Full Report
This blog provides a deep-dive into SniperDz, a centralised PhaaS platform with more than 80 ready-made phishing templates impersonating over 30 global brands, and uncovers the hidden infrastructure behind this sophisticated and highly-organized fraud ecosystem.
Analysis Summary
# Tool/Technique: SniperDz
## Overview
SniperDz is a sophisticated, centralized Phishing-as-a-Service (PhaaS) platform designed to facilitate large-scale fraud. It provides cybercriminals with a streamlined ecosystem to host, manage, and deploy phishing campaigns. The platform is notable for offering a "free-to-use" model for its affiliates, where the platform developers monetize the service by stealing a portion of the victim data (credentials/information) collected by the affiliates—a technique known as "double-dipping."
## Technical Details
- **Type:** Phishing-as-a-Service (PhaaS) / Fraud Framework
- **Platform:** Web-based (cross-platform targets including Mobile and Desktop browsers)
- **Capabilities:** Automated phishing page hosting, real-time credential harvesting, session token theft, bypass of security filters, and administrative dashboards for tracking victims.
- **First Seen:** Active through 2023-2024 (Platform evolution indicates long-term development).
## MITRE ATT&CK Mapping
- **[TA0001 - Initial Access]**
- **[T1566 - Phishing]**
- **[T1566.002 - Spearphishing Link]**
- **[TA0007 - Discovery]**
- **[T1082 - System Information Discovery]** (Browser fingerprinting)
- **[TA0006 - Credential Access]**
- **[T1557 - Adversary-in-the-Middle]**
- **[T1539 - Steal Web Session Cookie]**
- **[TA0011 - Command and Control]**
- **[T1071.001 - Web Protocols]**
## Functionality
### Core Capabilities
- **Extensive Template Library:** Over 80 ready-made phishing templates impersonating 30+ global brands (banks, social media, e-commerce, and logistics).
- **Centralized Infrastructure:** Victims are directed to centralized servers managed by the SniperDz developers rather than the individual affiliates.
- **Automated Exfiltration:** Captured credentials and PII are sent to Telegram bots or administrative panels.
### Advanced Features
- **Anti-Bot and Anti-Analysis:** Implementation of techniques to detect and block security researchers, crawlers, and automated sandboxes.
- **Browser Notification Abuse:** Use of rogue browser notifications to maintain persistence on the victim’s device and deliver follow-up scams.
- **Dynamic Content Loading:** Phishing pages dynamically adjust based on the victim’s IP address or browser language to increase legitimacy.
## Indicators of Compromise
### Network Indicators
- **C2/Hosting Domains:**
- win.feezossl[.]xyz
- win[.]anababayala[.]com
- aff.bnaosf1he[.]shop
- raviral[.]com
- **IP Addresses:**
- 65.60.9[.]236
- 108.178.23[.]118
- 184.154.10[.]254
### Behavioral Indicators
- Redirects from legitimate link-in-bio services (Linktree, Linkbio) to suspicious subdomains.
- Sudden requests for "Allow Notifications" on unrelated or low-reputation websites.
- High-frequency automated Telegram API calls for data exfiltration.
## Associated Threat Actors
- **SniperDz Group:** The primary developers/operators of the PhaaS platform.
- **General Cybercriminals:** Used by a wide range of low-to-mid-tier affiliates due to the platform's ease of use and "free" entry cost.
## Detection Methods
- **Behavioral Detection:** Monitor for redirects to newly registered domains (NRDs) immediately following clicks on social media advertisement links.
- **Network Monitoring:** Flag outbound traffic to known PhaaS administrative interfaces or Telegram bot API endpoints containing sensitive form data.
- **Threat Intelligence:** Monitoring for the specific URI patterns used by SniperDz templates (often containing unique affiliate IDs).
## Mitigation Strategies
- **User Education:** Train users to identify "Link-in-bio" abuse and to be wary of unsolicited promotional offers on social media.
- **Browser Security:** Enforce policies that disable or strictly control browser notifications at the organizational level.
- **Multi-Factor Authentication (MFA):** Implementation of FIDO2/WebAuthn-based hardware security keys to prevent session hijacking and AiTM (Adversary-in-the-Middle) bypass.
- **Domain Filtering:** Block access to the identified IOC domains and implement real-time URL scanning for email and messaging platforms.
## Related Tools/Techniques
- **LabHost:** A similar PhaaS platform recently disrupted by law enforcement.
- **Greatness:** A phishing kit focused on Microsoft 365 credential harvesting.
- **Tycoon 2FA:** An advanced AiTM phishing kit targeting session cookies.