Mansour Alhmoud

APT Research Team Leader

Mansour leads Advanced Persistent Threat research within Group-IB’s META Threat Intelligence department, where he drives the investigation of state-sponsored cyber operations — from uncovering novel toolsets and mapping adversary infrastructure to dissecting the tactics, techniques, and procedures that define today’s most sophisticated threat actors. His research directly informs strategic cyber defence decisions for organizations operating across the Middle East, Turkey, and Africa.

With over five years of dedicated experience across advanced threat intelligence, digital forensics and incident response (DFIR), and offensive security, Mansour brings a rare combination of hands-on technical depth and strategic analytical thinking. His work has contributed to the exposure of previously unreported threat actor capabilities, expansion of known adversary targeting profiles, and the production of actionable intelligence that enables defenders to stay ahead of evolving cyber threats.

 

 

Blog posts by Mansour Alhmoud

Tortoiseshell blog image
Advanced Persistent Threats
August 26, 2026
Tortoiseshell: New Toolset and Operational Infrastructure Exposed
Group-IB Threat Intelligence performed enrichment and APT hunting based on recent public data about the Tortoiseshell APT group, leading to the discovery of new samples sharing similarities with known Tortoiseshell malware and additional operational infrastructure.
MuddyWater Strikes Again
Advanced Persistent Threats
February 20, 2026
Operation Olalampo: Inside MuddyWater’s Latest Campaign
MuddyWater APT has launched a new cyber offensive operation, dubbed Operation Olalampo, deploying new malware variants and leveraging Telegram bots for command-and-control. Analysis of the campaign provides a glimpse into the group’s post-exploitation tactics, which largely align with their historical operations.
Advanced Persistent Threats
October 22, 2025
Unmasking MuddyWater’s New Malware Toolkit Driving International Espionage
Group-IB Threat Intelligence has uncovered a sophisticated phishing campaign, attributed with high confidence to the Advanced Persistent Threat (APT) MuddyWater. The attack used a compromised mailbox to distribute Phoenix backdoor malware to international organizations and across the whole Middle East and North Africa region, targeting more than 100 government entities.
Advanced Persistent Threats
September 17, 2025
Tracking MuddyWater in Action: Infrastructure, Malware and Operations during 2025
The blog provides an in-depth look at MuddyWater’s evolution in tooling, targeting, and infrastructure management, suggesting a more mature and capable advanced persistent threat within the META region.
Threat Intelligence
March 13, 2025
ClickFix: The Social Engineering Technique Hackers Use to Manipulate Victims
Discover how the ClickFix social engineering attack exploits human psychology to bypass security. Learn how hackers use this tactic and how to protect against it.