logo

Investigating Infrastructure and Tactics of Phishing-as-a-Service Platform Sniper Dz

ID: 540cd4d4-7b25-5467-8de9-0789c26fccd9

STIX ID: report--540cd4d4-7b25-5467-8de9-0789c26fccd9

Feed Name: Palo Alto Networks Unit 42

Threat Score
75/100

Date Published: 2024-09-24

Date Updated: 2026-04-28

Author: Shehroze Farooqi, Howard Tong and Alex Starov

...
...

Unit 42 investigates Sniper Dz, a free phishing-as-a-service (PhaaS) platform that has produced over 140,000 phishing pages in the past year; the platform offers hosted phishing pages and downloadable templates, hides backend servers behind a public proxy to evade detection, obfuscates code, centrally exfiltrates credentials to domains it controls, tracks victims with embedded scripts, abuses legitimate SaaS hosting (e.g., Blogspot), and redirects victims to malicious ads and PUPs — the report includes IOCs, screenshots of the admin panel and examples of affected URLs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.