INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Lazarus Group Disrupts SniperDz Phishing Network
| 2026-06-11 16:18 MEDIUM HIGH PHISHING & SOCIAL ENGINEERING STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
The threat actor behind the Sniper Dz phishing platform has been dismantled through an INTERPOL-led operation, resulting in the disruption of a decade-long service that offered ready-made phishing kits and operational support to cybercriminals. Authorities seized hardware containing phishing software and scripts, targeting 30 major global organizations including PayPal, Facebook, Instagram, Yahoo, Netflix, and Steam. The platform leveraged social engineering techniques to exploit public figures' credibility across the Middle East and North Africa, making it a sophisticated criminal operation that exploited vulnerabilities in technology, social media, and streaming platforms.
Technical Mitigations AI-generated
* Implement robust security measures, such as encryption and secure authentication protocols, to protect user data and prevent phishing attacks.
* Regularly update software and systems to patch vulnerabilities and address known exploits, reducing the risk of exploitation by cybercriminals.
* Conduct thorough network monitoring and intrusion detection system (IDS) scans to identify potential threats and alert administrators promptly.
* Utilize secure communication channels, such as end-to-end encrypted messaging apps or email services, for sensitive communications with users and partners.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ha•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation Takes DownOperation Takes DownOperation RamzOperation Ramz
Target & Sectors
AFRICA
AFRICA
MENA
MENA
mediamedia
Incident Timeline
at least 2015
Threat actors used INTERPOL's cybercrime division to disrupt SniperDz, a global PhaaS platform.
Click on any entity below to view its context and source!
tactic
Phishing
SniperDz: A Global Phishing-as-a-Service Platform
SniperDz is a PhaaS platform that has been running since at least 2015.
tactic
T1566 - Phishing
SniperDz: A Global Phishing-as-a-Service Platform
SniperDz is a PhaaS platform that has been running since at least 2015.
between October 2025
Threat actors used INTERPOL to target SniperDz in a raid that was part of Operation Ramz, which ran between October 2025 and February 2026.
Click on any entity below to view its context and source!
campaign
Operation Ramz
This raid was part of a broader threat mitigation initiative called Operation Ramz that ran between October 2025 and 28 February 2026.
The effort, codenamed
Operation Ramz
, took place between October 2025 and February 2026, and saw authorities from 13 countries in the Middle East and North Africa (MENA) region making 201 arrests.
general_metric
13 nations
The effort, codenamed
Operation Ramz
, took place between October 2025 and February 2026, and saw authorities from 13 countries in the Middle East and North Africa (MENA) region making 201 arrests.
general_metric
201 arrests
The effort, codenamed
Operation Ramz
, took place between October 2025 and February 2026, and saw authorities from 13 countries in the Middle East and North Africa (MENA) region making 201 arrests.
target_region
MENA
The effort, codenamed
Operation Ramz
, took place between October 2025 and February 2026, and saw authorities from 13 countries in the Middle East and North Africa (MENA) region making 201 arrests.
source_region
AFRICA
The effort, codenamed
Operation Ramz
, took place between October 2025 and February 2026, and saw authorities from 13 countries in the Middle East and North Africa (MENA) region making 201 arrests.
October 2025
Threat actors used INTERPOL's database to identify and target individuals associated with the SniperDz phishing network.
Click on any entity below to view its context and source!
campaign
Operation Ramz
The crackdown, dubbed
Operation Ramz
, ran from October 2025 to February 2026 across 13 countries in the Middle East and North Africa (MENA) region.
general_metric
13 nations
The crackdown, dubbed
Operation Ramz
, ran from October 2025 to February 2026 across 13 countries in the Middle East and North Africa (MENA) region.
target_region
MENA
The crackdown, dubbed
Operation Ramz
, ran from October 2025 to February 2026 across 13 countries in the Middle East and North Africa (MENA) region.
target_region
AFRICA
The crackdown, dubbed
Operation Ramz
, ran from October 2025 to February 2026 across 13 countries in the Middle East and North Africa (MENA) region.
28 February 2026
Threat actors used INTERPOL's database to target SniperDz in a raid that disrupted their phishing network.
Click on any entity below to view its context and source!
campaign
Operation Ramz
This raid was part of a broader threat mitigation initiative called Operation Ramz that ran between October 2025 and 28 February 2026.
February 2026
Threat actors used INTERPOL to disrupt the SniperDz phishing network.
Click on any entity below to view its context and source!
attribution
Operation Ramz
The effort, codenamed
Operation Ramz
, took place between October 2025 and February 2026, and saw authorities from 13 countries in the Middle East and North Africa (MENA) region making 201 arrests.
The crackdown, dubbed
Operation Ramz
, ran from October 2025 to February 2026 across 13 countries in the Middle East and North Africa (MENA) region.
general_metric
13 nations
The effort, codenamed
Operation Ramz
, took place between October 2025 and February 2026, and saw authorities from 13 countries in the Middle East and North Africa (MENA) region making 201 arrests.
The crackdown, dubbed
Operation Ramz
, ran from October 2025 to February 2026 across 13 countries in the Middle East and North Africa (MENA) region.
general_metric
201 arrests
The effort, codenamed
Operation Ramz
, took place between October 2025 and February 2026, and saw authorities from 13 countries in the Middle East and North Africa (MENA) region making 201 arrests.
target_region
MENA
The effort, codenamed
Operation Ramz
, took place between October 2025 and February 2026, and saw authorities from 13 countries in the Middle East and North Africa (MENA) region making 201 arrests.
The crackdown, dubbed
Operation Ramz
, ran from October 2025 to February 2026 across 13 countries in the Middle East and North Africa (MENA) region.
source_region
AFRICA
The effort, codenamed
Operation Ramz
, took place between October 2025 and February 2026, and saw authorities from 13 countries in the Middle East and North Africa (MENA) region making 201 arrests.
The crackdown, dubbed
Operation Ramz
, ran from October 2025 to February 2026 across 13 countries in the Middle East and North Africa (MENA) region.
2026/05/13
Ravie Lakshmanan and Group-IB worked with INTERPOL to disrupt Sniper Dz, a phishing-as-a-service platform.
Click on any entity below to view its context and source!
tactic
Phishing
Ravie Lakshmanan
Jun 12, 2026
Cybercrime / Phishing
An INTERPOL-led operation last month resulted in the disruption of
Sniper Dz
, a decade-long phishing-as-a-service (PhaaS) platform, Group-IB said Thursday.
tactic
T1566 - Phishing
Ravie Lakshmanan
Jun 12, 2026
Cybercrime / Phishing
An INTERPOL-led operation last month resulted in the disruption of
Sniper Dz
, a decade-long phishing-as-a-service (PhaaS) platform, Group-IB said Thursday.
organisation
INTERPOL
Ravie Lakshmanan
Jun 12, 2026
Cybercrime / Phishing
An INTERPOL-led operation last month resulted in the disruption of
Sniper Dz
, a decade-long phishing-as-a-service (PhaaS) platform, Group-IB said Thursday.
organisation
Group-IB
Ravie Lakshmanan
Jun 12, 2026
Cybercrime / Phishing
An INTERPOL-led operation last month resulted in the disruption of
Sniper Dz
, a decade-long phishing-as-a-service (PhaaS) platform, Group-IB said Thursday.
general_metric
12 Jun
Ravie Lakshmanan
Jun 12, 2026
Cybercrime / Phishing
An INTERPOL-led operation last month resulted in the disruption of
Sniper Dz
, a decade-long phishing-as-a-service (PhaaS) platform, Group-IB said Thursday.
18 May
On 18 May, INTERPOL released its results in a press statement regarding the disruption of the SniperDz phishing network.
2026/06/11
Phishing actors used INTERPOL's cybercrime platform to target and disrupt the SniperDz phishing network.
Click on any entity below to view its context and source!
tactic
Phishing
Today, the cybercrime platform has a global reach and has sophisticated offerings, including ready-made phishing kits, infrastructure hosting and operational support to cybercriminals.
June 11
Algeria's government arrested the primary developer of SniperDz, a notorious phisher.
Click on any entity below to view its context and source!
source_region
Algeria
On June 11, Group-IB, one Interpol’s main partners for this effort,
revealed
that the operation led to the takedown of SniperDz and the arrest of its primary developer in Algeria.
between 2023 and 2024 alone
Palo Alto Networks' Unit 42 discovered over 140,000 phishing pages associated with SniperDz between 2023 and 2024.
Click on any entity below to view its context and source!
tactic
Phishing
In
2024
, Palo Alto Networks’ Unit 42 said it had discovered over 140,000 phishing pages associated with SniperDz between 2023 and 2024 alone.
organisation
Palo Alto Networks’ Unit
In
2024
, Palo Alto Networks’ Unit 42 said it had discovered over 140,000 phishing pages associated with SniperDz between 2023 and 2024 alone.
2026/06/11
SniperDz was taken down by INTERPOL Operation Ramz.
Click on any entity below to view its context and source!
organisation
Operation Ramz
According to INTERPOL’s
press release
, Operation Ramz covered 13 nations, including Egypt, Morocco, Jordan, and Qatar, leading to 201 arrests and the seizure of 53 malicious servers.
As part of Operation Ramz, the website used to offer PhaaS capabilities to other cybercriminals was taken down.
infrastructure
53 malicious servers
According to INTERPOL’s
press release
, Operation Ramz covered 13 nations, including Egypt, Morocco, Jordan, and Qatar, leading to 201 arrests and the seizure of 53 malicious servers.
The results,
announced by Interpol at the end of May
, included 201 arrests, 53 servers seized and 382 suspects and 3867 victims identified.
organisation
Hackread.com
Decade-Long SniperDz Phishing Network on Telegram (Image credit: Hackread.com)
About Operation Ramz
victims
3867 victims
The results,
announced by Interpol at the end of May
, included 201 arrests, 53 servers seized and 382 suspects and 3867 victims identified.
victims
15 forced workers
During the mitigation process in Jordan, investigators tracked an investment scam platform run by 15 forced workers.
organisation
Telegram
Operating via Telegram and Facebook channels, SniperDz allowed anyone, even novice hackers, to use its toolkit of 80
ready-made phishing templates
for free to create fake login pages and trick people into giving away their login credentials (usernames – passwords) and other personal data.
organisation
PayPal
The phishing platform allowed scammers to target users on around 30 popular platforms, including PayPal, Facebook, Instagram, Netflix, and Steam, via more than 20,000 domains.
The toolkit primarily targeted 30 major global organizations, including PayPal, Facebook, Instagram, Yahoo, Netflix, and Steam, using 80 phishing templates deployed in five languages, including Arabic, English, French, Spanish, and Hebrew.
Over the past nine years, Group-IB identified more than 20,000 unique domains associated with SniperDz that impersonated at least 30 major global organizations, including PayPal, Facebook, Instagram, Yahoo, Netflix and Steam.
infrastructure
20,000 domains
The phishing platform allowed scammers to target users on around 30 popular platforms, including PayPal, Facebook, Instagram, Netflix, and Steam, via more than 20,000 domains.
Over the past nine years, Group-IB identified more than 20,000 unique domains associated with SniperDz that impersonated at least 30 major global organizations, including PayPal, Facebook, Instagram, Yahoo, Netflix and Steam.
In the years since then, more than 20,000 unique domains associated with the PhaaS service have been identified.
organisation
INTERPOL Operation Takes Down Sniper Dz
INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator.
victims
30 major global organizations
The toolkit primarily targeted 30 major global organizations, including PayPal, Facebook, Instagram, Yahoo, Netflix, and Steam, using 80 phishing templates deployed in five languages, including Arabic, English, French, Spanish, and Hebrew.
Over the past nine years, Group-IB identified more than 20,000 unique domains associated with SniperDz that impersonated at least 30 major global organizations, including PayPal, Facebook, Instagram, Yahoo, Netflix and Steam.
organisation
INTERPOL
Interpol Dismantles SniperDz Phishing-as-a-Service Platform.
Tracking the Infrastructure
As per the details shared by INTERPOL and Group-IB, this PhaaS network was launched in 2015 but evaded detection for so long because the admins constantly changed its name.
organisation
Group-IB
Cybersecurity firm Group-IB has revealed that a recent Interpol-led cybercrime law enforcement operation has led to the takedown of an established phishing-as-a-service (PhaaS) platform and the arrest of its main operator developer.
Tracking the Infrastructure
As per the details shared by INTERPOL and Group-IB, this PhaaS network was launched in 2015 but evaded detection for so long because the admins constantly changed its name.
organisation
Group
Over the past nine years, Group-IB identified more than 20,000 unique domains associated with SniperDz that impersonated at least 30 major global organizations, including PayPal, Facebook, Instagram, Yahoo, Netflix and Steam.
In 2024, Group-IB cybersecurity researchers detected fake Facebook accounts of politicians in the Middle East and North Africa delivering malicious links.
organisation
JokerDz, StormDz
The platform was also known as JokerDz, StormDz, and SpamDz.
organisation
SpamDz
The platform was also known as JokerDz, StormDz, and SpamDz.
organisation
Guedz
With the support of INTERPOL, slowly, information started emerging; the code’s developer turned out to be a threat actor known online as Guedz.
data_breach
45,000 victim records
The scale of its reach became concrete in 2016, when the platform published statistics showing that campaigns run through its service had already collected more than 45,000 victim records.
Included among them was Guedz, the primary developer and administrator of Sniper Dz, a PhaaS service that's said to have collected more than 45,000 victim records.
organisation
Sniper Dz
Included among them was Guedz, the primary developer and administrator of Sniper Dz, a PhaaS service that's said to have collected more than 45,000 victim records.
infrastructure
3,867 compromised endpoints
Over 3,867 compromised endpoints and victims were identified.
Jun 12, 2026
Threat actors used INTERPOL's database to identify and target SniperDz in an operation aimed at disrupting the sniper phishing network.
Tactical Metrics
Metrics
infrastructure
53
Malicious Servers
Click for context!
According to INTERPOL’s
press release
, Operation Ramz covered 13 nations, including Egypt, Morocco, Jordan, and Qatar, leading to 201 arrests and the seizure of 53 malicious servers.
The results,
announced by Interpol at the end of May
, included 201 arrests, 53 servers seized and 382 suspects and 3867 victims identified.
Metrics
victims
15
Forced Workers
During the mitigation process in Jordan, investigators tracked an investment scam platform run by 15 forced workers.
Metrics
infrastructure
20,000
Domains
The phishing platform allowed scammers to target users on around 30 popular platforms, including PayPal, Facebook, Instagram, Netflix, and Steam, via more than 20,000 domains.
In the years since then, more than 20,000 unique domains associated with the PhaaS service have been identified.
Over the past nine years, Group-IB identified more than 20,000 unique domains associated with SniperDz that impersonated at least 30 major global organizations, including PayPal, Facebook, Instagram, Yahoo, Netflix and Steam.
Metrics
data_breach
45,000
Victim Records
The scale of its reach became concrete in 2016, when the platform published statistics showing that campaigns run through its service had already collected more than 45,000 victim records.
Included among them was Guedz, the primary developer and administrator of Sniper Dz, a PhaaS service that's said to have collected more than 45,000 victim records.
Metrics
infrastructure
3,867
Compromised Endpoints
Over 3,867 compromised endpoints and victims were identified.
Metrics
victims
30
Major Global Organizations
The toolkit primarily targeted 30 major global organizations, including PayPal, Facebook, Instagram, Yahoo, Netflix, and Steam, using 80 phishing templates deployed in five languages, including Arabic, English, French, Spanish, and Hebrew.
Over the past nine years, Group-IB identified more than 20,000 unique domains associated with SniperDz that impersonated at least 30 major global organizations, including PayPal, Facebook, Instagram, Yahoo, Netflix and Steam.
Metrics
victims
3,867
Victims
The results,
announced by Interpol at the end of May
, included 201 arrests, 53 servers seized and 382 suspects and 3867 victims identified.
Intelligence Sources
HackRead
2026-06-11
The Hacker News
2026-06-12
HackRead
2026-06-11
Infosecurity-Magazine
2026-06-11
Interpol Dismantles SniperDz Phishing-as-a-Service Platform
Infosecurity-Magazine
The Hacker News
2026-06-12
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T10:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
15x
timeline
Temporal Reference
2024
date
13x
organisation
Identified Entity
Operation Ramz
entity
5x
target region
Target Country
Egypt
country
5x
source region
Origin Country
Morocco
country
5x
attribution
Attributing Entity
Group-IB
authority
3x
industry
Targeted Sector
Technology
sector
2x
campaign
Campaign
Operation Ramz
operation
2x
tactic
Cyber Operation Type
Phishing
tactic
2x
tactic
MITRE ATT&CK Technique
T1566 - Phishing
technique
2x
target region
Target Region
MENA
region
Contextual Telemetry
Context Block
15 METRICS
general metric
Nations
13
nations
general metric
Arrests
201
arrests
infrastructure
Malicious Servers
53
malicious servers
victims
Forced Workers
15
forced workers
general metric
Made Phishing Templates
80
made phishing templates
general metric
Popular Platforms
30
popular platforms
infrastructure
Domains
20,000
domains
data breach
Victim Records
45,000
victim records
infrastructure
Compromised Endpoints
3,867
compromised endpoints
general metric
Jun
12
jun
victims
Major Global Organizations
30
major global organizations
source region
Origin Region
AFRICA
region
general metric
Suspects
382
suspects
victims
Victims
3,867
victims
general metric
Pieces
8,000
pieces
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.