
An INTERPOL-coordinated operation last month led to the dismantling of Sniper Dz, a phishing-as-a-service (PhaaS) platform that had been active for a decade, Group-IB reported Thursday.
The initiative, called Operation Ramz, ran from October 2025 to February 2026, with authorities from 13 nations in the Middle East and North Africa (MENA) region carrying out 201 arrests.
Among those detained was Guedz, the main developer and administrator of Sniper Dz, a PhaaS service believed to have gathered over 45,000 victim records. The arrest was executed by the Algerian National Police. Throughout its existence, the platform rebranded as Joker Dz, Storm Dz, and Spam Dz.
As part of Operation Ramz, the website used to provide PhaaS capabilities to other cybercriminals was shut down. Officials also confiscated hardware containing phishing software and scripts.
"Active since at least 2015, Sniper Dz developed into a sophisticated criminal platform offering ready-made phishing kits, hosting infrastructure, and operational support to cybercriminals," stated the Singapore-based cybersecurity firm.
In the years since, more than 20,000 unique domains linked to the PhaaS service have been identified. The toolkit primarily targeted 30 major global organizations, such as PayPal, Facebook, Instagram, Yahoo, Netflix, and Steam, utilizing 80 phishing templates deployed in five languages, including Arabic, English, French, Spanish, and Hebrew.
Phishing campaigns employing Sniper Dz singled out users of technology, social media, and streaming platforms across multiple regions by impersonating popular brands and government entities through convincing imitation websites aimed at harvesting credentials, personal information, and other sensitive data.
"Beyond traditional credential theft, the platform also leveraged social engineering techniques that exploited the popularity and credibility of public figures across the Middle East and North Africa," Group-IB explained. "Threat actors created fake social media accounts impersonating well-known political personalities and used them to promote phishing links disguised as promotional offers or free internet access."
Sniper Dz was the focus of a detailed analysis by Palo Alto Networks Unit 42 in October 2024, which outlined the threat actor's use of a Telegram channel with over 7,300 subscribers to share tutorial videos and the options it provides to host phishing pages on its own infrastructure behind a proxy server.
What set Sniper Dz apart in the crowded PhaaS market was that it offered its entire infrastructure for free, making it easier for aspiring cybercriminals to execute phishing campaigns at scale. Instead, monetization avenues relied on credential theft and victim traffic.
"Stolen credentials could be harvested through phishing campaigns, while users who did not yield credentials could still be redirected into carrier billing fraud, premium SMS subscriptions, browser notification abuse schemes, and other affiliate-driven scam campaigns," Group-IB said.