logo

Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts

ID: 10158838-6f88-5d6d-9dd4-251c771d13f9

STIX ID: report--10158838-6f88-5d6d-9dd4-251c771d13f9

Feed Name: CosmicBytez Labs

Threat Score
70/100

Date Published: 2026-06-15

Date Updated: 2026-06-15

...
...

Researchers attribute a large-scale phishing campaign to the actor 'Sniper Dz' that uses fake and cloned Facebook accounts, promoted posts, localized credential-harvesting landing pages, and abused browser push notifications to funnel victims in the MENA region into credential-stealing traps; the operation is described as a phishing‑as‑a‑service platform supporting affiliates with templates, administration panels, and real-time exfiltration, and targets countries including Jordan, Morocco, Egypt, Saudi Arabia, Tunisia, and the UAE while recommending MFA, revoking notification permissions, URL verification, reporting, user training, and password managers as defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.