Incorporating S.P.I.C.Y. DICOM Polyglot Threats into Cyber Warfare Exercises

Authors

  • Danny "Danhammer" Hetzel Biohacking village , Husaria Security https://orcid.org/0009-0008-4145-2261
  • Xavier-Lewis Palmer Biohacking Village , BiosView Labs
  • Lucas Potter BiosView Labs
  • Nina Alli Biohacking Village

DOI:

https://doi.org/10.34190/eccws.25.1.4843

Keywords:

DICOM, Polyglot, Healthcare, Cybersecurity, S.P.I.C.Y., Operational gap, Automated pipeline

Abstract

The technical feasibility of crafting polyglot files, objects valid under multiple file formats, has been repeatedly demonstrated in various contexts, including the DICOM medical imaging standard. While prior work has established that DICOM polyglots are technically constructible, a significant operational gap exists between this known vulnerability and the preparedness of healthcare organizations to detect and mitigate such data-centric threats. This paper addresses this critical oversight by shifting the focus from how to construct DICOM polyglots to why they pose an unmitigated, systemic risk in clinical workflows. We argue that this operational gap stems from three primary issues: non-uniform inspection across heterogeneous security tools, misplaced trust in the structural compliance of medical data, and insufficient threat modelling for automated pipelines. Our feasibility analysis, using a controlled DICOM/Portable Executable (PE) polyglot, demonstrates that mainstream security tools exhibit substantial inconsistencies in detection, with different systems interpreting the same object according to varying, often shallow, parsing assumptions. This non-uniform inspection allows the polyglot to remain stealthy and polyglot. To provide a structured framework for analyzing and mitigating this threat, we introduce the S.P.I.C.Y. framework, defined by five operational characteristics: Stealthy, Polyglot, Infiltrative, Cascading, and Yield. S.P.I.C.Y. helps practitioners measure the operational impact of malicious data artifacts that propagate through trusted, automated workflows, such as Picture Archiving and Communication Systems (PACS) and Vendor Neutral Archives (VNAs). The Infiltrative and Cascading characteristics highlight how an object, once past initial inspection, maintains its dual functionality across multiple automated processes. Finally, we redefine Yield to include not just execution, but the operational value gained from persistence within trusted infrastructure. By applying the S.P.I.C.Y. framework, organizations can move beyond traditional security models and strategically address the critical blind spots created by operational complexity and the assumed trust placed in medical data standards.

Author Biographies

Danny "Danhammer" Hetzel, Biohacking village , Husaria Security

Danny “Danhammer” Hetzel is a cybersecurity researcher and medical device security practitioner focused on offensive security, healthcare systems, and real-world attack simulation. He serves as Lead CTF Administrator for DEF CON Biohacking Village and works extensively on medical device and healthcare security research.

Xavier-Lewis Palmer, Biohacking Village , BiosView Labs

Xavier comes from multiple disciplines, with work focused largely in biomedical contexts. He is fond of positive and creative projects that foster curiosity and helpful conversations around technologies that interface with biology.

Lucas Potter, BiosView Labs

Lucas Potter is a biomedical engineer specializing in the integration of biology, medicine, and engineering to design and optimize medical technologies. Throughout his academic career, Lucas has contributed to various research projects, focusing on areas such as biocybersecurity, virtual surgical planning, and the security risks associated with (IoT) health devices.

Nina Alli, Biohacking Village

Janine Medina is the Executive Director of Biohacking Village and a healthcare cybersecurity leader focused on medical devices, clinical systems, and patient safety. She has worked in hospital environments, served in national roles advancing medical device security, and builds partnerships between researchers, manufacturers, and public-sector stakeholders to drive responsible disclosure and resilient care.

Downloads

Published

2026-06-15