Jérôme Segura
banner
Jérôme Segura
@jeromesegura.com
Security researcher with a special interest for web threats.
Also, this seems like a small feature but much appreciated:
April 30, 2025 at 4:24 AM
Crooks doing quality control the hard way 😂

console.log("!!!WORKING!!!")

#skimming #ecommerce
April 12, 2025 at 3:46 AM
If you manage #wordpress sites using #managewp, watch out for this #phishing campaign via #googleads.

-> menagewp[.]com (ad URL and redirect)

-> orion[.]manaqewp[.]com (phishing page)
March 24, 2025 at 10:36 PM
Scammers are happily abusing multiple platforms at once thanks to lack of controls.

Who's going to protect users here? Google? Facebook?
March 11, 2025 at 5:50 PM
PayPal’s “no-code checkout” abused by scammers

www.malwarebytes.com/blog/scams/2...

#malvertising #techsupportscams
February 28, 2025 at 2:45 AM
SecTopRAT bundled in Chrome installer distributed via Google Ads

📖
www.malwarebytes.com/blog/news/20...

⚠️
sites[.]google[.]com/view/gfbtechd/
chrome[.]browser[.]com[.]de/GoogleChrome.exe

#malvertising #SecTopRAT
February 20, 2025 at 9:51 PM
If you are a developer and use #homebrew, beware of this fraudulent ad on Google.

⚠️
Fake site: brewsh[.]org
Malicious curl command: hxxps[://]raw[.]brewsh[.]org/Homebrew/install/HEAD/install[.]sh
Atomic Stealer (AMOS): www.virustotal.com/gui/file/389...
⚠️

#malvertising #atomicstealer
February 8, 2025 at 3:26 AM
Malicious Google ad for Virtuals Protocol

⚠️ virtnals[.]com

#malvertising
December 28, 2024 at 12:20 AM
Malicious Google ad for Aerodrome Finance

⚠️ aeroclrome[.]finance

#malvertising
December 27, 2024 at 10:47 PM
Malicious Google ad for #Freecad

⚠️
freecad3dmodeling[.]com
freecad3d-download[.]com
hxxps[://]3d-digitals[.]org/downloads/guthub/FreeCAD_Setup_2[.]0[.]74_win_x64[.]zip

#malvertising
December 22, 2024 at 12:43 AM
‘Fix It’ social-engineering scheme impersonates several brands

www.malwarebytes.com/blog/news/20...
December 19, 2024 at 10:35 PM
Malicious Google ad for Netflix

⚠️ +1[-]877[-]906[-]4471

#malvertising
December 18, 2024 at 8:36 PM
Malicious Google ad for onshape 3D

⚠️
onshapeservices[.]com

#malvertising
December 18, 2024 at 8:34 PM
Malicious Google ad for Freecad

⚠️
freecad3design[.]com

#malvertising
December 17, 2024 at 6:09 PM
Malicious Google ad for Rhino 3D

⚠️
rhino3ddev[.]net

#malvertising
December 17, 2024 at 6:07 PM
Malicious Google ad for m⁣y⁣N⁣Y⁣LG⁣B⁣S⁣⁣

⚠️
bluehome[.]uk
essnewyorkplatform[.]com

#malvertising
December 17, 2024 at 5:01 PM
Malicious Google ad for PayPal

⚠️
hxxps[:]//repairsexpert[.]online/services/

#malvertising
December 16, 2024 at 11:11 PM
Malicious Google ad for Malwarebytes

⚠️
hxxps[://]sites[.]google[.]com/view/dexters-antivirus/home

#malvertising
December 16, 2024 at 5:55 PM
Malicious Google ad for New York Life

⚠️
alicehotels[.]com[.]ng
eddutvolkinang[.]com/online/

#malvertising #phishing
December 16, 2024 at 5:16 PM
Malicious Google ad for Kaiser Permanente

⚠️
bellonasoftware[.]com

#malvertising
December 16, 2024 at 4:24 AM
Malicious Google ad for Grammarly

⚠️
grammarly[.]pc-download[.]live

#malvertising
December 13, 2024 at 11:34 PM
Malicious Google ad for Planner 5D

⚠️
planner5ddevelop[.]com

#malvertising
December 13, 2024 at 9:36 PM
Malicious Google ad for eBay

⚠️
fbdecors[.]online

#malvertising
December 13, 2024 at 7:27 PM
Malicious Google ad for PayPal

⚠️
https[:]//sites[.]google.com/view/pay-pal-helpcustomerservic/

#malvertising
December 13, 2024 at 7:10 PM
Malicious Google ad for Microsoft

⚠️
hxxps[://]sites[.]google[.]com/view/micrlochus1011/home

#malvertising
December 12, 2024 at 9:49 PM