Sniper Dz Phishing-as-a-Service Goes Dark After INTERPOL Sweep Nets 201 Arrests

Operation Ramz dismantled a decade-old PhaaS storefront and pulled in its alleged operator, 'Guedz', across 13 MENA jurisdictions.

ThreatVectr Newsdesk· 2 min read
Sniper Dz Phishing-as-a-Service Goes Dark After INTERPOL Sweep Nets 201 Arrests
Share

A ten-year-old phishing-as-a-service operation called Sniper Dz is offline, and its alleged operator is in custody.

The takedown came out of Operation Ramz, an INTERPOL-coordinated effort that ran from October 2025 through February 2026. Authorities across 13 countries in the Middle East and North Africa made 201 arrests. The headline collar: a suspect known online as Guedz, described as the platform's primary administrator.

Sniper Dz was not a boutique outfit. It was a storefront. For years it sold ready-made phishing kits and hosted credential-harvesting pages for paying customers, lowering the technical bar for anyone who wanted to run a campaign against a bank login page or a webmail portal. Independent research published in 2024 tied the platform to more than 140,000 phishing domains targeting brands across retail, telecom, and finance.

The service ran on a tiered model. Free customers got hosted phishing pages; the operators kept a copy of every harvested credential — a classic double-dip where the PhaaS provider monetises the same victims their own customers are phishing. Paid tiers offered custom templates and exfiltration to attacker-controlled endpoints.

What actually got seized, beyond arrests, has not been fully detailed in the joint statement. Expect that picture to firm up as national prosecutors in MENA jurisdictions file charging documents. INTERPOL's role here is coordination; the underlying cases will be prosecuted locally, under each country's computer-misuse and fraud statutes.

A few things worth flagging.

First, PhaaS takedowns rarely stay clean. The 16shop disruption in 2023 was followed within months by clones and rebrands. Sniper Dz's customer base — the people who actually ran the campaigns — is largely untouched by 201 arrests focused on operators and resellers.

Second, credential reuse is the long tail. Anything harvested through Sniper Dz over the past decade has likely been resold, stuffed against other services, or sitting in combo lists. The takedown stops new collection. It does not unring the bell on years of stolen logins.

What affected users should do

If you have entered credentials into a suspicious-looking login page at any point — particularly for banking, webmail, or a telecom account in the MENA region — assume the password is burned. Rotate it. Rotate anything that shared it. Turn on phishing-resistant MFA (a hardware key or passkey, not SMS) on the accounts that matter. Check Have I Been Pwned for known exposures tied to your email address, and pull a credit report if your jurisdiction supports it.

For defenders: now is a reasonable moment to hunt historical logs for callbacks to known Sniper Dz infrastructure. The domains are public in prior research. The credentials they stole are not.

© 2026 Threat Vectr