the headings - Remove useless adverbs (AI loves “actually”) - Check that the flow of ideas is coherent. - Check for accuracy. (1/2)
110
Jimmy Wylie @mayahustle.com · 04/05/2026
My "Introduction to ICS Malware Analysis" workshop was accepted at the SANS ICS Security Summit. You'll learn about ICS malware by analyzing samples modeled on FrostyGoop and CRASHOVERRIDE. No prior RE experience needed. It's running twice: June 8 and June 10.
sans.org
SANS ICS Security Summit & Training 2026
Obtain hands-on, practical skills from the world's best instructors by taking a SANS course at SANS ICS Security Summit 2026.
030
Jimmy Wylie @mayahustle.com · 30/04/2026
Quoted in Dark Reading on the latest LotusWiper release by Kaspersky. I'm always glad when our team's expertise can reach a wide audience. We've seen an uptick in Wiper use since 2022, which makes sense. They're cheap to develop and effective at turning access into damage.
darkreading.com
Lotus Wiper Attack Targets Venezuelan Energy Firms, Utilities
An analysis of the destructive malware reveals extensive living-off-the-land (LotL) techniques and detailed strategies for the widespread data deletion.
010
Jimmy Wylie @mayahustle.com · 23/04/2026
ZionSiphon is an AI-generated, non-functional attempt at ICS malware. Malicious intent doesn't imply ability, and broken malware like this is a distraction when we have proven threats like VOLTZITE/Volt Typhoon out there hitting water utilities.: www.dragos.com/blog/zionsip...
dragos.com
ZionSiphon: Why This Malware Isn't A Credible ICS Threat
Dragos analyzed ZionSiphon and assessed it as non-functional OT malware. Here's why it poses no credible threat to dam desalination or critical infrastructure
195
Jimmy Wylie @mayahustle.com · 17/04/2026
Ironically, S4 dropped my talk on vibe coding ICS malware on the same day that non-functional AI-slop OT "malware" is making headlines. It’s hype “malware” distracting us from real threats. More to say, but it's Friday :) In the meantime, I hope you enjoy the talk.
youtube.com
Building FrostyGoop With The Help Of AI
How easy or hard is it for an attacker to build an OT attack platform such as FrostyGoop? Jimmy Wylie answered this question by developing, with the help of AI, a FrostyGoop attack platform. There were two caveats to this effort: 1. He built this from scratch without reusing any of the FrostyGoop
290
Jimmy Wylie @mayahustle.com · 08/04/2026
This blog nails some real problems with bringing AI into an organization in any industry, not just cybersecurity. The article brings up a human training issue that I've been pondering a lot. What does it look like to train a new reverse engineer with AI tools available?
sentinelone.com
The Implementation Blind Spot | Why Organizations Are Confusing Temporary Friction with Permanent Safety
Our new blog post explores the ‘cognitive rust belt’ — how AI friction masks skill loss and why organizations must act now.
210
Jimmy Wylie @mayahustle.com · 01/04/2026
TIL FLARE distributes educational content for free on GitHub. github.com/mandiant/fla...
github.com
GitHub - mandiant/flare-learning-hub: Free educational content on reverse engineering and malware analysis from the FLARE team · GitHub
Free educational content on reverse engineering and malware analysis from the FLARE team - mandiant/flare-learning-hub
043
Jimmy Wylie @mayahustle.com · 23/03/2026
Capable attackers are still the threat, not the AI. The defenses we've been preaching for years still work. Stop worrying about AI. Instead, change your default passwords and enable MFA. 2/2
020
Jimmy Wylie @mayahustle.com · 23/03/2026
"Claude hacks government" is as silly as saying "Metasploit hacked a hospital!" Blaming AI shifts responsibility away from the humans who orchestrate it, and confuses defenders into thinking they're up against some vague AI supervillain. AI hasn't changed the fundamental problem. 1/2
173
Jimmy Wylie @mayahustle.com · 11/03/2026
I had a great time on Jim's podcast discussing malware analysis, reverse engineering, working at Dragos, and a little bit of my personal history. www.youtube.com/watc...
021
Jimmy Wylie @mayahustle.com · 10/03/2026
Afterwards, if you try to use remnux install, it will again break the vm tools inside the VM. I'm unsure the cause. I'm avoiding it for now. 3/3
000
Jimmy Wylie @mayahustle.com · 10/03/2026
Remnux docs say to run "remnux install" after loading into KVM to install spice and other tools. When I do that, the VM gets worse: cursor disappears, resolution gets jacked. Instead, simply installing spice-vdagent using apt gets you dynamic resolution and copy-paste, and a nicer to use VM. 2/3
100
Jimmy Wylie @mayahustle.com · 10/03/2026
If you're trying to run Remnux on KVM by loading the OVA: For network access: KVM changes the network adapter name, so change the config in /etc/netplan, replacing the old adapter (like enss0) with the new one and reboot. Use networkctl to find the non-loopback adapter name (like en1ps0) 1/3
100
Jimmy Wylie @mayahustle.com · 19/02/2026
I earned my first CVE credit (CVE-2025-7676) for helping with a Windows ARM vuln. So, to commemorate the credit, my coworker, Reid, presented me last week with a Trophy of Perpetual Futility, because there’s always more work to do. raw.githubusercontent.com/reidmefirst/...
Photo of smiling Jimmy holding a gold and red trophy in right hand. The top of the trophy is a gold statue of a king holding a sceptre. The king is standing on a red column, with a white base and a gold plaque.Hand holding a trophy of king standing on a column. At the base of the column is the text:
‘MY NAME IS OZYMANDIAS, KING
OF KINGS; LOOK ON MY WORKS, 
YE MIGHTY, AND DESPAIR
1120
Jimmy Wylie @mayahustle.com · 17/02/2026
The Dragos 2026 Year In Review Report is live: 3 new threat groups, updates from 3 of our more active threat groups, and (my personal favorite) coverage of a subset ICS-related capabilities that we found last year.
dragos.com
Dragos 2026 OT Cybersecurity Report: a Year in Review
Get the latest OT threats, vulnerabilities, and lessons learned from real-world incidents in this year’s 2026 OT Cybersecurity Report.
042
Jimmy Wylie @mayahustle.com · 10/02/2026
I've spent a lot of time reversing ICS malware. Recently, I've been building it with AI tools. While there's been plenty of commentary and news about AI and malware, I'm excited to share what I learned actually trying to build some at S4x26. Stage 2, Feb 24, 12pm.
021
Jimmy Wylie @mayahustle.com · 30/01/2026
CERT.PL's report on the attacks against Polish infrastructure. A full destructive playbook enabled by default credentials: firmware corruption, wipers, factory resets, even booted Tiny Core Linux on KVM to DD-wipe servers. The report is excellent work.
cert.pl
Energy Sector Incident Report - 29 December 2025
CERT Polska presents a report on the analysis of an incident in the energy sector that occurred on 29 December 2025. The attacks were destructive in nature and targeted wind and photovoltaic farms, a large combined heat and power plant, and a company from the manufacturing sector. The publication aims to raise awareness of the risks associated with sabotage in cyberspace.
010
Jimmy Wylie @mayahustle.com · 29/01/2026
I know I'm feeling stressed out when I go back to reading Thich Nhat Hahn. His teachings calm me, and I need that reminder that happiness is available in any moment despite circumstance. I'm not even Buddhist. or maybe I am? He'd probably say the distinction isn't important.
041
Jimmy Wylie @mayahustle.com · 27/01/2026
This is the first known attack on DERs. Attackers compromised RTUs at 30 different sites. The report has an overview, defensive guidance, and a comparison to past ELECTRUM ops. Hats off to CERT Polska for leading the charge, and kudos to our Intel team for the hard work.
hubs.la
Intel Report | ELECTRUM: Cyber Attack on Poland's Electric System 2025 | Dragos
A 2025 cyber attack on Poland’s electric system highlights both risk and resilience in modern power grids. Download the report →
052
Jimmy Wylie @mayahustle.com · 16/12/2025
I spent a couple months arguing with Claude and Copilot while building FrostyGoop variants for DNP3 (and Modbus), keeping detailed notes on what worked and what didn't. At S4, I’ll share my honest assessment of these tools and how they might lower barriers to ICS malware dev. See you in Miami!
031
Reposted by Jimmy Wylie
Iceman @iceman1001.bsky.social · 11/11/2025
Finally sharing what’s been under wraps for months. Adam Foster and I tore into HID SEOS to build the first open-source implementation for Proxmark3. This is our Black Hat Asia 2025 story → www.youtube.com/watch?v=mnhG... #RFIDHacking #SEOS #CyberSecurity
youtube.com
Dismantling the SEOS Protocol
YouTube video by Black Hat
051
Jimmy Wylie @mayahustle.com · 17/11/2025
We have a job opening in our Community Defense Program (CDP) which gives small utilities free access to the Dragos Platform. This opening is a chance to do some truly meaningful work for the community. Job Description: job-boards.greenhous... CDP Description: www.dragos.com/commu...
job-boards.greenhouse.io
Associate Project Manager
Hanover, MD
091
Jimmy Wylie @mayahustle.com · 14/11/2025
Had a great time presenting at LSU this week on hunting and analyzing Go and Python malware samples while hunting for ICS malware. For those who couldn't make it, you can catch a recording of this talk from Hou.Sec.Con last month with @sam-hans0n.bsky.social www.youtube.com/watc...
021
Jimmy Wylie @mayahustle.com · 11/11/2025
Props to their Threat Research team for identifying and publicizing these harmful packages. If you want to understand what the code does, check out their post. Bottom line: Always verify your dependencies and their sources! socket.dev/blog/9-ma... 6/6
socket.dev
9 Malicious NuGet Packages Deliver Time-Delayed Destructive ...
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control system...
010
Jimmy Wylie @mayahustle.com · 11/11/2025
The evidence also doesn't rule out security research as an explanation. I’d give this a low confidence assessment for malicious intent. That said, it's normal for analysts to reach different conclusions, and this isn't a criticism of Socket's solid technical analysis. 5/6
110
Jimmy Wylie @mayahustle.com · 11/11/2025
- The lure isn't convincing. - The packages are unpopular (even by Socket's metrics), so infection of new projects seems improbable. - Why would existing projects switch to the malicious dependencies? - There's no C2 code to confirm victims. How would an attacker know if this worked? 4/6
110
Jimmy Wylie @mayahustle.com · 11/11/2025
While I agree the code is harmful and the packages are suspicious, I'm not convinced about the supply chain attack angle -- or if it is one, it’s not a particularly effective one. Several factors give me pause: 3/6
110
Jimmy Wylie @mayahustle.com · 11/11/2025
No legitimate projects were compromised, and no S7, Sharp7, or Siemens codebases were modified. Socket identified packages published by a separate user ("shanhai666") containing code that probabilistically kills host processes and causes database write failures within specific date ranges. 2/6
110
Jimmy Wylie @mayahustle.com · 11/11/2025
A lot of folks have reached out about Socket’s recent report on a supply chain attack using malicious NuGet packages to target Siemens S7 protocol and other PLCs. This is not a supply chain attack in the traditional sense. 1/6
132
Jimmy Wylie @mayahustle.com · 31/10/2025
“No, that’s my neighbor, Bobby. I live at 502, but you have to write 501 on the package or the mail carrier brings it to the wrong house. He has a problem.” ICS is fun. This blog covers the problem: blog.softwaretoolbox.com/topserver-mo... (H/T to Reid Wightman for inspiring this post) (2/2)
blog.softwaretoolbox.com
Modbus Offset vs. Addressing: Why Does It Matter?
Discover the relationship between the Modbus address used by TOP Server and the physical offset in a device when enabling/disabling Zero-Based Addressing.
021
Jimmy Wylie @mayahustle.com · 31/10/2025
Learning Modbus is basically this conversation: “I live at 502 Westport Ave.” “Sweet, I’m sending you a package.” “Wait! If you talk to the mail carrier, my address is 501 Westport Ave.” “Oh. So, you live at 501 Westport?” (1/2)
121
Jimmy Wylie @mayahustle.com · 27/10/2025
Other questions I'm exploring: How much does AI know about ICS protocols? Does AI truly lower the barrier for entry? If not, is that an AI limitation or am I just "holding it wrong"? Is it shortening my development time? Or solving some problems but creating new ones for a net-zero benefit? 2/2
030
Jimmy Wylie @mayahustle.com · 27/10/2025
I'm speaking at S4x26 on creating a FrostyGoop-style tool using AI. This experiment has been a good avenue for tackling a few questions I've had about AI-enabled software development. Most importantly, just how easy is it? I'm excited to share what I learn come February! 1/2
140
Jimmy Wylie @mayahustle.com · 24/10/2025
MinusOne, a deobfuscation engine for scripting languages: github.com/airbus-ce... EPIC Erebus for PCIe and DMA attack research: www.crowdsupply.com/... 3/3
github.com
GitHub - airbus-cert/minusone: Powershell Linter
Powershell Linter. Contribute to airbus-cert/minusone development by creating an account on GitHub.
010
Jimmy Wylie @mayahustle.com · 24/10/2025
Here are a few of the projects I enjoyed learning about this time around: Thorium Malware Pipeline: github.com/cisagov/t... CTADL Static Taint Analysis Tool: github.com/sandialab... 2/3
github.com
GitHub - cisagov/thorium: A scalable file analysis and data generation platform that allows users to easily orchestrate arbitrary docker/vm/shell tools at scale.
A scalable file analysis and data generation platform that allows users to easily orchestrate arbitrary docker/vm/shell tools at scale. - cisagov/thorium
110
Jimmy Wylie @mayahustle.com · 24/10/2025
I had a great experience at #FTSCon on Monday. Both the speakers and the audience are such high caliber that an interesting discussion can be had at any point during the day. The information presented is useful for folks in any technical aspect of cybersecurity, not just DFIR folks. 1/3
121
Jimmy Wylie @mayahustle.com · 21/10/2025
MacOS 26 really kills the T2 Intel Macs. It's technically compatible, but the experience is a drag, especially just after boot with all the indexing. I'm going to put a T2 Linux distro on this thing, and hope it improves the experience. I refuse to throw away a computer that's barely 5 years old.
100
Jimmy Wylie @mayahustle.com · 18/10/2025
My cousin is raising money to go to the MLS Next Youth Showcase. You buy tasty popcorn, and the money funds the trip with an option to donate to teachers. Check it out and support a good cause! I just bought a bunch for our weekly board game meetup :) s.dgpopup.com/0o409evs/rp
s.dgpopup.com
Giovanni’s Pop-Up Store - Double Good Online Fundraising
Click here to buy our delicious popcorn and 50% of your purchase benefits this fundraiser. #doublegood #dgpopup
000
Jimmy Wylie @mayahustle.com · 16/10/2025
Our DEF CON33 ICS Village talk is now on YouTube! @sam-hans0n.bsky.social and I share stories of malware we discovered while searching for ICS threats, and discuss our approach to assessing their reputation. Don't Cry Wolf: Evidence-Based Assessment of ICS Threats
youtube.com
DEF CON 33 - Don’t Cry Wolf: Evidence based assessments of ICS Threats - Jimmy Wylie & Sam Hanson
CS Malware is rare. Yet, ICS Malware like FrostyGoop and TRISIS, and related discoveries like COSMICENERGY, were all found on VirusTotal, so analysts still hunt for novel ICS Malware in public malware repositories. In the process, they discover all kinds of tools: research, CTFs, obfuscated nonsense
065
Jimmy Wylie @mayahustle.com · 10/10/2025
I couldn’t think of a picture, so here’s an image from an old show that probably planted the seed for me to become a malware analyst.
010
Jimmy Wylie @mayahustle.com · 10/10/2025
In ICS, malware analysis can feel like archaeology. I started the week with a 13 year old sample and ended the week with @sam-hans0n.bsky.social pinging about an 18 years old sample. So, save your old Windows ISOs and VMs, you might need them!
141
Jimmy Wylie @mayahustle.com · 08/10/2025
I enjoyed it, but I’ll readily admit, it’s not for everyone.
110
Jimmy Wylie @mayahustle.com · 08/10/2025
Thanks to @cybrseccon.bsky.social / HOU.SEC.CON for having us last week. (and for a really unique speaker gift!) The conference has grown into a valuable industry event, and I'm looking forward to the next one! ICYMI, we posted resources from our talk here: gist.github.com/maya...
Selfie of Jimmy holding a belt buckle. The belt buckle is a western style buckle. The buckle has Speaker along the top, an image of the HOUSECCON flying saucer logo below it, and an astronaut riding a horse. The bottom of the buckle has the year, 2025. The rest of the buckle is decorated with filigree.
040
Jimmy Wylie @mayahustle.com · 07/10/2025
Well.. I can’t help but listen to this. 🤘It’s weird, and I like it. deathmeta.bandcamp.com/album/malware
deathmeta.bandcamp.com
MALWARE | DEATH META
10 track album
110
Jimmy Wylie @mayahustle.com · 03/10/2025
The Difference Maker Awards are about contributions to the community, so they let the community decide. Voting ends on Wednesday, October 8. If you haven’t voted yet, please consider it! (I’m a finalist in the ICS category alongside some amazing industry leaders) www.sans.org/about/awards...
sans.org
SANS Difference Makers Awards
These are the people and organizations acknowledged by the SANS Institute for their oustanding contributions to cyber security each year.
030