INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator

spsingh
By
spsingh
4 Min Read

Ravie LakshmananJun 12, 2026Cybercrime / Phishing

An INTERPOL-led operation final month resulted within the disruption of Sniper Dz, a decade-long phishing-as-a-service (PhaaS) platform, Group-IB mentioned Thursday.

The trouble, codenamed Operation Ramz, occurred between October 2025 and February 2026, and noticed authorities from 13 international locations within the Center East and North Africa (MENA) area making 201 arrests.

Included amongst them was Guedz, the first developer and administrator of Sniper Dz, a PhaaS service that is mentioned to have collected greater than 45,000 sufferer data. The arrest was made by the Algerian Nationwide Police. Through the years, the platform rebranded itself as Joker Dz, Storm Dz, and Spam Dz.

As a part of Operation Ramz, the web site used to supply PhaaS capabilities to different cybercriminals was taken down. Authorities additionally seized {hardware} containing phishing software program and scripts.

“Active since at least 2015, Sniper Dz evolved into a sophisticated criminal platform offering ready-made phishing kits, hosting infrastructure, and operational support to cybercriminals,” the Singapore-headquartered cybersecurity firm mentioned.

Within the years since then, greater than 20,000 distinctive domains related to the PhaaS service have been recognized. The toolkit primarily focused 30 main international organizations, together with PayPal, Fb, Instagram, Yahoo, Netflix, and Steam, utilizing 80 phishing templates deployed in 5 languages, together with Arabic, English, French, Spanish, and Hebrew.

Phishing campaigns utilizing Sniper Dz singled out customers of know-how, social media, and streaming platforms throughout a number of geographies by impersonating in style manufacturers and authorities entities utilizing convincing imitation web sites with the objective of harvesting credentials, private data, and different delicate information.

“Beyond traditional credential theft, the platform also leveraged social engineering techniques that exploited the popularity and credibility of public figures across the Middle East and North Africa,” Group-IB defined. “Threat actors created fake social media accounts impersonating well-known political personalities and used them to promote phishing links disguised as promotional offers or free internet access.”

Sniper Dz was the topic of a complete evaluation by Palo Alto Networks Unit 42 in October 2024, which detailed the risk actor’s use of a Telegram channel with greater than 7,300 subscribers to share tutorial movies and the choices it offers to host the phishing pages by itself infrastructure behind a proxy server.

What made Sniper Dz stand out from the crowded PhaaS market is that it supplied its total infrastructure without cost, making it simpler for aspiring cybercriminals to drag off phishing campaigns at scale. The monetization avenues as an alternative relied on credential theft and sufferer site visitors.

“Stolen credentials could be harvested through phishing campaigns, while users who did not yield credentials could still be redirected into carrier billing fraud, premium SMS subscriptions, browser notification abuse schemes, and other affiliate-driven scam campaigns,” Group-IB mentioned.

Editor’s Notice: That is an up to date model of the unique information article. The preliminary model was printed at: https://thehackernews.com/2026/06/interpol-takes-down-sniper-dz-phishing.html.

Website |  + posts
author avatar
spsingh
Share This Article