discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator

An INTERPOL-led operation disrupted Sniper Dz, a long-running phishing platform, and arrested its administrator. Authorities from 13 MENA countries made 201 arrests.

By Ravie Lakshmanan·Jun 12·thehackernews.com·2 min read

Intelligence analysis by GPT-5.4 Mini

INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator
Image: thehackernews.com

Group-IB says an INTERPOL-led operation shut down Sniper Dz, a free phishing-as-a-service platform active since at least 2015. The action also led to 201 arrests across 13 MENA countries and the seizure of phishing-related hardware.

Why it matters

This is a major disruption of a phishing service that lowered the barrier for criminals to run large-scale credential theft campaigns. It also shows how coordinated cross-border enforcement can target the infrastructure behind phishing, not just individual campaigns.

Sniper Dz was like a free toolkit and rented store for thieves online. Police and investigators shut it down and arrested people running it, which should make it harder for scammers to trick people into giving away passwords and personal details.

Analysis

What happened

Group-IB says an INTERPOL-led effort disrupted Sniper Dz, a long-running phishing-as-a-service platform, during Operation Ramz. The operation ran from October 2025 to February 2026 and involved authorities from 13 countries in the Middle East and North Africa. Group-IB says the action led to 201 arrests, including the arrest of Guedz, described as the platform's primary developer and administrator, by the Algerian National Police.

What Sniper Dz did

According to Group-IB, Sniper Dz had been active since at least 2015 and evolved into a criminal service that offered ready-made phishing kits, hosting infrastructure, and operational support. The platform rebranded over time as Joker Dz, Storm Dz, and Spam Dz. Authorities also seized hardware containing phishing software and scripts, and the service's website was taken down.

The report says the platform had been linked to more than 45,000 victim records and over 20,000 unique domains. Its phishing toolkit targeted about 30 major global organizations, including PayPal, Facebook, Instagram, Yahoo, Netflix, and Steam, and used 80 phishing templates in five languages: Arabic, English, French, Spanish, and Hebrew.

Why it stood out

Group-IB says Sniper Dz was unusual because it offered its infrastructure for free, which made it easier for other criminals to launch phishing campaigns at scale. The platform's operators then monetized traffic and stolen credentials through schemes such as carrier billing fraud, premium SMS subscriptions, browser notification abuse, and affiliate scam redirects.

The company also says the operation used social engineering tied to public figures in the region. Fake accounts impersonating political personalities were used to spread phishing links disguised as promotions or free internet access. The story underscores how phishing services can combine technical kits, hosting, and social manipulation into one repeatable criminal business.

Key points

  • INTERPOL-led Operation Ramz disrupted Sniper Dz, a phishing-as-a-service platform active since at least 2015.
  • Authorities from 13 MENA countries made 201 arrests, including the platform's alleged administrator in Algeria.
  • Group-IB says Sniper Dz collected more than 45,000 victim records and used over 20,000 domains.
  • The service targeted major brands and used phishing templates in Arabic, English, French, Spanish, and Hebrew.
  • Its unusual model offered infrastructure for free and relied on credential theft plus scam traffic monetization.
The Upside

If the shutdown holds, one of the easier-to-use phishing services in circulation is now gone, which could slow down copycat campaigns. The arrests and seizure of infrastructure may also help investigators identify more people and related sites tied to the same network.

The Downside

The platform's past rebrands show that phishing operators can regroup under new names if pressure eases. The same playbook of free kits, fake brands, and social engineering can be rebuilt elsewhere, so the disruption may be temporary if follow-up enforcement is weak.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityglobal-newsmiddle-eastcybercrimephishing

Author

Ravie Lakshmanan

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 12, 2026

Source

thehackernews.com

Share

Topics

securityglobal-newsmiddle-eastcybercrimephishing

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…