{"id":1303,"date":"2026-06-15T07:34:20","date_gmt":"2026-06-15T07:34:20","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1303"},"modified":"2026-06-15T07:34:20","modified_gmt":"2026-06-15T07:34:20","slug":"sniper-dz-scams-target-mena-users-via-fake-facebook-offers-and-browser-alerts","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1303","title":{"rendered":"Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 15, 2026<\/span><\/span><span class=\"p-tags\">Social Engineering \/ Browser Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj-L0YMpJQcSqCJeQR6NevaPeBZW1uc13Y3nV37mR6tEuSsuMxWV6RrohLtgsVqG_Ja_kBoZTAMcKXlaG-OfyjrLDAUwhO_pQifFv64iRc-HE0nAAMJ88BF_xEQwOj39EdAE5ZTNU7q7y3SjBjKsvBZckb_jcg1FzMM9YRe9OV9UFsNyjH2km2jAXvBIdTa\/s1700-e365\/phishing-sniperdz.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have disclosed details of fraudulent activity targeting users across the Middle East and North Africa by employing various fraudulent Facebook accounts impersonating politicians, public figures, and trusted organizations.<\/p>\n<p>\u00abThese accounts promoted fake offers, including free mobile internet packages, financial compensation, and government subsidy programs,\u00bb Group-IB analysts Anna Yurtaeva and Viacheslav Shevchenko <a href=\"https:\/\/www.group-ib.com\/blog\/inside-sniperdz-phaas-ecosystem\/\">said<\/a>.<\/p>\n<p>\u00abVictims were encouraged to click embedded links to claim the advertised benefits, but were instead redirected through a chain of intermediary websites that ultimately led to phishing and traffic monetization infrastructure.\u00bb<\/p>\n<p>The Singapore-headquartered cybersecurity company has these campaigns to Sniper Dz, a turnkey phishing-as-a-service (PhaaS) platform that was taken down last month in an INTERPOL-led operation. The findings indicate that the platform goes beyond facilitating credential theft, generating illicit revenue via browser notification abuse, premium SMS subscriptions, premium-rate calls, and investment scams.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>A \u00abtypical Sniper Dz scam victim funnel\u00bb begins with localized social engineering lures, with the scammers impersonating well-known telecom providers such as Alg\u00e9rie T\u00e9l\u00e9com to promote fake offers, to direct users to domains hosted on Link in bio services that act as an intermediary layer between the social media post and the final destination.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>\u00abRather than directing victims straight to a malicious website, the campaign first routes users through trusted link-aggregation platforms such as Linkbio and Linktree,\u00bb Group-IB researchers said. \u00abThe attackers create decoy landing pages on domains operated by these services.\u00bb<\/p>\n<p>The attack ends with directing victims to a page that obtains browser notification permissions by prompting users to click \u00abAllow\u00bb to continue. Behind the scenes, code embedded in the web page subscribes the web browser to a push notification system using a Voluntary Application Server Identification (<a href=\"https:\/\/blog.mozilla.org\/services\/2016\/08\/23\/sending-vapid-identified-webpush-notifications-via-mozillas-push-service\/\">VAPID<\/a>) public key.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhWUCIqI6jKCCP3L-BD3TFpocrCa-UPpOKdfXqdMLJfDwhzlye9Zl6Ds7fg7d2TkvGnFehOFn1F67a7L8z7wxx3bt8Q4Ya_5akCOCatWoDlrjtgSZJllvCylZz-7BiJYlTKYclj4yfkyNLAV8vBcjfvrm5rgqep8NC_S6LJGsZ8i7Qz5hwSFf7kK5LAQwk-\/s1700-e365\/Sniperdz.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhWUCIqI6jKCCP3L-BD3TFpocrCa-UPpOKdfXqdMLJfDwhzlye9Zl6Ds7fg7d2TkvGnFehOFn1F67a7L8z7wxx3bt8Q4Ya_5akCOCatWoDlrjtgSZJllvCylZz-7BiJYlTKYclj4yfkyNLAV8vBcjfvrm5rgqep8NC_S6LJGsZ8i7Qz5hwSFf7kK5LAQwk-\/s1700-e365\/Sniperdz.png\" alt=\"\" border=\"0\" data-original-height=\"1500\" data-original-width=\"2520\"\/><\/a><\/div>\n<p>Group-IB said the same VAPID key has been observed across campaigns masquerading as telecommunications providers in Algeria and investment-related scams targeting users in multiple regions.<\/p>\n<p>\u00abBecause VAPID public keys are used to identify the notification service responsible for delivering push messages, their reuse can provide valuable insight into underlying infrastructure relationships,\u00bb the company said. \u00abThe consistent appearance of the same key across otherwise distinct campaigns suggests that the operators are relying on a shared push-notification ecosystem rather than independent infrastructure.\u00bb<\/p>\n<p>Furthermore, the page engages in back button hijacking by injecting 10 fake history states, tricking users into visiting sites that may serve unsolicited ads, or trapping them in a \u00abback-button prison\u00bb and within attacker-controlled content to inflate ad impressions, promote scams, or deliver malicious content.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abThe page also implements a tab-under technique that activates when users interact with certain links,\u00bb the cybersecurity company noted. If a link opens a new browser tab, a delayed script silently redirects the original tab to another destination controlled by the operators.<\/p>\n<p>\u00abThis allows the campaign to continue driving traffic through its redirection and monetization infrastructure even after the victim believes they have left the site. By combining browser notification abuse with history manipulation and tab-under redirections, the operators make it significantly more difficult for users to escape the scam ecosystem.\u00bb<\/p>\n<p>Once users are enrolled into the notification infrastructure, the attacks progress to the monetization phase, routing the victims to a traffic distribution system (TDS) that determines which scam to present based on factors like device type, location, and mobile carrier. Potential pathways include premium-rate call scams, premium SMS subscription fraud, and investment scams.<\/p>\n<p>\u00abThis campaign demonstrates how modern fraud operations increasingly rely on the abuse of legitimate web technologies rather than traditional malware,\u00bb Group-IB said. \u00abInstead of infecting devices, the operators exploit trusted platforms, browser features, and social engineering techniques to guide victims through a carefully designed monetization funnel.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jun 15, 2026Social Engineering \/ Browser Security Cybersecurity researchers have disclosed details of fraudulent activity targeting users across the Middle East and North Africa by employing various fraudulent Facebook&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1304,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[940,265,1188,150,161,18,243,2022,492,826],"class_list":["post-1303","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-alerts","tag-browser","tag-facebook","tag-fake","tag-mena","tag-offers","tag-scams","tag-sniper","tag-target","tag-users"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1303","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1303"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1303\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1304"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1303"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1303"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1303"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}