Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Jimmy Wylie

@mayahustle@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Distinguished Malware Analyst at Dragos. Lead #Malware Analyst on TRISIS and PIPEDREAM. Spend my time searching for and tearing apart #ICS threats.

1120 Followers
490 Following
21 Posts
Joined November 04, 2022
BlueSky:
https://bsky.app/profile/mayahustle.com
LinkedIn:
https://www.linkedin.com/in/jimmywyliejr
Twittodon:
https://twittodon.com/share.php?t=mayahustle&m=mayahustle@infosec.exchange
Twitter:
https://twitter.com/mayahustle
Open post
Jimmy Wylie @mayahustle@infosec.exchange
· 5mo ago

ZionSiphon is an AI-generated, non-functional attempt at ICS malware. Malicious intent doesn't imply ability, and broken malware like this is a distraction when we have proven threats like VOLTZITE/Volt Typhoon out there hitting water utilities.:

https://www.dragos.com/blog/zionsiphon-ot-malware-analysis

#ICS #malware

dragos.com
19
0
11
0
Open post
Jimmy Wylie @mayahustle@infosec.exchange
· 7mo ago

I earned my first CVE credit (CVE-2025-7676) for helping with a Windows ARM vuln. So, to commemorate the credit, @reverseics@infosec.exchange presented me last week with a Trophy of Perpetual Futility, because there’s always more work to do.

https://raw.githubusercontent.com/reidmefirst/vuln-disclosure/refs/heads/main/2025-04.txt

raw.githubusercontent.com
18
1
0
0
Open post
Jimmy Wylie @mayahustle@infosec.exchange
· 6mo ago

TIL FLARE distributes educational content for free on GitHub.

https://github.com/mandiant/flare-learning-hub

GitHub

GitHub - mandiant/flare-learning-hub: Free educational content on reverse engineering and malware analysis from the FLARE team

Free educational content on reverse engineering and malware analysis from the FLARE team - mandiant/flare-learning-hub

8
0
4
0
Open post
Jimmy Wylie @mayahustle@infosec.exchange
· 6mo ago

This blog nails some real problems with bringing AI into an organization in any industry, not just cybersecurity.

The article brings up a human training issue that I've been pondering a lot. What does it look like to train a new reverse engineer with AI tools available?

https://www.sentinelone.com/blog/the-implementation-blind-spot-why-organizations-are-confusing-temporary-friction-with-permanent-safety/

The Implementation Blind Spot | Why Organizations Are Confusing Temporary Friction with Permanent Safety | SentinelOne
SentinelOne

The Implementation Blind Spot | Why Organizations Are Confusing Temporary Friction with Permanent Safety | SentinelOne

Our new blog post explores the ‘cognitive rust belt’ — how AI friction masks skill loss and why organizations must act now.

6
0
1
0
Open post
Jimmy Wylie @mayahustle@infosec.exchange
· 6mo ago

Folks are giving AI way too much credit.
"AI wins CTF"
"Claude hacks government"

Sound as silly as saying:
"Metasploit hacked a hospital!"
or "Hammer builds a house!"

Blaming AI shifts responsibility away from the humans who orchestrate it, and confuses defenders into thinking they're up against some vague AI supervillain.

AI hasn't changed the fundamental problem. Capable attackers are still the threat, not AI. Stop worrying about AI. Instead, change your default passwords and enable MFA

6
1
0
0
Open post
Jimmy Wylie @mayahustle@infosec.exchange
· 5mo ago

Ironically, S4 dropped my talk on vibe coding ICS malware on the same day that non-functional AI-slop OT "malware" is making headlines. It’s hype “malware” distracting us from real threats.

More to say, but it's Friday :) In the meantime, I hope you enjoy the talk.

https://www.youtube.com/watch?v=v0grXXc5zgw

Building FrostyGoop With The Help Of AI

4
0
2
0
Open post
Jimmy Wylie @mayahustle@infosec.exchange
· 8mo ago

I've spent a lot of time reversing ICS malware. Recently, I've been building it with AI tools. While there's been plenty of commentary and news about AI and malware, I'm excited to share what I learned actually trying to build some at S4x26.

Stage 2, Feb 24, 12pm.

3
0
1
0
Open post
Jimmy Wylie @mayahustle@infosec.exchange
· 8mo ago

CERT.PL's report on the coordinated attacks against Polish infrastructure. Adversaries used all manner of destructive techniques: firmware corruption, wipers, SSH commands, FTP deletes, factory resets, even booted Tiny Core Linux on KVM to DD-wipe servers.

They targeted a grid connection point, CHP plant, and a manufacturing site. The forensic reconstruction and malware analysis is excellent. Worth a read for the technical depth.

https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/

#ICS #OTSecurity

Energy Sector Incident Report - 29 December 2025
cert.pl

Energy Sector Incident Report - 29 December 2025

CERT Polska presents a report on the analysis of an incident in the energy sector that occurred on 29 December 2025. The attacks were destructive in nature and targeted wind and photovoltaic farms, a large combined heat and power plant, and a company from the manufacturing sector. The publication aims to raise awareness of the risks associated with sabotage in cyberspace.

3
0
2
0
Open post
Jimmy Wylie @mayahustle@infosec.exchange
· 8mo ago

This is the first known attack on DERs. Attackers compromised RTUs at 30 different sites. The report has an overview, defensive guidance, and a comparison to past ELECTRUM ops.
Hats off to CERT Polska for leading the charge, and kudos to our Intel team for the hard work.

https://hubs.la/Q040Bwpg0

#ICS #otsecurity

Intel Report | ELECTRUM: Cyber Attack on Poland's Electric System 2025 | Dragos
hubs.la

Intel Report | ELECTRUM: Cyber Attack on Poland's Electric System 2025 | Dragos

A 2025 cyber attack on Poland’s electric system highlights both risk and resilience in modern power grids. Download the report →

2
1
2
0
Open post
Jimmy Wylie @mayahustle@infosec.exchange
· 9mo ago

I spent a couple months arguing with Claude and Copilot while building FrostyGoop variants for DNP3 (and Modbus), keeping detailed notes on what worked and what didn't. At S4, I'll share my honest assessment: where these tools actually help, where they fail, and how much skill an attacker needs to make them useful.

See you in Miami!

#ICS #malware #otsecurity

2
0
1
0
Open post
Jimmy Wylie @mayahustle@infosec.exchange
· 10mo ago

Had a great time presenting at LSU this week on hunting and analyzing Go and Python malware samples while hunting for ICS malware. For those who couldn't make it, you can catch a recording of this talk from Hou.Sec.Con last month with @secureloon@infosec.exchange

https://www.youtube.com/watch?v=R8xFGz-AGEE

#ICS #malware #otsecurity #malwareanalysis

2
0
1
0
Open post
Jimmy Wylie @mayahustle@infosec.exchange
· 7mo ago

The Dragos 2026 Year In Review Report is live: 3 new threat groups, updates from 3 of our more active threat groups, and (my personal favorite) coverage of a subset ICS-related capabilities that we found last year.

https://www.dragos.com/ot-cybersecurity-year-in-review

dragos.com
1
0
2
0
Open post
Jimmy Wylie @mayahustle@infosec.exchange
· 8mo ago

I know I'm feeling stressed out when I go back to reading Thich Nhat Hahn. His teachings calm me, and I need that reminder that happiness is available in any moment despite circumstance. I'm not even Buddhist. or maybe I am? He'd probably say the distinction isn't important.

1
0
0
0
Open post
Jimmy Wylie @mayahustle@infosec.exchange
· 10mo ago

We have a job opening in our Community Defense Program (CDP) which gives small utilities free access to the Dragos Platform. This opening is a chance to do some truly meaningful work for the community.

Job Description: https://job-boards.greenhouse.io/dragos/jobs/4976260008

CDP Description:
https://www.dragos.com/community/community-defense-program

#otsecurity #ics

Dragos
job-boards.greenhouse.io

Dragos

1
0
1
0
Open post
Jimmy Wylie @mayahustle@infosec.exchange
· 11mo ago

A lot of folks have reached out about Socket's recent report on a supply chain attack using malicious NuGet packages to target Siemens S7 protocol and other PLCs.

This is not a supply chain attack in the traditional sense. No legitimate projects were compromised, and no S7, Sharp7, or Siemens codebases were modified. Socket identified packages published by a separate user ("shanhai666") containing code that probabilistically kills host processes and causes database write failures within specific date ranges.

While I agree the code is harmful and the packages are suspicious, I'm not convinced about the supply chain attack angle -- or if it is one, it's not a particularly effective one. Several factors give me pause:

- The lure isn't particularly convincing.
- The packages are unpopular (even by Socket's metrics), so infection of new projects seems improbable.
- It's unclear how or why existing projects that use legit Sharp7 or SQL would switch to the malicious dependency.
- There's no C2 code or infrastructure to confirm victims. How would an attacker even know if this worked?
- The evidence doesn't clearly rule out the alternative explanation of offensive security research.

I'd give this a low confidence assessment for malicious intent. That said, it's normal for analysts to reach different conclusions based on the same data, and my assessment isn't a criticism of Socket's solid technical analysis and code breakdown.

Props to their Threat Research team for identifying and publicizing these harmful packages. If you want to understand what the code does, check out their post. Their package search tool also has a neat decompilation feature that lets you examine the code yourself.

Bottom line: Always verify your dependencies and their sources!

https://socket.dev/blog/9-malicious-nuget-packages-deliver-time-delayed-destructive-payloads

socket.dev
1
0
0
0
Open post
Jimmy Wylie @mayahustle@infosec.exchange
· 31mo ago
Replying to
@shellsharks Love this idea. I’m already appreciating the curation of smart lists in the Mammoth client. Such a useful feature. Thanks for the mention, and thanks for the good work! 👏👏👏
2
0
0
0
Open post
Jimmy Wylie @mayahustle@infosec.exchange
· 7mo ago
Replying to
Separate but related, when did VMware and Virtual Box get so terrible on Linux? I used to use them all the time, but with secure boot, installing either of them is not so straightforward. I gave up on VMWare after a few hours of trying to figure out the which combination of software version, user-provided patches, and kernel version to install. I realized later that I had forgotten to sign keys for secure boot. You'd think the installer would at least give you a warning. Virtual Box on the other hand, told me I had to sign its kernel modules, had me go through the process, and then failed to install. (via apt). Downloading the deb appeared to fix it, but the actual VM experience wasn't great. KVM on the other hand, installs (optionally) with the Kubuntu installer, and worked fine out the box.
0
2
0
0
Open post
Jimmy Wylie @mayahustle@infosec.exchange
· 7mo ago

I had a great time on Jim's podcast discussing malware analysis, reverse engineering, working at Dragos, and a little bit of my personal history.

https://www.youtube.com/watch?v=qCgnIMbgs3Y

ICS & OT Malware Analyst Jimmy Wylie

0
0
2
0
Open post
Jimmy Wylie @mayahustle@infosec.exchange
· 2mo ago
I used to spend hours finding wrong answers to Linux issues on Reddit before giving up and figuring it out myself. Now, an LLM gives me the wrong answers instantly, boils the ocean, and forces me to manually solve the problem sooner. I feel so productive!
0
0
0
0
Open post
Jimmy Wylie @mayahustle@infosec.exchange
· 7mo ago
Replying to
VMware workstation was the one I had issues with. I needed to sign the vmnet and vmmon drivers so secure boot wouldn’t reject them. This was the main problem on Debian 13 anyhow. On Kubuntu 24.04, on kernel 6.17, I had that same problem + hiccups building those same modules. (https://www.lucaswilliams.net/index.php/2025/11/25/building-the-vmware-workstation-modules-on-ubuntu-24-04-with-secure-boot-enabled/) I’ve since figured out where I went wrong, but by that point, I already had KVM up and running 🤷‍♂️ Seeing as I didn’t strictly need VMware, I didn’t see any point in trying it again. But, I wish the VMware installer gave you more of a heads up. Def would have saved me time and headache.
Behind the Eyes

Building the VMware Workstation Modules on Ubuntu 24.04 with Secure Boot Enabled - Behind the Eyes

Hello everyone! I hope you have all been well and staying safe. Today's blog is one that I hope you find helpful. So while I use KVM primarily for VM's on my laptop and even on my servers, I still use VMware Workstation on my Laptop for quick testing. However, with the latest release (25H2 as of today), I was…

0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 20:08:27 UTC