Ahmed Mohamed Ibrahim
3 articles
-
BlogInside SHADOW-WATER-084: A Steganographic Loader-as-a-Service Delivering Remcos, LXBASE, and More
TrendAI™ Research tracked three campaigns that ship completely different decoy applications and unrelated payloads, all riding one shared toolkit. This analysis covers the full chain, from the pixel data that hides the first stage, through a flexible shared loader to deliver multiple payloads, revealing how adversaries are standardizing their delivery mechanisms.
August 27th, 2026 30 minAhmed Mohamed Ibrahim, Ashish Verma, Deep Patel
Read article -
BlogFrom Extension to Infection: An In-Depth Analysis of the Evelyn Stealer Campaign Targeting Software Developers
This blog entry provides an in-depth analysis of the multistage delivery of the Evelyn information stealer, which was used in a campaign targeting software developers.
January 19th, 2026 6 minAhmed Mohamed Ibrahim
Read article -
BlogBehind the Great Wall: Void Arachne Targets Chinese-Speaking Users With the Winos 4.0 C&C Framework
We recently discovered a new threat actor group that we dubbed Void Arachne. This group targets Chinese-speaking users with malicious Windows Installer (MSI) files in a recent campaign. These MSI files contain legitimate software installer files for AI software and other popular software but are bundled with malicious Winos payloads.
June 19th, 2024 18 minPeter Girnus, Aliakbar Zahravi, Ahmed Mohamed Ibrahim
Read article