Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors sniperdz

Also known as: tracked as, Z-Pentest, JokerDz, StormDz, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, SpamDz, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code

Description

An investigation into phishing activity targeting users across the Middle East and North Africa uncovered SniperDz, a centralized Push-Notification-as-a-Service and Phishing-as-a-Service platform. The operation uses fraudulent Facebook accounts impersonating politicians, public figures, and trusted organizations to promote fake offers including free mobile internet packages and financial compensation. Victims are redirected through trusted link-aggregation services like Linktree and Linkbio to evade detection. SniperDz provides 80 phishing templates mimicking over 30 global brands across financial services, social media, streaming, and gaming platforms. The infrastructure employs browser notification abuse, history manipulation creating a back-button prison, premium SMS subscriptions, premium-rate calls, investment scams, and affiliate marketing for monetization. Analysis revealed over 900 suspicious domains linked to shared hosting infrastructure and a recurring VAPID public key connecting multiple campai...

Goals & Targeting

Targeted Sectors

Financial services
Communications
Entertainment
Media
Defense
Manufacturing
Telecommunications
Government
Chemical
Gaming
Information technology

Targeted Countries / Regions

Algeria
GB
DE
FR
US
TR

AI Analysis

· 1 week ago

Executive Summary

SniperDz is identified as a phishing campaign targeting users across the Middle East and North Africa through fraudulent Facebook accounts impersonating trusted figures. The operation leverages push notifications, browser history manipulation, and redirection via third-party services like Linktree and Linkbio to evade detection. SniperDz provides over 80 phishing templates mimicking global brands for financial gain.

Goals & Targeting

SniperDz's primary goal appears to be financial gain through phishing, investment scams, and fraudulent monetization. The targeting of sectors such as financial services, communications, and entertainment reflects a focus on industries with high customer engagement and sensitive data. The geographic concentration in Algeria suggests an initial operational focus within the Middle East and North Africa region, potentially expanding based on success.

Enhanced Description

SniperDz operates a sophisticated 'Push-Notification-as-a-Service' (P-Naas) and 'Phishing-as-a-Service' (PaaS) platform, enabling attackers to carry out large-scale phishing campaigns. The group uses falsified Facebook accounts to impersonate politicians, public figures, and trusted organizations to spread fake offers such as free mobile internet packages or financial compensation. Victims are directed to malicious links using legitimate-looking third-party services like Linktree and Linkbio to bypass detection mechanisms. The platform offers over 80 phishing templates designed to mimic more than 30 global brands across various sectors, including financial services, social media, streaming, and gaming. Monetization techniques include browser notification abuse, premium SMS subscriptions, investment scams, and affiliate marketing. Analysis has identified over 900 suspicious domains linked to shared hosting infrastructure and the reuse of a single VAPID public key across multiple campaigns, indicating operational persistence and potential association with larger threat networks.

Key Capabilities

  • Phishing template creation and distribution
  • Browser notification abuse for malicious intent
  • History manipulation (back-button prison technique)
  • Premium SMS subscriptions and investment scams
  • Affiliate marketing for monetization
  • Use of third-party link aggregation services to avoid detection

MITRE ATT&CK Tactics

Social Engineering
Credential Access
Defense Evasion

ATT&CK Techniques

T1059
T1566.003

Software / Tooling

Phishing templates for social engineering campaigns
Push notification systems with browser manipulation capabilities
Malware distribution tools (likely)

Campaigns & Victims

SniperDz's campaigns involve large-scale phishing operations targeting individuals through social media platform impersonation. The use of shared infrastructure and recurring identifiers like VAPID keys suggests operational persistence and resourcefulness. Campaign patterns include the rapid deployment of new domains, frequent updates to phishing templates, and a focus on exploit techniques that evade detection. Notable past operations involve investment scams and premium service hijacking, targeting both individual consumers and corporate entities.

IOC Patterns

  • Spear-phishing campaigns originating from fraudulent Facebook accounts
  • Browser notifications leading to malicious domains
  • Redirection through legitimate-looking services like Linktree and Linkbio
  • Shared hosting infrastructure with high domain count
  • Recurring VAPID public keys associated with push notification campaigns

Recommended Actions

  • Implement multi-factor authentication (MFA) for critical accounts to mitigate credential theft risk.
  • Monitor social media channels for suspicious activity and impersonation attempts targeting organizational figures or employees.
  • Use browser extensions or policies blocking unauthorized push notifications as a defense against push-based attacks.
  • Set up DMARC, BIMI, and SPF records for domain authentication to prevent email spoofing and phishing.
  • Regularly audit and update third-party service integrations for vulnerabilities and suspicious activity.

Suggested Tags

Phishing
Fraudulent Activities
Financial-Services-Threats

Confidence Assessment

Confidence in the severity of SniperDz's activities is high, based on documented campaigns and infrastructure analysis. However, limited information is available on their potential ties to state-sponsored actors or organized crime groups. Further clarification of their operational history and specific campaign patterns could enhance understanding.

ATT&CK Techniques

Exfiltration
1 technique
Initial Access
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.group-ib.com — Cited by web research for: JokerDz
  2. attack.mitre.org — Cited by web research for: services
  3. www.group-ib.com — Cited by web research for: Dark
  4. unit42.paloaltonetworks.com — Cited by web research for: ClickFix
  5. attack.mitre.org — Cited by web research for: Rogue
  6. unit42.paloaltonetworks.com — Cited by web research for: US
  7. gbhackers.com — Cited by web research for: Turkey

Intel Summary

40

Techniques

41

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

Phishing
Fraudulent Activities
Financial-Services-Threats

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
55%
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.