SniperDz is a long-running phishing-as-a-service (PhaaS) criminal platform active since at least 2015 and disrupted during INTERPOL-led Operation Ramz. It operated through Telegram and Facebook channels and provided ready-made phishing kits, hosting infrastructure, and operational support that enabled affiliates, including low-skill fraud actors, to conduct phishing campaigns at scale. The platform is also known by the aliases JokerDz, StormDz, and SpamDz. SniperDz specialized in impersonation of major online brands and services through multilingual phishing templates, with reporting linking the ecosystem to tens of thousands of domains and large volumes of phishing pages over many years. Its templates targeted users of payment platforms, social media services, streaming platforms, gaming marketplaces, and other consumer-facing online services. Campaigns were observed in Arabic, English, French, Spanish, and Hebrew, with a strong concentration on victims across the Middle East and North Africa. The ecosystem used social engineering extensively, including fake social media accounts impersonating politicians, public figures, government programs, and telecom providers. Common lures included free internet access, subsidies, compensation, gifts, and promotional offers. Beyond credential harvesting, SniperDz also supported broader fraud monetization through browser notification abuse, premium SMS and carrier-billing scams, premium-rate call schemes, investment scams, and affiliate-driven traffic redirection. Researchers also described SniperDz as a centralized push-notification-as-a-service-enabled fraud ecosystem. Observed campaigns routed victims through intermediary link-aggregation services and attacker-controlled redirect chains, then prompted them to grant browser notification permissions. The operation used cloaking, browser history manipulation, and tab-under techniques to evade analysis, trap users, and sustain post-click monetization. SniperDz additionally offered tooling to adapt phishing content for hosting on legitimate blogging infrastructure, improving resilience and evasion. Attribution linked the platform to an Algeria-based operator known as Guedz, identified as its developer and administrator. Investigators correlated technical artifacts, affiliate recruitment activity, tutorial videos, and long-term social media presence to support attribution. Law enforcement action in Algeria reportedly resulted in the arrest of the primary developer and seizure of hardware containing phishing software and scripts. The actor’s dominant motivation is financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates a phishing-as-a-service platform used in fraudulent campaigns across the Middle East and North Africa, leveraging fake Facebook accounts, social engineering, browser notification abuse, traffic monetization, premium SMS and call fraud, and investment scams.
Recently disrupted phishing service referenced as a comparable example of a platform that lowers the barrier to entry for fraudsters to conduct convincing phishing attacks at scale.
Long-running phishing-as-a-service operation providing free phishing infrastructure and templates, monetizing through credential theft, carrier billing fraud, premium SMS scams, browser notification abuse, and affiliate-driven scam campaigns.
Operated a long-running phishing-as-a-service platform that provided phishing kits, hosting infrastructure, and operational support to cybercriminals, enabling large-scale credential theft and related fraud campaigns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.