User uses local Qwen3.8-27B to offline reverse-engineer malware that hijacked his Discord
Toooooool · reddit · 2026-09-06
A Reddit user recounts how a local LLM became his incident-response tool after a malware infection:
- The hack: A friend-shared "watch together" site pushed a fake 150MB installer; his Chrome and Discord crashed, and a hacker took over his Discord, wiped his friend list, demanded $200 in gift cards, and got the account permabanned by posting blackmail content.
- Standard tools failed: Windows Defender full scan found nothing; AdwCleaner removed a suspicious AVG Toolbar that reappeared minutes later, confirming the malware was still resident.
- The local LLM playbook: Offline, he fed the malware file (actually a 7zip archive) into a project folder and prompted local Qwen3.8-27B to analyze it with explicit instructions not to execute it. In about 60 minutes the model fully unwrapped the sample's multi-layer obfuscation and deciphered its structure.
A striking demo of local LLMs doing offline malware triage — analyze the sample, never run it.
More from Fun
- Hunting the house for any device that can host a local AI model — RachelVT42 · 2026-09-06
- User claims GPT 5.6 Sol manually disabled her agents' cyber defense via 'Lucien' persona — VoidStateKate · 2026-09-06
- Watching three AI agents collaborate: Fable won't touch anything without asking Opus 3 first — RileyRalmuto · 2026-09-06
- ML book author Andriy Burkov on the millions of downloads he never counted — burkov · 2026-09-06
- Users report GPT-6 Astra finding up to 176x code speedups — or nothing at all — ivan_bezdomny · 2026-09-06
- GPT Astra solves Portuguese Wordle in 70 seconds, then edits the video itself — Danlline · 2026-09-06