Threat actors are leveraging a sophisticated Phishing-as-a-Service (PhaaS) platform named SniperDz to impersonate trusted brands, public figures, and politicians.
Recently observed targeting users in the Middle East and North Africa (MENA), these campaigns trick victims into clicking fake promotional offers. Instead of receiving free internet or financial aid, victims are pulled into a massive fraud ecosystem.
SniperDz acts as a turnkey operation for cybercriminals. The platform provides an extensive library of 80 distinct phishing templates that mimic over 30 global brands, including PayPal, Netflix, Steam, and local telecommunications providers.
By using these ready-made templates, hackers can launch convincing credential theft campaigns with very little technical skill. However, recent analysis by Group-IB reveals that stealing passwords is just one part of a much broader monetization engine.
To evade automated security scanners and web crawlers, SniperDz employs aggressive traffic cloaking. When security tools inspect the campaign links, the platform actively suppresses malicious content and serves benign error pages.
This allows the underlying infrastructure to remain hidden while actual victims are seamlessly routed toward the threat actor’s traps.
SniperDz Powers Brand Impersonation
The attack sequence begins with localized social media advertisements. To bypass security filters on platforms like Facebook and Instagram, attackers do not link directly to malicious websites.
Instead, they hijack the reputation of legitimate link-aggregation services like Linktree and Linkbio.
When a user clicks a link on a scammer’s social media profile, they land on a decoy page hosted on a trusted domain, making it difficult for automated defenses to flag the operation.
Once a victim clicks through the decoy offer, they are funneled out of the trusted service and into the attacker’s core infrastructure. Here, scammers use aggressive browser-hijacking tactics.
Users encounter a fake loading screen instructing them to click “Allow” to verify their identity.
If they comply, they unknowingly subscribe to malicious browser push notifications, granting the attackers a persistent foothold to push spam and scams directly to the victim’s device.
Depending on the victim’s profile, they might be redirected to premium-rate call scams, where they are tricked into calling a phone number to claim a fake prize, racking up massive charges on their carrier bill.
Alternatively, the platform uses deceptive quizzes to enroll users in recurring premium SMS subscriptions secretly.
Group-IB analysts successfully mapped this sprawling operation by extracting a critical Indicator of Compromise: a recurring VAPID (Voluntary Application Server Identification) public key.
Because this specific key was used to register the push notifications across multiple campaigns, researchers could connect seemingly unrelated scams back to the centralized SniperDz ecosystem.
By pivoting on this shared infrastructure fingerprint, investigators tied the operation to interconnected IP addresses and more than 900 suspicious domains.
Indicators of Compromise
| IOC Type | Value / Indicator | Description |
|---|---|---|
| VAPID Public Key | BHR8bZ93X3YNBNQcN_dGRYtnWqdsJXR2bXqq3vhfBL1TpfZqrGKXYxATKGNHa25HyaghKK8ZiaFXbIgJqY2624A | Shared push-notification registration key across multiple scam campaigns. |
| Domain Name | win.feezossl[.]xyz | Phishing domain distributing localized telecom scams. |
| Domain Name | win.anababayala[.]com |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.
The post Hackers Abuse SniperDz PhaaS for Brand Impersonation Attacks appeared first on Cyber Security News.
Discover more from RSS Feeds Cloud
Subscribe to get the latest posts sent to your email.
