Jérôme Segura
@jeromesegura.com
Security researcher with a special interest for web threats.
Reposted by Jérôme Segura
mitmproxy 12 is out! 🚀 It’s now possible to modify the prettified representation of binary protocols. Editing Protobufs is now as easy as editing YAML, no .proto schema needed. 🙌
mitmproxy.org/posts/releas...
mitmproxy.org/posts/releas...
Mitmproxy 12: Interactive Contentviews
mitmproxy.org
April 29, 2025 at 9:23 PM
mitmproxy 12 is out! 🚀 It’s now possible to modify the prettified representation of binary protocols. Editing Protobufs is now as easy as editing YAML, no .proto schema needed. 🙌
mitmproxy.org/posts/releas...
mitmproxy.org/posts/releas...
Reposted by Jérôme Segura
2025-04-22 (Tuesday): Always fun to find the fake CAPTCHA pages with the "ClickFix" style instructions trying to convince viewers to infect their computers with malware. Saw #StealC from an infection today. Indicators at github.com/malware-traf...
April 22, 2025 at 9:20 PM
2025-04-22 (Tuesday): Always fun to find the fake CAPTCHA pages with the "ClickFix" style instructions trying to convince viewers to infect their computers with malware. Saw #StealC from an infection today. Indicators at github.com/malware-traf...
April 12, 2025 at 3:46 AM
Reposted by Jérôme Segura
“Attack techniques so stupid, they can’t possibly succeed… except they do!”,
The Unwitting Accomplice
textslashplain.com/2024/06/04/a...
The Unwitting Accomplice
textslashplain.com/2024/06/04/a...
Attack Techniques: Trojaned Clipboard
Today in “Attack techniques so stupid, they can’t possibly succeed… except they do!” — the trojan clipboard technique. The attacking website convinces the victim user …
textslashplain.com
April 8, 2025 at 3:59 PM
“Attack techniques so stupid, they can’t possibly succeed… except they do!”,
The Unwitting Accomplice
textslashplain.com/2024/06/04/a...
The Unwitting Accomplice
textslashplain.com/2024/06/04/a...
Reposted by Jérôme Segura
Reposted by Jérôme Segura
Fake PuTTy, signed "Eptins Enterprises Llp"
Sets scheduled task "Security Updater" and checks into IP address: 185.196.10.127
Triage: tria.ge/250401-wnbad...
www.virustotal.com/gui/file/7ca...
@jeromesegura.com
Sets scheduled task "Security Updater" and checks into IP address: 185.196.10.127
Triage: tria.ge/250401-wnbad...
www.virustotal.com/gui/file/7ca...
@jeromesegura.com
April 1, 2025 at 6:58 PM
Fake PuTTy, signed "Eptins Enterprises Llp"
Sets scheduled task "Security Updater" and checks into IP address: 185.196.10.127
Triage: tria.ge/250401-wnbad...
www.virustotal.com/gui/file/7ca...
@jeromesegura.com
Sets scheduled task "Security Updater" and checks into IP address: 185.196.10.127
Triage: tria.ge/250401-wnbad...
www.virustotal.com/gui/file/7ca...
@jeromesegura.com
If you manage #wordpress sites using #managewp, watch out for this #phishing campaign via #googleads.
-> menagewp[.]com (ad URL and redirect)
-> orion[.]manaqewp[.]com (phishing page)
-> menagewp[.]com (ad URL and redirect)
-> orion[.]manaqewp[.]com (phishing page)
March 24, 2025 at 10:36 PM
If you manage #wordpress sites using #managewp, watch out for this #phishing campaign via #googleads.
-> menagewp[.]com (ad URL and redirect)
-> orion[.]manaqewp[.]com (phishing page)
-> menagewp[.]com (ad URL and redirect)
-> orion[.]manaqewp[.]com (phishing page)
Reposted by Jérôme Segura
Malicious ads target Semrush users to steal Google account credentials
📖 Read more: www.helpnetsecurity.com/2025/03/21/m...
#cybersecurity #cybersecuritynews #accountcredentials #SEO @malwarebytes.com @jeromesegura.com @semrushofficial.bsky.social
📖 Read more: www.helpnetsecurity.com/2025/03/21/m...
#cybersecurity #cybersecuritynews #accountcredentials #SEO @malwarebytes.com @jeromesegura.com @semrushofficial.bsky.social
Malicious ads target Semrush users to steal Google account credentials - Help Net Security
Cyber crooks are exploiting users' interest in Semrush, a popular SEO and market research SaaS platform, to steal Google account credentials.
www.helpnetsecurity.com
March 21, 2025 at 12:58 PM
Malicious ads target Semrush users to steal Google account credentials
📖 Read more: www.helpnetsecurity.com/2025/03/21/m...
#cybersecurity #cybersecuritynews #accountcredentials #SEO @malwarebytes.com @jeromesegura.com @semrushofficial.bsky.social
📖 Read more: www.helpnetsecurity.com/2025/03/21/m...
#cybersecurity #cybersecuritynews #accountcredentials #SEO @malwarebytes.com @jeromesegura.com @semrushofficial.bsky.social
Scammers are happily abusing multiple platforms at once thanks to lack of controls.
Who's going to protect users here? Google? Facebook?
Who's going to protect users here? Google? Facebook?
March 11, 2025 at 5:50 PM
Scammers are happily abusing multiple platforms at once thanks to lack of controls.
Who's going to protect users here? Google? Facebook?
Who's going to protect users here? Google? Facebook?
PayPal’s “no-code checkout” abused by scammers
www.malwarebytes.com/blog/scams/2...
#malvertising #techsupportscams
www.malwarebytes.com/blog/scams/2...
#malvertising #techsupportscams
February 28, 2025 at 2:45 AM
PayPal’s “no-code checkout” abused by scammers
www.malwarebytes.com/blog/scams/2...
#malvertising #techsupportscams
www.malwarebytes.com/blog/scams/2...
#malvertising #techsupportscams
SecTopRAT bundled in Chrome installer distributed via Google Ads
📖
www.malwarebytes.com/blog/news/20...
⚠️
sites[.]google[.]com/view/gfbtechd/
chrome[.]browser[.]com[.]de/GoogleChrome.exe
#malvertising #SecTopRAT
📖
www.malwarebytes.com/blog/news/20...
⚠️
sites[.]google[.]com/view/gfbtechd/
chrome[.]browser[.]com[.]de/GoogleChrome.exe
#malvertising #SecTopRAT
February 20, 2025 at 9:51 PM
SecTopRAT bundled in Chrome installer distributed via Google Ads
📖
www.malwarebytes.com/blog/news/20...
⚠️
sites[.]google[.]com/view/gfbtechd/
chrome[.]browser[.]com[.]de/GoogleChrome.exe
#malvertising #SecTopRAT
📖
www.malwarebytes.com/blog/news/20...
⚠️
sites[.]google[.]com/view/gfbtechd/
chrome[.]browser[.]com[.]de/GoogleChrome.exe
#malvertising #SecTopRAT
If you are a developer and use #homebrew, beware of this fraudulent ad on Google.
⚠️
Fake site: brewsh[.]org
Malicious curl command: hxxps[://]raw[.]brewsh[.]org/Homebrew/install/HEAD/install[.]sh
Atomic Stealer (AMOS): www.virustotal.com/gui/file/389...
⚠️
#malvertising #atomicstealer
⚠️
Fake site: brewsh[.]org
Malicious curl command: hxxps[://]raw[.]brewsh[.]org/Homebrew/install/HEAD/install[.]sh
Atomic Stealer (AMOS): www.virustotal.com/gui/file/389...
⚠️
#malvertising #atomicstealer
February 8, 2025 at 3:26 AM
If you are a developer and use #homebrew, beware of this fraudulent ad on Google.
⚠️
Fake site: brewsh[.]org
Malicious curl command: hxxps[://]raw[.]brewsh[.]org/Homebrew/install/HEAD/install[.]sh
Atomic Stealer (AMOS): www.virustotal.com/gui/file/389...
⚠️
#malvertising #atomicstealer
⚠️
Fake site: brewsh[.]org
Malicious curl command: hxxps[://]raw[.]brewsh[.]org/Homebrew/install/HEAD/install[.]sh
Atomic Stealer (AMOS): www.virustotal.com/gui/file/389...
⚠️
#malvertising #atomicstealer
ClickFix vs. traditional download in new DarkGate campaign
www.malwarebytes.com/blog/news/20...
#ClickFix #malvertising
www.malwarebytes.com/blog/news/20...
#ClickFix #malvertising
ClickFix vs. traditional download in new DarkGate campaign
Social engineering methods are being put to the test to distribute malware.
www.malwarebytes.com
January 31, 2025 at 11:46 PM
ClickFix vs. traditional download in new DarkGate campaign
www.malwarebytes.com/blog/news/20...
#ClickFix #malvertising
www.malwarebytes.com/blog/news/20...
#ClickFix #malvertising
Microsoft advertisers phished via malicious Google ads
www.malwarebytes.com/blog/news/20...
#malvertising #googleads #microsoft #bing
www.malwarebytes.com/blog/news/20...
#malvertising #googleads #microsoft #bing
Microsoft advertisers phished via malicious Google ads
Just days after we uncovered a campaign targeting Google Ads accounts, a similar attack has surfaced, this time aimed at Microsoft...
www.malwarebytes.com
January 30, 2025 at 4:13 PM
Microsoft advertisers phished via malicious Google ads
www.malwarebytes.com/blog/news/20...
#malvertising #googleads #microsoft #bing
www.malwarebytes.com/blog/news/20...
#malvertising #googleads #microsoft #bing
Imagine for a moment that Google allowed a sponsored link to a phishing site for Google ads...
www.malwarebytes.com/blog/news/20...
#GoogleSearch #GoogleAds #malvertising #phishing
www.malwarebytes.com/blog/news/20...
#GoogleSearch #GoogleAds #malvertising #phishing
The great Google Ads heist: criminals ransack advertiser accounts via fake Google ads
An ongoing malvertising campaign steals Google advertiser accounts via fraudulent ads for Google Ads itself.
www.malwarebytes.com
January 15, 2025 at 1:55 PM
Imagine for a moment that Google allowed a sponsored link to a phishing site for Google ads...
www.malwarebytes.com/blog/news/20...
#GoogleSearch #GoogleAds #malvertising #phishing
www.malwarebytes.com/blog/news/20...
#GoogleSearch #GoogleAds #malvertising #phishing
December 28, 2024 at 12:20 AM
December 27, 2024 at 10:47 PM
Malicious Google ad for #Freecad
⚠️
freecad3dmodeling[.]com
freecad3d-download[.]com
hxxps[://]3d-digitals[.]org/downloads/guthub/FreeCAD_Setup_2[.]0[.]74_win_x64[.]zip
#malvertising
⚠️
freecad3dmodeling[.]com
freecad3d-download[.]com
hxxps[://]3d-digitals[.]org/downloads/guthub/FreeCAD_Setup_2[.]0[.]74_win_x64[.]zip
#malvertising
December 22, 2024 at 12:43 AM
Malicious Google ad for #Freecad
⚠️
freecad3dmodeling[.]com
freecad3d-download[.]com
hxxps[://]3d-digitals[.]org/downloads/guthub/FreeCAD_Setup_2[.]0[.]74_win_x64[.]zip
#malvertising
⚠️
freecad3dmodeling[.]com
freecad3d-download[.]com
hxxps[://]3d-digitals[.]org/downloads/guthub/FreeCAD_Setup_2[.]0[.]74_win_x64[.]zip
#malvertising
December 19, 2024 at 10:35 PM
December 18, 2024 at 8:36 PM
December 18, 2024 at 8:34 PM
December 17, 2024 at 6:09 PM
December 17, 2024 at 6:07 PM
December 17, 2024 at 5:01 PM
December 16, 2024 at 11:11 PM