SniperDz is an Algerian-linked phishing-as-a-service (PhaaS) platform and criminal fraud ecosystem active since at least 2015. It has also operated under the names JokerDz, StormDz, and SpamDz. The service provided ready-made phishing kits, hosting infrastructure, operational support, and affiliate enablement through Telegram and Facebook channels, lowering the barrier to entry for large numbers of fraud actors. Unlike many subscription-based PhaaS offerings, SniperDz was reported to offer its infrastructure for free and monetize operations through stolen credentials, traffic redirection, carrier billing fraud, premium SMS scams, browser notification abuse, premium-rate call scams, and investment fraud. The platform used dozens of multilingual phishing templates impersonating major global brands across social media, financial services, streaming, gaming, and other online services. Campaigns were especially prominent across the Middle East and North Africa, where operators used fake social media accounts impersonating politicians, public figures, government programs, and telecom providers to lure victims with offers such as free mobile data, gifts, compensation, and subsidies. Victims were commonly routed through trusted link-aggregation services and multi-stage redirect chains before reaching phishing or monetization infrastructure. SniperDz also functioned as a push-notification abuse ecosystem, with campaigns prompting victims to grant browser notification permissions and then monetizing those subscriptions through unsolicited advertisements, scam promotions, and other malicious content. Reported tradecraft included social engineering, phishing, credential harvesting, cloaking, browser history manipulation, tab-under redirection, and traffic distribution based on victim attributes such as device type, geography, and carrier. The platform harvested usernames, passwords, timestamps, and victim geolocation-related data, and investigators linked more than 20,000 domains to the broader ecosystem. The operation was attributed to the threat actor known as Guedz, identified as the developer and administrator. Intelligence sharing with INTERPOL and the Algerian National Police contributed to the disruption of SniperDz during Operation Ramz, a multinational law-enforcement effort across the Middle East and North Africa that resulted in arrests, server seizures, and the takedown of infrastructure associated with the service.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates a phishing-as-a-service platform used in fraudulent campaigns across the Middle East and North Africa, leveraging fake Facebook accounts, social engineering, browser notification abuse, traffic monetization, premium SMS and call fraud, and investment scams.
Recently disrupted phishing service referenced as a comparable example of a platform that lowers the barrier to entry for fraudsters to conduct convincing phishing attacks at scale.
Long-running phishing-as-a-service operation providing free phishing infrastructure and templates, monetizing through credential theft, carrier billing fraud, premium SMS scams, browser notification abuse, and affiliate-driven scam campaigns.
Operated a long-running phishing-as-a-service platform that provided phishing kits, hosting infrastructure, and operational support to cybercriminals, enabling large-scale credential theft and related fraud campaigns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.