惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
Martin Fowler
Martin Fowler
博客园_首页
量子位
T
Tailwind CSS Blog
博客园 - Franky
G
Google Developers Blog
D
DataBreaches.Net
Vercel News
Vercel News
B
Blog
Recent Announcements
Recent Announcements
S
SegmentFault 最新的问题
M
MIT News - Artificial intelligence
爱范儿
爱范儿
博客园 - 【当耐特】
The Cloudflare Blog
H
Help Net Security
云风的 BLOG
云风的 BLOG
P
Proofpoint News Feed
C
Check Point Blog
有赞技术团队
有赞技术团队
Microsoft Security Blog
Microsoft Security Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Hackread – Cybersecurity News, Data Breaches, AI and More

Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks New GhostShell Hacking Group Targets Ukraine’s Drone Defense Sector Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords Best Crypto Payment Solutions for E-Commerce Businesses Internet Society Foundation Opens Global Call for Common Good Cyber Fund to Strengthen Cybersecurity LastPass Confirms Customer Data Breach After Klue OAuth Token Theft ‘Cordyceps’ CI/CD Flaw Exposes Microsoft, Google, Apache Repos to Pipeline Hijacking The Rise of AI-Powered Academic Fraud: Beyond Traditional Plagiarism New CryptoBandits Malware Uses USB Drives and Tor to Steal Crypto The Evolution of iGaming Fraud: What Security Teams Should Expect in 2027 2 Scattered Spider-Linked Hackers Plead Guilty Over £39M TfL Cyberattack Beats Studio Buds Flaw Could Let Nearby Attackers Eavesdrop on Users Texas Parks and Wildlife Data Breach Affects Over 3M License Customers Threat Hunting Beyond Alerts: Finding the Activity Detection Misses Scammers Use Fake GitHub Stars, VirusTotal Reviews to Spread Crypto Clipper Salesforce Disables Klue Integration After OAuth Token Theft Hits Customer Data MDR Provider Comparison: Time to Discover and Respond to Threats Meteor 3.0 Migration Helped Rocket.Chat Move Off End-of-Life Node.js Runtime Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections Nintendo America Employee Data Exposed After Shadowbyt3$ Targets TinyPulse eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks FIFA World Cup 2026: Hackers Target Football Fans With Fake Tickets Sites MacBook Neo vs Windows Laptops for Cybersecurity Tasks Operation Endgame Disrupts SocGholish Malware Infrastructure What Businesses Should Know Before Migrating Their CMS DragonForce Ransomware Abused Microsoft Teams to Hide Malware Activity Agentjacking: Researchers Show How One Fake Bug Report Can Hijack AI Coding Agents FortiBleed Attack Exposes Fortinet Firewall Credentials in 194 Countries SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies 152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Fake Search Clicks
Authorities Dismantle Decade-Old SniperDZ Phishing Network
Deeba Ahmed · 2026-06-12 · via Hackread – Cybersecurity News, Data Breaches, AI and More

In a collective operation, Group-IB, INTERPOL, and the Algerian National Police have dismantled SniperDZ, an online Phishing-as-a-Service (PhaaS) network that helped hackers steal user data for nearly ten years.

Operating via Telegram and Facebook channels, SniperDz allowed anyone, even novice hackers, to use its toolkit of 80 ready-made phishing templates for free to create fake login pages and trick people into giving away their login credentials (usernames – passwords) and other personal data.

The phishing platform allowed scammers to target users on around 30 popular platforms, including PayPal, Facebook, Instagram, Netflix, and Steam, via more than 20,000 domains.

Templates offered in different languages (Source: Group-IB)

Tracking the Infrastructure

As per the details shared by INTERPOL and Group-IB, this PhaaS network was launched in 2015 but evaded detection for so long because the admins constantly changed its name. The platform was also known as JokerDz, StormDz, and SpamDz.

In 2024, Group-IB cybersecurity researchers detected fake Facebook accounts of politicians in the Middle East and North Africa delivering malicious links. These accounts lured users into clicking those links by promising free internet access and gifts.

With the support of INTERPOL, slowly, information started emerging; the code’s developer turned out to be a threat actor known online as Guedz. The hacker created a massive vulnerability for himself by producing video tutorials to train affiliate scammers.

In those recordings, Guedz failed to mask his active administrator panel and personal backend email addresses, and Group-IB’s analysts used data correlation to trace him using these clues.

SniperDZ admin panel

Server Disruption and Mitigation

Group-IB compiled and shared this data with INTERPOL and the Algerian National Police. This helped Algerian authorities arrest Guedz and seize active hardware containing phishing code and malicious scripts.

This raid was part of a broader threat mitigation initiative called Operation Ramz that ran between October 2025 and 28 February 2026. INTERPOL shared its results in a press release on 18 May but didn’t explicitly name the SniperDz network at the time. Group-IB is the first to name the network and share more details on this network in a report published today.

“For nearly ten years, SniperDz served as quiet criminal infrastructure, available to anyone with the motivation to use it. The scale of its reach became concrete in 2016, when the platform published statistics showing that campaigns run through its service had already collected more than 45,000 victim records. That figure represented only the activity captured at a single point in time, years before the operation was dismantled,” Group-IB revealed.

Decade-Long SniperDz Phishing Network Disrupted in Operation Ramz
Decade-Long SniperDz Phishing Network on Telegram (Image credit: Hackread.com)

About Operation Ramz

According to INTERPOL’s press release, Operation Ramz covered 13 nations, including Egypt, Morocco, Jordan, and Qatar, leading to 201 arrests and the seizure of 53 malicious servers. Over 3,867 compromised endpoints and victims were identified.

During the mitigation process in Jordan, investigators tracked an investment scam platform run by 15 forced workers. These individuals were victims of human trafficking who had their travel documents withheld and were forced to run the scam scripts.

Authorities arrested the two primary operators running that facility. This coordinated shutdown proves that even the most long-standing scam networks eventually fall when international threat intelligence and local law enforcement align.

“In a world where cybercriminals exploit the digital landscape without borders, Operation Ramz demonstrates the effectiveness of global collaboration. INTERPOL is dedicated to working with its member countries and private sector partners to take down malicious infrastructure, disrupt criminal groups, and bring perpetrators to justice,” stated INTERPOL’s Director of Cybercrime, Neal Jetton.