SniperDz Phishing Service Used for Brand Impersonation and Browser Hijacking
Cybercriminals used the SniperDz phishing-as-a-service platform to run brand impersonation scams, abuse browser notifications, and monetize victims long after the first click. A new Group-IB investigation shows that the operation went beyond credential theft and functioned as a wider fraud ecosystem.
The platform offered ready-made phishing infrastructure to low-skilled attackers. According to a Group-IB press release, SniperDz had 80 phishing templates in five languages and impersonated more than 30 major organizations, including PayPal, Facebook, Instagram, Yahoo, Netflix, and Steam.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
The campaigns targeted users across the Middle East and North Africa with fake social media posts. Scammers impersonated telecom providers, politicians, public figures, and government-related pages to promote fake mobile data offers, compensation schemes, subsidies, and investment opportunities.
How the SniperDz Scam Funnel Worked
The attack usually started on Facebook or Instagram. Victims saw posts or ads that appeared to come from trusted local brands or public figures. The offers looked simple and urgent, such as free internet data or financial support.
Instead of sending users directly to an obvious phishing site, attackers routed them through trusted link-aggregation services such as Linktree and Linkbio. The SniperDz research found that this helped attackers hide the final destination and avoid early detection by automated security systems.
Once victims reached attacker-controlled pages, the campaign shifted from social engineering to browser abuse. The pages asked users to click โAllowโ on a browser notification prompt, often while showing a loading spinner or fake verification message.
| Attack stage | What victims saw | Attacker goal |
|---|---|---|
| Social media lure | Fake free data, subsidy, prize, or investment offer | Get users to click |
| Link-aggregation page | A trusted-looking intermediary page | Hide the phishing destination |
| Final landing page | Loading screen and โAllowโ prompt | Capture browser notification permission |
| Monetization | Ads, scams, premium SMS, or redirects | Generate revenue from victim traffic |
Browser Notifications Turned One Click Into Ongoing Access
When victims clicked โAllow,โ the malicious site registered them for browser push notifications. Group-IB found that several campaigns reused the same VAPID public key, which helped researchers link otherwise separate scam flows to the same push-notification ecosystem.
The pages also used browser history manipulation. Researchers found code that injected 10 fake entries into the userโs browser history, creating a โback-button prisonโ that made it harder to leave the scam page.

Some pages also used a tab-under technique. If a victim opened a new tab, the original tab could silently redirect to another attacker-controlled destination. Users who granted permission could later receive scam alerts, ads, and malicious promotions even after closing the original page.
- Review suspicious sites in Chrome notification settings.
- Block unknown sites in Edge notification controls.
- Do not click โAllowโ to claim prizes, free mobile data, subsidies, or investment offers.
- Report unexplained premium SMS or carrier billing charges to your mobile provider.
- Change passwords if you entered credentials on a suspicious page.
Users can stop future browser alerts by removing unfamiliar websites from their browser permission list. Google explains how to manage site alerts in Chrome, while Microsoft provides similar steps for Microsoft Edge.
Operation Ramz Disrupted SniperDz
SniperDz has now been tied to a wider law enforcement action. Group-IB said its intelligence helped INTERPOL and Algerian authorities identify and arrest the alleged primary developer and administrator of the platform.
INTERPOL said Operation Ramz ran across 13 countries in the Middle East and North Africa. The operation resulted in 201 arrests, 382 additional suspects identified, 3,867 victims recorded, and 53 servers seized.
In Algeria, authorities dismantled a phishing-as-a-service website, seized a server, a computer, a mobile phone, and hard drives containing phishing software and scripts. Operation Ramz also involved partners including Group-IB, Kaspersky, the Shadowserver Foundation, Team Cymru, and TrendAI.
| Confirmed detail | Information |
|---|---|
| Platform | SniperDz, also known as JokerDz, StormDz, and SpamDz |
| Activity period | Active since at least 2015 |
| Templates | 80 phishing templates |
| Targeted brands | More than 30 major organizations |
| Associated domains | More than 20,000 unique domains linked to the ecosystem |
| Operation Ramz result | 201 arrests and 53 servers seized across 13 countries |
Why SniperDz Matters for Brands and Users
SniperDz shows how phishing-as-a-service platforms lower the barrier for cybercrime. Attackers no longer need to build phishing kits, manage hosting, or design convincing pages from scratch. They can use ready-made templates and focus on spreading lures through social media.
The case also shows how fraud groups abuse legitimate web features. The campaigns did not always need malware to create harm. They used trusted link services, browser notification prompts, redirects, and carrier billing flows to keep victims inside a monetization funnel.
For companies, this makes brand monitoring more important. Fake pages can appear on social media, link-aggregation platforms, and newly registered domains. For users, the safest approach is to verify offers through official websites and avoid notification prompts tied to promotions, prizes, or account checks.
Indicators Reported by Researchers
Security teams can use the following indicators for awareness and investigation. These indicators should not replace broader detection rules, since phishing infrastructure often changes quickly.
| Type | Indicator | Context |
|---|---|---|
| Domain | win.feezossl[.]xyz | Redirect and tracking domain observed in the scam funnel |
| Domain | win.anababayala[.]com | Redirect and tracking domain observed in the scam funnel |
| Domain | aff.bnaosf1he[.]shop | Domain linked to a campaign impersonating a political figure |
| Domain | offer.raviral[.]com | Previously identified as part of the SniperDz ecosystem |
| IP address | 65.60.9[.]236 | Infrastructure hosted by Horizon IQ |
| IP address | 108.178.23[.]118 | Infrastructure hosted by Horizon IQ |
| IP address | 184.154.10[.]254 | Infrastructure hosted by Horizon IQ |
| VAPID public key | BHR8bZ93X3YNBNQcN_dGRYtnWqdsJXR2bXqq3vhfBL1TpfZqrGKXYxATKGNHa25HyaghKK8ZiaFXbIgJqY2624A | Recurring key used to register browser push subscriptions |
FAQ
SniperDz is a phishing-as-a-service platform that offered phishing templates, hosting infrastructure, and support for cybercriminal campaigns. Researchers linked it to brand impersonation, credential theft, browser notification abuse, and traffic monetization schemes.
The campaigns used fake social media posts that impersonated telecom providers, public figures, politicians, and trusted organizations. Victims were promised free data, subsidies, compensation, prizes, or investment opportunities, then sent through redirect chains to phishing or monetization pages.
The Allow prompt gave the scam site permission to send browser notifications. Once permission was granted, attackers could push ads, scam links, and malicious promotions to the user even after the original page was closed.
Authorities disrupted SniperDz as part of Operation Ramz. INTERPOL and Algerian authorities acted on intelligence from Group-IB, and the alleged primary developer and administrator was arrested.
Users should open their browser site settings, remove notification permissions for unknown websites, close suspicious tabs, clear unwanted redirects, check mobile bills for premium SMS charges, and change any passwords entered on suspicious pages.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages