SniperDz Phishing Service Used for Brand Impersonation and Browser Hijacking


Cybercriminals used the SniperDz phishing-as-a-service platform to run brand impersonation scams, abuse browser notifications, and monetize victims long after the first click. A new Group-IB investigation shows that the operation went beyond credential theft and functioned as a wider fraud ecosystem.

The platform offered ready-made phishing infrastructure to low-skilled attackers. According to a Group-IB press release, SniperDz had 80 phishing templates in five languages and impersonated more than 30 major organizations, including PayPal, Facebook, Instagram, Yahoo, Netflix, and Steam.

The campaigns targeted users across the Middle East and North Africa with fake social media posts. Scammers impersonated telecom providers, politicians, public figures, and government-related pages to promote fake mobile data offers, compensation schemes, subsidies, and investment opportunities.

How the SniperDz Scam Funnel Worked

The attack usually started on Facebook or Instagram. Victims saw posts or ads that appeared to come from trusted local brands or public figures. The offers looked simple and urgent, such as free internet data or financial support.

Instead of sending users directly to an obvious phishing site, attackers routed them through trusted link-aggregation services such as Linktree and Linkbio. The SniperDz research found that this helped attackers hide the final destination and avoid early detection by automated security systems.

Once victims reached attacker-controlled pages, the campaign shifted from social engineering to browser abuse. The pages asked users to click โ€œAllowโ€ on a browser notification prompt, often while showing a loading spinner or fake verification message.

Attack stageWhat victims sawAttacker goal
Social media lureFake free data, subsidy, prize, or investment offerGet users to click
Link-aggregation pageA trusted-looking intermediary pageHide the phishing destination
Final landing pageLoading screen and โ€œAllowโ€ promptCapture browser notification permission
MonetizationAds, scams, premium SMS, or redirectsGenerate revenue from victim traffic

Browser Notifications Turned One Click Into Ongoing Access

When victims clicked โ€œAllow,โ€ the malicious site registered them for browser push notifications. Group-IB found that several campaigns reused the same VAPID public key, which helped researchers link otherwise separate scam flows to the same push-notification ecosystem.

The pages also used browser history manipulation. Researchers found code that injected 10 fake entries into the userโ€™s browser history, creating a โ€œback-button prisonโ€ that made it harder to leave the scam page.

Typical SniperDz scam victim funnel (Source – Group-IB)

Some pages also used a tab-under technique. If a victim opened a new tab, the original tab could silently redirect to another attacker-controlled destination. Users who granted permission could later receive scam alerts, ads, and malicious promotions even after closing the original page.

  • Review suspicious sites in Chrome notification settings.
  • Block unknown sites in Edge notification controls.
  • Do not click โ€œAllowโ€ to claim prizes, free mobile data, subsidies, or investment offers.
  • Report unexplained premium SMS or carrier billing charges to your mobile provider.
  • Change passwords if you entered credentials on a suspicious page.

Users can stop future browser alerts by removing unfamiliar websites from their browser permission list. Google explains how to manage site alerts in Chrome, while Microsoft provides similar steps for Microsoft Edge.

Operation Ramz Disrupted SniperDz

SniperDz has now been tied to a wider law enforcement action. Group-IB said its intelligence helped INTERPOL and Algerian authorities identify and arrest the alleged primary developer and administrator of the platform.

INTERPOL said Operation Ramz ran across 13 countries in the Middle East and North Africa. The operation resulted in 201 arrests, 382 additional suspects identified, 3,867 victims recorded, and 53 servers seized.

In Algeria, authorities dismantled a phishing-as-a-service website, seized a server, a computer, a mobile phone, and hard drives containing phishing software and scripts. Operation Ramz also involved partners including Group-IB, Kaspersky, the Shadowserver Foundation, Team Cymru, and TrendAI.

Confirmed detailInformation
PlatformSniperDz, also known as JokerDz, StormDz, and SpamDz
Activity periodActive since at least 2015
Templates80 phishing templates
Targeted brandsMore than 30 major organizations
Associated domainsMore than 20,000 unique domains linked to the ecosystem
Operation Ramz result201 arrests and 53 servers seized across 13 countries

Why SniperDz Matters for Brands and Users

SniperDz shows how phishing-as-a-service platforms lower the barrier for cybercrime. Attackers no longer need to build phishing kits, manage hosting, or design convincing pages from scratch. They can use ready-made templates and focus on spreading lures through social media.

The case also shows how fraud groups abuse legitimate web features. The campaigns did not always need malware to create harm. They used trusted link services, browser notification prompts, redirects, and carrier billing flows to keep victims inside a monetization funnel.

For companies, this makes brand monitoring more important. Fake pages can appear on social media, link-aggregation platforms, and newly registered domains. For users, the safest approach is to verify offers through official websites and avoid notification prompts tied to promotions, prizes, or account checks.

Indicators Reported by Researchers

Security teams can use the following indicators for awareness and investigation. These indicators should not replace broader detection rules, since phishing infrastructure often changes quickly.

TypeIndicatorContext
Domainwin.feezossl[.]xyzRedirect and tracking domain observed in the scam funnel
Domainwin.anababayala[.]comRedirect and tracking domain observed in the scam funnel
Domainaff.bnaosf1he[.]shopDomain linked to a campaign impersonating a political figure
Domainoffer.raviral[.]comPreviously identified as part of the SniperDz ecosystem
IP address65.60.9[.]236Infrastructure hosted by Horizon IQ
IP address108.178.23[.]118Infrastructure hosted by Horizon IQ
IP address184.154.10[.]254Infrastructure hosted by Horizon IQ
VAPID public keyBHR8bZ93X3YNBNQcN_dGRYtnWqdsJXR2bXqq3vhfBL1TpfZqrGKXYxATKGNHa25HyaghKK8ZiaFXbIgJqY2624ARecurring key used to register browser push subscriptions

FAQ

What is SniperDz?

SniperDz is a phishing-as-a-service platform that offered phishing templates, hosting infrastructure, and support for cybercriminal campaigns. Researchers linked it to brand impersonation, credential theft, browser notification abuse, and traffic monetization schemes.

How did SniperDz campaigns trick users?

The campaigns used fake social media posts that impersonated telecom providers, public figures, politicians, and trusted organizations. Victims were promised free data, subsidies, compensation, prizes, or investment opportunities, then sent through redirect chains to phishing or monetization pages.

Why did the scam ask users to click Allow?

The Allow prompt gave the scam site permission to send browser notifications. Once permission was granted, attackers could push ads, scam links, and malicious promotions to the user even after the original page was closed.

Was SniperDz taken down?

Authorities disrupted SniperDz as part of Operation Ramz. INTERPOL and Algerian authorities acted on intelligence from Group-IB, and the alleged primary developer and administrator was arrested.

What should users do if they clicked Allow on a suspicious site?

Users should open their browser site settings, remove notification permissions for unknown websites, close suspicious tabs, clear unwanted redirects, check mobile bills for premium SMS charges, and change any passwords entered on suspicious pages.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages