logo

Hackers Abuse SniperDz PhaaS Ecosystem for Brand Impersonation and Browser Hijacking

ID: fa99a3cf-fd40-59e5-9419-9acce6e4ae8d

STIX ID: report--fa99a3cf-fd40-59e5-9419-9acce6e4ae8d

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

Author: Tushar Subhra Dutta

...
...

SniperDz is a turnkey Phishing-as-a-Service and Push-Notification-as-a-Service ecosystem enabling large-scale social-media phishing in the Middle East and North Africa; attackers use link-aggregation intermediaries, multi-stage redirects, cloaking, browser-push subscription abuse (shared VAPID key), and history/tab manipulation to trap victims and deliver scams and unsolicited/malicious content. The report includes multiple IoCs (domains, IPs hosted by Horizon IS, sample URLs and a recurring VAPID public key) and recommends revoking browser notification permissions and treating redirection chains as suspicious.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.