Sniper Dz free PhaaS ecosystem rebranded to scale phishing operations
Threat Actor Meta
Summary
Hide ▲
Show ▼
A long-running Sniper Dz ecosystem operated as a free phishing-as-a-service (PhaaS) platform that repeatedly rebranded, lowering the barrier for large-scale credential theft and scam delivery. Its bundled kits, hosting, and support helped cybercriminals launch phishing campaigns across major brands and government impersonations.
Related Happenings
BTMOB phishing campaign targeting Android users in Brazil and beyond
Campaign
H score34
First: 26.05.2026 17:00
Last: 26.05.2026 17:00
Sources 1
About this happening:
The **BTMOB phishing distribution campaign** is pushing **malicious APKs** through **fake app stores**, expanding Android compromise risk across **Brazil and beyond**. Operators l...
BTMOB phishing campaign targeting Android users in Brazil and beyond
CampaignAbout this happening: The **BTMOB phishing distribution campaign** is pushing **malicious APKs** through **fake app stores**, expanding Android compromise risk across **Brazil and beyond**. Operators l...
Interpol Operation Ramz cybercrime crackdown in MENA
Law Enforcement
H score20
First: 18.05.2026 17:00
Last: 18.05.2026 17:00
Sources 1
How related:
The effort, codenamed Operation Ramz, took place between October 2025 and February 2026, and saw authorities from 13 countries in the Middle East and North Africa (MENA) region making 201 arrests.
About this happening:
**INTERPOL**-led **Operation Ramz** disrupted **Sniper Dz**, a decade-long **phishing-as-a-service (PhaaS)** platform, during **October 2025-February 2026**. Authorities in **13 M...
Interpol Operation Ramz cybercrime crackdown in MENA
Law EnforcementHow related: The effort, codenamed Operation Ramz, took place between October 2025 and February 2026, and saw authorities from 13 countries in the Middle East and North Africa (MENA) region making 201 arrests.
About this happening: **INTERPOL**-led **Operation Ramz** disrupted **Sniper Dz**, a decade-long **phishing-as-a-service (PhaaS)** platform, during **October 2025-February 2026**. Authorities in **13 M...
Red Menshen telecom espionage campaign
Campaign
H score41
First: 26.03.2026 19:40
Last: 26.03.2026 19:40
Sources 1
About this happening:
A **China-nexus** **Red Menshen** operation has sustained **covert access** in **telecom networks** across the **Middle East and Asia**, increasing the risk of **government espion...
Red Menshen telecom espionage campaign
CampaignAbout this happening: A **China-nexus** **Red Menshen** operation has sustained **covert access** in **telecom networks** across the **Middle East and Asia**, increasing the risk of **government espion...
Kimwolf and Aisuru linked as a shared botnet operator ecosystem
Threat Actor Meta
H score42
First: 09.01.2026 01:23
Last: 09.01.2026 01:23
Sources 1
About this happening:
**Infoblox** says **PBaaS service providers** are helping industrialize **pig butchering** operations by supplying **scam kits**, **stolen identities**, **mobile apps**, **CRM/SCR...
Kimwolf and Aisuru linked as a shared botnet operator ecosystem
Threat Actor MetaAbout this happening: **Infoblox** says **PBaaS service providers** are helping industrialize **pig butchering** operations by supplying **scam kits**, **stolen identities**, **mobile apps**, **CRM/SCR...
Dragon Breath Campaign Trio and Campaign Chorus brand-impersonation Gh0st RAT campaign
Campaign
H score39
First: 17.11.2025 13:20
Last: 17.11.2025 13:20
Sources 1
About this happening:
Dragon Breath's **Campaign Trio** and **Campaign Chorus** are using **trojanized NSIS installers** to deliver **Gh0st RAT** to **Chinese-speaking users**, widening the risk of rem...
Dragon Breath Campaign Trio and Campaign Chorus brand-impersonation Gh0st RAT campaign
CampaignAbout this happening: Dragon Breath's **Campaign Trio** and **Campaign Chorus** are using **trojanized NSIS installers** to deliver **Gh0st RAT** to **Chinese-speaking users**, widening the risk of rem...
Timeline
-
12.06.2026 11:52 2 articles · 8h ago
Operation Ramz disrupts Sniper Dz phishing platform
Initial DisclosureINTERPOL-led Operation Ramz disrupted Sniper Dz, a phishing-as-a-service platform active since at least 2015 and also known as Joker Dz, Storm Dz, and Spam Dz. Authorities arrested Guedz, the platform's primary developer and administrator, took down the website used to provide PhaaS capabilities, and seized hardware containing phishing software and scripts.
Show sources
- INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator — thehackernews.com — 12.06.2026 11:52
- INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator — thehackernews.com — 12.06.2026 11:52