Jimmy Wylie

@mayahustle.com

I look for ICS threats, and spend a lot of time reverse engineering. Distinguished Malware Analyst @ Dragos. Lead Analyst on TRISIS and PIPEDREAM. He/Him

I used to spend hours finding wrong answers to Linux issues on Reddit before giving up and figuring it out myself. Now, an LLM gives me the wrong answers instantly, boils the ocean, and forces me to manually solve the problem sooner. I feel so productive!

“The AI wrote it, so it must be good” is a trap, and a poor excuse to ignore a human edit. At the very least: - Rewrite the headings - Remove useless adverbs (AI loves “actually”) - Check that the flow of ideas is coherent. - Check for accuracy. (1/2)

Quoted in Dark Reading on the latest LotusWiper release by Kaspersky. I'm always glad when our team's expertise can reach a wide audience. We've seen an uptick in Wiper use since 2022, which makes sense. They're cheap to develop and effective at turning access into damage.

Lotus Wiper Attack Targets Venezuelan Energy Firms, Utilities

An analysis of the destructive malware reveals extensive living-off-the-land (LotL) techniques and detailed strategies for the widespread data deletion.

darkreading.com

ZionSiphon is an AI-generated, non-functional attempt at ICS malware. Malicious intent doesn't imply ability, and broken malware like this is a distraction when we have proven threats like VOLTZITE/Volt Typhoon out there hitting water utilities.: www.dragos.com/blog/zionsip...

ZionSiphon: Why This Malware Isn't A Credible ICS Threat

Dragos analyzed ZionSiphon and assessed it as non-functional OT malware. Here's why it poses no credible threat to dam desalination or critical infrastructure

dragos.com

Ironically, S4 dropped my talk on vibe coding ICS malware on the same day that non-functional AI-slop OT "malware" is making headlines. It’s hype “malware” distracting us from real threats. More to say, but it's Friday :) In the meantime, I hope you enjoy the talk.

Building FrostyGoop With The Help Of AI

How easy or hard is it for an attacker to build an OT attack platform such as FrostyGoop? Jimmy Wylie answered this question by developing, with the help of AI, a FrostyGoop attack platform. There were two caveats to this effort: 1. He built this from scratch without reusing any of the FrostyGoop

youtube.com

This blog nails some real problems with bringing AI into an organization in any industry, not just cybersecurity. The article brings up a human training issue that I've been pondering a lot. What does it look like to train a new reverse engineer with AI tools available?

The Implementation Blind Spot | Why Organizations Are Confusing Temporary Friction with Permanent Safety

Our new blog post explores the ‘cognitive rust belt’ — how AI friction masks skill loss and why organizations must act now.

sentinelone.com

"Claude hacks government" is as silly as saying "Metasploit hacked a hospital!" Blaming AI shifts responsibility away from the humans who orchestrate it, and confuses defenders into thinking they're up against some vague AI supervillain. AI hasn't changed the fundamental problem. 1/2

If you're trying to run Remnux on KVM by loading the OVA: For network access: KVM changes the network adapter name, so change the config in /etc/netplan, replacing the old adapter (like enss0) with the new one and reboot. Use networkctl to find the non-loopback adapter name (like en1ps0) 1/3

I've spent a lot of time reversing ICS malware. Recently, I've been building it with AI tools. While there's been plenty of commentary and news about AI and malware, I'm excited to share what I learned actually trying to build some at S4x26. Stage 2, Feb 24, 12pm.

Bild

I know I'm feeling stressed out when I go back to reading Thich Nhat Hahn. His teachings calm me, and I need that reminder that happiness is available in any moment despite circumstance. I'm not even Buddhist. or maybe I am? He'd probably say the distinction isn't important.

This is the first known attack on DERs. Attackers compromised RTUs at 30 different sites. The report has an overview, defensive guidance, and a comparison to past ELECTRUM ops. Hats off to CERT Polska for leading the charge, and kudos to our Intel team for the hard work.

Intel Report | ELECTRUM: Cyber Attack on Poland's Electric System 2025 | Dragos

A 2025 cyber attack on Poland’s electric system highlights both risk and resilience in modern power grids. Download the report →

hubs.la

I spent a couple months arguing with Claude and Copilot while building FrostyGoop variants for DNP3 (and Modbus), keeping detailed notes on what worked and what didn't. At S4, I’ll share my honest assessment of these tools and how they might lower barriers to ICS malware dev. See you in Miami!

Bild

A lot of folks have reached out about Socket’s recent report on a supply chain attack using malicious NuGet packages to target Siemens S7 protocol and other PLCs. This is not a supply chain attack in the traditional sense. 1/6

Learning Modbus is basically this conversation: “I live at 502 Westport Ave.” “Sweet, I’m sending you a package.” “Wait! If you talk to the mail carrier, my address is 501 Westport Ave.” “Oh. So, you live at 501 Westport?” (1/2)

I'm speaking at S4x26 on creating a FrostyGoop-style tool using AI. This experiment has been a good avenue for tackling a few questions I've had about AI-enabled software development. Most importantly, just how easy is it? I'm excited to share what I learn come February! 1/2

Bild

I had a great experience at #FTSCon on Monday. Both the speakers and the audience are such high caliber that an interesting discussion can be had at any point during the day. The information presented is useful for folks in any technical aspect of cybersecurity, not just DFIR folks. 1/3

MacOS 26 really kills the T2 Intel Macs. It's technically compatible, but the experience is a drag, especially just after boot with all the indexing. I'm going to put a T2 Linux distro on this thing, and hope it improves the experience. I refuse to throw away a computer that's barely 5 years old.

My cousin is raising money to go to the MLS Next Youth Showcase. You buy tasty popcorn, and the money funds the trip with an option to donate to teachers. Check it out and support a good cause! I just bought a bunch for our weekly board game meetup :) s.dgpopup.com/0o409evs/rp

Giovanni’s Pop-Up Store - Double Good Online Fundraising

Click here to buy our delicious popcorn and 50% of your purchase benefits this fundraiser. #doublegood #dgpopup

s.dgpopup.com