Law Enforcement: INTERPOL and Group-IB Dismantle Nine-Year Phishing-as-a-Service Platform SniperDz
Executive Summary
In a major victory for international cybercrime enforcement, INTERPOL, alongside Algerian national law enforcement and cybersecurity firm Group-IB, has successfully dismantled SniperDz, a highly prolific Phishing-as-a-Service (PaaS) platform that operated for over nine years. Executed under the global umbrella of Operation First Light, the synchronized raids disrupted a massive cybercrime syndicate.
SniperDz provided automated, cloud-hosted phishing templates to thousands of low-skilled cybercriminals worldwide, mimicking global financial institutions, social media networks, and e-commerce giants. Threat intelligence indicates that the platform's templates were responsible for harvesting the credentials and financial details of millions of victims. The seizure of core command-and-control (C2) servers and the arrest of key developers represent a massive blow to the global phishing-as-a-service economy.
Deep-Dive Technical Analysis
The rise of Phishing-as-a-Service (PaaS) has heavily commoditized the cybercrime landscape. Rather than writing code, configuring servers, or designing complex web interfaces, novice criminals (known as "phishing affiliates") can simply purchase pre-made kits, host them on the PaaS provider's infrastructure, and split the harvested credential profits with the platform developers.
A technical analysis of the SniperDz operational architecture, mapped by Group-IB’s High-Tech Crime Investigations unit, reveals a highly industrialized phishing network:
1. Automated Template Generation: SniperDz hosted a vast, cloud-based catalog of high-fidelity phishing templates. These templates mimicked the exact, real-time login pages of prominent global banks, payment processors, and SaaS providers, complete with dynamic localized language rendering.
2. Reverse-Proxy and Session Hijacking: Advanced kits on the platform utilized reverse-proxy frameworks (such as Evilginx or custom equivalents). When a victim entered their credentials, the proxy intercepted the connection, captured the username and password, and forwarded the authentication requests to the legitimate service. Crucially, this allowed the attackers to intercept active session cookies (tokens), successfully bypassing Multi-Factor Authentication (MFA) controls.
3. Admin Panel and C2 Distribution: SniperDz operated a centralized web console where affiliates managed their campaigns. Harvested credentials and session tokens were written directly to databases on the C2 servers, which then pushed automated notifications to affiliates via Telegram API bots.
4. The Takedown Sequence: Forensic researchers at Group-IB utilized advanced threat intelligence platforms to trace the underlying domain registration patterns, DNS history, and hosting infrastructure of the SniperDz platform. This forensic trail led directly to hosting nodes geolocated in Algeria. INTERPOL coordinated with Algerian cybercrime units, executing synchronized physical raids that seized key databases, disrupted the C2 servers, and arrested the lead administrators behind the nine-year operation.
Industry Impact and Recommendations
The takedown of SniperDz removes one of the most resilient and long-standing enablers of global credential theft. However, as the PaaS model remains highly profitable, replacement platforms will inevitably emerge, requiring enterprises to adopt strict, zero-trust authentication policies.
We recommend that all enterprise administrators, brand protection officers, and CISOs implement the following mitigations:
1. Transition to Phishing-Resistant MFA: Traditional multi-factor authentication (such as SMS codes, email PINs, or push notifications) is easily bypassed by the reverse-proxy kits provided by PaaS platforms. Mandate the use of phishing-resistant MFA standards, such as FIDO2-compliant physical hardware security keys or certificate-based smart cards.
2. Implement Brand Protection and Domain Monitoring: Deploy automated domain-monitoring tools to continuously scan public DNS registries for newly registered domains that mimic your corporate brand or domain name (typosquatting/homoglyph attacks), proactively submitting take-down requests.
3. Harden Cloud Gateways with Conditional Access: Configure Conditional Access Policies inside identity providers (such as Entra ID or Okta). Restrict access to corporate applications based on device compliance, managed IP subnets, and geographic locations, blocking logins attempted via proxy nodes.
4. Deploy Advanced Email and URL Filtering: Implement secure email gateways (SEG) with advanced behavioral analysis. Configure filters to automatically flag, isolate, and scan incoming emails containing uncharacteristic URLs or links hosted on newly registered domains (less than 30 days old).
References:
* Group-IB — Group-IB investigation helped INTERPOL and Algerian authorities dismantle SniperDz
* Check Point Research — 6th July Threat Intelligence Report