Sniper's Nest: From Brand Impersonation to Browser Hijacking and CPA Fraud

June 11, 2026, 2:37 p.m.

Description

An investigation into phishing activity targeting users across the Middle East and North Africa uncovered SniperDz, a centralized Push-Notification-as-a-Service and Phishing-as-a-Service platform. The operation uses fraudulent Facebook accounts impersonating politicians, public figures, and trusted organizations to promote fake offers including free mobile internet packages and financial compensation. Victims are redirected through trusted link-aggregation services like Linktree and Linkbio to evade detection. SniperDz provides 80 phishing templates mimicking over 30 global brands across financial services, social media, streaming, and gaming platforms. The infrastructure employs browser notification abuse, history manipulation creating a back-button prison, premium SMS subscriptions, premium-rate calls, investment scams, and affiliate marketing for monetization. Analysis revealed over 900 suspicious domains linked to shared hosting infrastructure and a recurring VAPID public key connecting multiple campai...

Date

  • Created: June 11, 2026, 11:49 a.m.
  • Published: June 11, 2026, 11:49 a.m.
  • Modified: June 11, 2026, 2:37 p.m.

Indicators

  • 65.60.9.236
  • 184.154.10.254

Attack Patterns

  • SniperDz

Additional Informations

  • Finance
  • Telecommunications
  • Technology
  • Media
  • win.feezossl.xyz
  • win.anababayala.com
  • aff.bnaosf1he.shop
  • Algeria