‹ BackHN Continuity

Thread

GLM-5.3 and the spread of advanced cyber capabilities

254 points · 241 comments · Philpax

  1. wg0 · · focus · HN ↗
    They're advertising GLM for free.

    Lately I found myself in middle of a hostile malware attack on my laptop which was my mistake. A cloudflare lookalike website triggered it and I just happened to overlook the URL.

    In panic I headed to Claude and first request was denied. Not looking beyond scope.

    Desperate - I fired opencode with DeepSeek v4 Flash (not even 4.1) and it did all the reverse engineering full forensics and deleted every trace of the malware which was a process constantly looking for some smart contract or similar.

    So no, GLM 5.3 is fine. Thank you for the free advertisement.

    1. crossroadsguy · · focus · HN ↗
      > A cloudflare lookalike

      Was that a page that made it look like one needs to do something as part of the browser&#x2F;session human verification process? And it was an obfuscated command (an echo cmd iirc)? Sth like this <a href="https:&#x2F;&#x2F;www.forcepoint.com&#x2F;blog&#x2F;x-labs&#x2F;odyssey-stealer-attacks-macos-users" rel="nofollow">https:&#x2F;&#x2F;www.forcepoint.com&#x2F;blog&#x2F;x-labs&#x2F;odyssey-stealer-attac...

      Or was it something else?

      1. wg0 · · focus · HN ↗
        Yeah it was something like that exactly with constant loop trying to take control.

        DeepSeek did full reverse engineering on this.

        1. crossroadsguy · · focus · HN ↗
          Great. I was able to do that in Gemini free web. Lots of copy&#x2F;pasting, well, what an irony - but I was careful this time. Gave inputs in Gemini Web and then followed up. Didn&#x27;t have a paid plan back then. I remember a dir name &quot;luvmrtrump&quot; or something. Haha.

          I was lucky enough to stop at the password prompt (something felt off). Gemini had pretty much established that it was almost entirely certain nothing left my Mac as I didn&#x27;t enter my password and I hadn&#x27;t. It also found some evidence that had I entered my password those evidences would have been gone certainly from my mac and then I had the script beautified and de-obfuscated and read it myself and had a much needed sigh of relief. The script literally did nothing unless it had the password.

          I started using nextdns after that but then the site I tricked on was a legit but very small e-com site from my country which was hacked&#x2F;taken over, so not sure how nextdns can even be helpful here. Also the script was identified as malicious by only one antivirus that I had tried later, just to see. I had tried 8–9 of them. Later I uninstalled all of them and even stopped using NextDNS.

          I wish browsers like Safari allowed specific options like disabling clipboard interaction instead of the &quot;disable js&quot; as the only possible option.

          Later (and still) I feel a bit of shame that how could I fall for this as a somewhat proud cynic and as well versed in &quot;browsing the Interwebs&quot; as it normally gets :) That (as small as it was) experience gave a whole new meaning to malicious online attacks for me and a whole lot of empathy towards people who fall for such attacks. It was my first &quot;experience&quot;. It might sound weird but the feeling of violation still lingers.

          (just wanted to share this)

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.