Sign in

Jérôme Segura

@jeromesegura.com
137 followers 93 following 68 posts

Security researcher with a special interest for web threats.

PostsRepliesMedia
Reposted by Jérôme Segura
Raphael Satter @raphae.li · 21/09/2026
New: ShinyHunters says it’s fighting with cl0p and the threat researchers that follow these actors are *very* eager to see what’s next. With @ajvicens.bsky.social: www.reuters.com/legal/govern...
reuters.com
Cybercrime feud erupts on dark web as notorious group claims hijack of rival's website
One of the world's best-known cybercrime groups said on Sunday it had hijacked ‌one of its chief rivals' dark web site, bringing what it said was a long-simmering feud out into the open.
1128
Reposted by Jérôme Segura
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 04/04/2026
NEW: I spoke to cybersecurity legend Mikko Hyppönen about his decades-long fight against computers viruses first, and then malware — and how computers have gotten safer over time. Mikko also told me why he has decided to now turn his focus to fight another enemy: killer drones.
techcrunch.com
After fighting malware for decades, this cybersecurity veteran is now hacking drones | TechCrunch
Mikko Hyppönen is one of the most recognizable faces of the cybersecurity industry. After fighting computer viruses, worms, and malware, for more than 35 years, he tells TechCrunch why he is now worki...
23416
Jérôme Segura @jeromesegura.com · 03/03/2026
Bots are adding to the already obvious RAM scarcity problem. datadome.co/threat-resea...
datadome.co
000
Reposted by Jérôme Segura
Max Hils @hi.ls · 29/04/2025
mitmproxy 12 is out! 🚀 It’s now possible to modify the prettified representation of binary protocols. Editing Protobufs is now as easy as editing YAML, no .proto schema needed. 🙌 mitmproxy.org/posts/releas...
mitmproxy.org
Mitmproxy 12: Interactive Contentviews
177
Reposted by Jérôme Segura
Brad @malware-traffic-analysis.net · 22/04/2025
2025-04-22 (Tuesday): Always fun to find the fake CAPTCHA pages with the "ClickFix" style instructions trying to convince viewers to infect their computers with malware. Saw #StealC from an infection today. Indicators at github.com/malware-traf...
Step 1: Search for bsc-dataseed.binance[.]org on URLscan (urlscan.io).  You can sign up for a URLscan account for free.  The search results should contain pages from legitimate sites that have been compromised for this campaign.Step 2:  Try one of the sites you found on the URLscan search in a web browser.  It should return a fake CAPTCHA page, with a box to check/click.  You have to click the box twice.  It then shows instructions on how to copy and run script that's been injected into the viewer's clipboard.

Note: Make sure you do this in a controlled lab environment on a Windows host specifically used for testing malware.  Don't try this on your regular Windows computer!Step 3: Run the script to infect a Windows host.  To emphasize once again, this should be done in a controlled lab environment.  This image shows network traffic from an infection filtered in Wireshark and it shows C2 traffic from the StealC infection.
002
Jérôme Segura @jeromesegura.com · 12/04/2025
Crooks doing quality control the hard way 😂 console.log("!!!WORKING!!!") #skimming #ecommerce
010
Reposted by Jérôme Segura
EricLaw 🎻 @ericlawrence.com · 08/04/2025
“Attack techniques so stupid, they can’t possibly succeed… except they do!”, The Unwitting Accomplice textslashplain.com/2024/06/04/a...
textslashplain.com
Attack Techniques: Trojaned Clipboard
Today in “Attack techniques so stupid, they can’t possibly succeed… except they do!” — the trojan clipboard technique. The attacking website convinces the victim user …
062
Reposted by Jérôme Segura
EricLaw 🎻 @ericlawrence.com · 07/04/2025
Understanding (and debugging) SmartScreen/Network Protection textslashplain.com/2025/04/07/u...
textslashplain.com
Understanding SmartScreen and Network Protection
The vast majority of cyberthreats arrive via one of two related sources: That means that combining network-level sensors and throttles with threat intelligence (which sites deliver attacks), securi…
1158
Reposted by Jérôme Segura
Squiblydoo @squiblydoo.bsky.social · 01/04/2025
Fake PuTTy, signed "Eptins Enterprises Llp" Sets scheduled task "Security Updater" and checks into IP address: 185.196.10.127 Triage: tria.ge/250401-wnbad... www.virustotal.com/gui/file/7ca... @jeromesegura.com
001
Jérôme Segura @jeromesegura.com · 24/03/2025
If you manage #wordpress sites using #managewp, watch out for this #phishing campaign via #googleads. -> menagewp[.]com (ad URL and redirect) -> orion[.]manaqewp[.]com (phishing page)
011
Reposted by Jérôme Segura
Help Net Security @helpnetsecurity.com · 21/03/2025
Malicious ads target Semrush users to steal Google account credentials 📖 Read more: www.helpnetsecurity.com/2025/03/21/m... #cybersecurity #cybersecuritynews #accountcredentials #SEO @malwarebytes.com @jeromesegura.com @semrushofficial.bsky.social
helpnetsecurity.com
Malicious ads target Semrush users to steal Google account credentials - Help Net Security
Cyber crooks are exploiting users' interest in Semrush, a popular SEO and market research SaaS platform, to steal Google account credentials.
012
Jérôme Segura @jeromesegura.com · 11/03/2025
Scammers are happily abusing multiple platforms at once thanks to lack of controls. Who's going to protect users here? Google? Facebook?
021
Jérôme Segura @jeromesegura.com · 28/02/2025
PayPal’s “no-code checkout” abused by scammers www.malwarebytes.com/blog/scams/2... #malvertising #techsupportscams
030
Jérôme Segura @jeromesegura.com · 20/02/2025
SecTopRAT bundled in Chrome installer distributed via Google Ads 📖 www.malwarebytes.com/blog/news/20... ⚠️ sites[.]google[.]com/view/gfbtechd/ chrome[.]browser[.]com[.]de/GoogleChrome.exe #malvertising #SecTopRAT
020
Jérôme Segura @jeromesegura.com · 08/02/2025
If you are a developer and use #homebrew, beware of this fraudulent ad on Google. ⚠️ Fake site: brewsh[.]org Malicious curl command: hxxps[://]raw[.]brewsh[.]org/Homebrew/install/HEAD/install[.]sh Atomic Stealer (AMOS): www.virustotal.com/gui/file/389... ⚠️ #malvertising #atomicstealer
000
Jérôme Segura @jeromesegura.com · 31/01/2025
ClickFix vs. traditional download in new DarkGate campaign www.malwarebytes.com/blog/news/20... #ClickFix #malvertising
malwarebytes.com
ClickFix vs. traditional download in new DarkGate campaign
Social engineering methods are being put to the test to distribute malware.
010
Jérôme Segura @jeromesegura.com · 30/01/2025
Microsoft advertisers phished via malicious Google ads www.malwarebytes.com/blog/news/20... #malvertising #googleads #microsoft #bing
malwarebytes.com
Microsoft advertisers phished via malicious Google ads
Just days after we uncovered a campaign targeting Google Ads accounts, a similar attack has surfaced, this time aimed at Microsoft...
000
Jérôme Segura @jeromesegura.com · 15/01/2025
Imagine for a moment that Google allowed a sponsored link to a phishing site for Google ads... www.malwarebytes.com/blog/news/20... #GoogleSearch #GoogleAds #malvertising #phishing
malwarebytes.com
The great Google Ads heist: criminals ransack advertiser accounts via fake Google ads
An ongoing malvertising campaign steals Google advertiser accounts via fraudulent ads for Google Ads itself.
011
Jérôme Segura @jeromesegura.com · 28/12/2024
Malicious Google ad for Virtuals Protocol ⚠️ virtnals[.]com #malvertising
000
Jérôme Segura @jeromesegura.com · 27/12/2024
Malicious Google ad for Aerodrome Finance ⚠️ aeroclrome[.]finance #malvertising
010
Jérôme Segura @jeromesegura.com · 22/12/2024
Malicious Google ad for #Freecad ⚠️ freecad3dmodeling[.]com freecad3d-download[.]com hxxps[://]3d-digitals[.]org/downloads/guthub/FreeCAD_Setup_2[.]0[.]74_win_x64[.]zip #malvertising
020
Jérôme Segura @jeromesegura.com · 19/12/2024
‘Fix It’ social-engineering scheme impersonates several brands www.malwarebytes.com/blog/news/20...
020
Jérôme Segura @jeromesegura.com · 18/12/2024
Malicious Google ad for Netflix ⚠️ +1[-]877[-]906[-]4471 #malvertising
000
Jérôme Segura @jeromesegura.com · 18/12/2024
Malicious Google ad for onshape 3D ⚠️ onshapeservices[.]com #malvertising
000
Jérôme Segura @jeromesegura.com · 17/12/2024
Malicious Google ad for Freecad ⚠️ freecad3design[.]com #malvertising
030
Jérôme Segura @jeromesegura.com · 17/12/2024
Malicious Google ad for Rhino 3D ⚠️ rhino3ddev[.]net #malvertising
010
Jérôme Segura @jeromesegura.com · 17/12/2024
Malicious Google ad for m⁣y⁣N⁣Y⁣LG⁣B⁣S⁣⁣ ⚠️ bluehome[.]uk essnewyorkplatform[.]com #malvertising
010
Jérôme Segura @jeromesegura.com · 16/12/2024
Malicious Google ad for PayPal ⚠️ hxxps[:]//repairsexpert[.]online/services/ #malvertising
010
Jérôme Segura @jeromesegura.com · 16/12/2024
Malicious Google ad for Malwarebytes ⚠️ hxxps[://]sites[.]google[.]com/view/dexters-antivirus/home #malvertising
021
Jérôme Segura @jeromesegura.com · 16/12/2024
Malicious Google ad for New York Life ⚠️ alicehotels[.]com[.]ng eddutvolkinang[.]com/online/ #malvertising #phishing
010
Jérôme Segura @jeromesegura.com · 16/12/2024
A fraudulent Google ad meant to phish employees for their login credentials redirects them to a fake browser update page instead. #malvertising #phishing #SocGholish 🔗 www.malwarebytes.com/blog/news/20...
malwarebytes.com
Malicious ad distributes SocGholish malware to Kaiser Permanente employees
A fraudulent Google ad meant to phish employees for their login credentials redirects them to a fake browser update page instead.
031
Jérôme Segura @jeromesegura.com · 16/12/2024
Malicious Google ad for Kaiser Permanente ⚠️ bellonasoftware[.]com #malvertising
021
Jérôme Segura @jeromesegura.com · 13/12/2024
Malicious Google ad for Grammarly ⚠️ grammarly[.]pc-download[.]live #malvertising
021
Jérôme Segura @jeromesegura.com · 13/12/2024
Malicious Google ad for Planner 5D ⚠️ planner5ddevelop[.]com #malvertising
010
Jérôme Segura @jeromesegura.com · 13/12/2024
Malicious Google ad for eBay ⚠️ fbdecors[.]online #malvertising
021
Jérôme Segura @jeromesegura.com · 13/12/2024
Malicious Google ad for PayPal ⚠️ https[:]//sites[.]google.com/view/pay-pal-helpcustomerservic/ #malvertising
032
Jérôme Segura @jeromesegura.com · 12/12/2024
Malicious Google ad for Microsoft ⚠️ hxxps[://]sites[.]google[.]com/view/micrlochus1011/home #malvertising
010
Jérôme Segura @jeromesegura.com · 11/12/2024
Malicious Google ad for HP ⚠️ vijtechnologies[.]store/result-page/
020
Jérôme Segura @jeromesegura.com · 10/12/2024
Malicious Google ad for HP ⚠️ Scammers' number: +1[-]844[-]954[-]54O4 #malvertising
010
Jérôme Segura @jeromesegura.com · 10/12/2024
Malicious Google ad for eBay ⚠️ Scammers' number: +1[-]888[-]747[-]9547 #malvertising
010
Jérôme Segura @jeromesegura.com · 10/12/2024
Malicious Google ad for PayPal ⚠️ hxxps[://]sites[.]google[.]com/view/womens-v-neck-cable/home #malvertising
010
Jérôme Segura @jeromesegura.com · 09/12/2024
Malicious Google ad for Onshape 3D ⚠️ onshape3d[.]org
010
Jérôme Segura @jeromesegura.com · 09/12/2024
Malicious Google ad for Freecad ⚠️ frecadsolution[.]net #malvertising
030
Jérôme Segura @jeromesegura.com · 08/12/2024
Malicious Google ad for Notion ⚠️ notion[.]downloads[.]com[.]pl/ notion[.]downloads[.]com[.]pl/Notion[.]exe #malvertising
010
Jérôme Segura @jeromesegura.com · 08/12/2024
Malicious Google ad for Rhino 3D ⚠️ rhino3dblog[.]net recad3dsolutions[.]org/setup/index[.]php calibrebook[.]org/downloads/Installer-8[.]39-win-x64[.]zip #malvertising
010
Jérôme Segura @jeromesegura.com · 08/12/2024
Malicious Google ad for Freecad ⚠️ frecad3dsolutions[.]org calibrebook[.]net/downloads/FreeCAD-Installer-4[.]5[.]089-win-x64[.]zip #malvertising
020
Jérôme Segura @jeromesegura.com · 06/12/2024
Malicious Google ads for Planner 5D ⚠️ planner5design[.]org planner5design[.]com calibrebook[.]net/downloads/Installer-8.39-win-x64.zip #malvertising
000
Jérôme Segura @jeromesegura.com · 06/12/2024
Malicious Google ad for Calibre ebook reader ⚠️ https[:]//calibrebook[.]com/downloads/Calibre-Installer-8.39-win-x64.zip #malvertising
000
Jérôme Segura @jeromesegura.com · 05/12/2024
Malicious Google ad for Planner 5D ⚠️ planner5design[.]net calibrebook[.]net/downloads/Installer-8.39-win-x64.zip #malvertising
120
Jérôme Segura @jeromesegura.com · 04/12/2024
Malicious Google ad for New York Life Landing page: urlscan.io/result/71763... #malvertising
000