Also known as: tracked as, Z-Pentest, JokerDz, StormDz, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, SpamDz, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code
An investigation into phishing activity targeting users across the Middle East and North Africa uncovered SniperDz, a centralized Push-Notification-as-a-Service and Phishing-as-a-Service platform. The operation uses fraudulent Facebook accounts impersonating politicians, public figures, and trusted organizations to promote fake offers including free mobile internet packages and financial compensation. Victims are redirected through trusted link-aggregation services like Linktree and Linkbio to evade detection. SniperDz provides 80 phishing templates mimicking over 30 global brands across financial services, social media, streaming, and gaming platforms. The infrastructure employs browser notification abuse, history manipulation creating a back-button prison, premium SMS subscriptions, premium-rate calls, investment scams, and affiliate marketing for monetization. Analysis revealed over 900 suspicious domains linked to shared hosting infrastructure and a recurring VAPID public key connecting multiple campai...
Targeted Sectors
Targeted Countries / Regions
Executive Summary
SniperDz is identified as a phishing campaign targeting users across the Middle East and North Africa through fraudulent Facebook accounts impersonating trusted figures. The operation leverages push notifications, browser history manipulation, and redirection via third-party services like Linktree and Linkbio to evade detection. SniperDz provides over 80 phishing templates mimicking global brands for financial gain.
Goals & Targeting
SniperDz's primary goal appears to be financial gain through phishing, investment scams, and fraudulent monetization. The targeting of sectors such as financial services, communications, and entertainment reflects a focus on industries with high customer engagement and sensitive data. The geographic concentration in Algeria suggests an initial operational focus within the Middle East and North Africa region, potentially expanding based on success.
Enhanced Description
SniperDz operates a sophisticated 'Push-Notification-as-a-Service' (P-Naas) and 'Phishing-as-a-Service' (PaaS) platform, enabling attackers to carry out large-scale phishing campaigns. The group uses falsified Facebook accounts to impersonate politicians, public figures, and trusted organizations to spread fake offers such as free mobile internet packages or financial compensation. Victims are directed to malicious links using legitimate-looking third-party services like Linktree and Linkbio to bypass detection mechanisms. The platform offers over 80 phishing templates designed to mimic more than 30 global brands across various sectors, including financial services, social media, streaming, and gaming. Monetization techniques include browser notification abuse, premium SMS subscriptions, investment scams, and affiliate marketing. Analysis has identified over 900 suspicious domains linked to shared hosting infrastructure and the reuse of a single VAPID public key across multiple campaigns, indicating operational persistence and potential association with larger threat networks.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
SniperDz's campaigns involve large-scale phishing operations targeting individuals through social media platform impersonation. The use of shared infrastructure and recurring identifiers like VAPID keys suggests operational persistence and resourcefulness. Campaign patterns include the rapid deployment of new domains, frequent updates to phishing templates, and a focus on exploit techniques that evade detection. Notable past operations involve investment scams and premium service hijacking, targeting both individual consumers and corporate entities.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the severity of SniperDz's activities is high, based on documented campaigns and infrastructure analysis. However, limited information is available on their potential ties to state-sponsored actors or organized crime groups. Further clarification of their operational history and specific campaign patterns could enhance understanding.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
41
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics