An INTERPOL-led operation codenamed Operation Ramz has successfully disrupted Sniper Dz, a decade-old phishing-as-a-service (PhaaS) platform, resulting in 201 arrests across 13 countries in the Middle East and North Africa (MENA) region. The operation, conducted between October 2025 and February 2026, included the arrest of Guedz, the primary developer and administrator of Sniper Dz, by the Algerian National Police.
According to Group-IB, Sniper Dz had been active since at least 2015 and evolved into a sophisticated criminal platform offering ready-made phishing kits, hosting infrastructure, and operational support. The platform rebranded itself as Joker Dz, Storm Dz, and Spam Dz over the years. Authorities seized hardware containing phishing software and scripts, and took down the website used to offer PhaaS capabilities.
More than 20,000 unique domains associated with Sniper Dz have been identified. The toolkit primarily targeted 30 major global organizations, including PayPal, Facebook, Instagram, Yahoo, Netflix, and Steam, using 80 phishing templates deployed in five languages: Arabic, English, French, Spanish, and Hebrew. Phishing campaigns impersonated popular brands and government entities to harvest credentials, personal information, and other sensitive data.
Beyond traditional credential theft, the platform leveraged social engineering techniques exploiting the popularity of public figures across the MENA region. Threat actors created fake social media accounts impersonating political personalities to promote phishing links disguised as promotional offers or free internet access. Sniper Dz offered its entire infrastructure for free, monetizing through credential theft and victim traffic, including carrier billing fraud, premium SMS subscriptions, and browser notification abuse schemes.
CVEs: CVE-2026-11645
Attack groups: Guedz
Malware: Sniper Dz, Joker Dz, Storm Dz, Spam Dz
Companies: Group-IB, Palo Alto Networks
Products: Unit 42
Events: Operation Ramz
Original source: thehackernews.com