216.73.217.98

Sniper's Nest: From Brand Impersonation to Browser Hijacking and CPA Fraud

· Published 11/06/2026 11:49 · Modified 11/06/2026 14:37

Export JSON

Essential information

Published
11/06/2026 11:49
Modified
11/06/2026 14:37
Tags
2026-06-11 browser hijacking phishing-as-a-service sniperdz
Related entities
2 observables, 1 intrusion sets (apt), 8 others

Description

An investigation into phishing activity targeting users across the Middle East and North Africa uncovered , a centralized Push-Notification-as-a-Service and platform. The operation uses fraudulent Facebook accounts impersonating politicians, public figures, and trusted organizations to promote fake offers including free mobile internet packages and financial compensation. Victims are redirected through trusted link-aggregation services like Linktree and Linkbio to evade detection. provides 80 phishing templates mimicking over 30 global brands across financial services, social media, streaming, and gaming platforms. The infrastructure employs browser notification abuse, history manipulation creating a back-button prison, premium SMS subscriptions, premium-rate calls, investment scams, and affiliate marketing for monetization. Analysis revealed over 900 suspicious domains linked to shared hosting infrastructure and a recurring VAPID public key connecting multiple campai...

External references