Actor Profile

Guedz is identified as the primary administrator of Sniper Dz, a phishing-as-a-service (PhaaS) platform that operated for approximately a decade across the Middle East and North Africa (MENA) region. As the platform's lead operator, Guedz facilitated credential harvesting and phishing campaigns by providing infrastructure and tooling to a broad customer base. The actor was arrested as part of INTERPOL-led Operation Ramz, which resulted in 201 total arrests across 13 MENA countries between October 2025 and February 2026. Guedz's motivation appears to be financially driven, monetizing access to phishing infrastructure for cybercriminal customers conducting credential theft and account compromise operations.

TTPs (Tactics, Techniques, Procedures)

Sniper Dz operated as a phishing-as-a-service platform, enabling customers to conduct credential harvesting attacks. Key TTPs likely include T1566 (Phishing) for initial access, T1589 and T1598 (Gather Victim Identity Information and Phishing for Information) for reconnaissance, T1078 (Valid Accounts) for leveraging stolen credentials, and T1583/T1584 (Acquire/Compromise Infrastructure) to support phishing operations. The platform's decade-long operation suggests robust OPSEC and infrastructure resilience, likely involving bulletproof hosting, domain generation or rotation, and compartmentalized customer access to evade detection and attribution.

Targets & Patterns

While specific targeted sectors are not identified, Sniper Dz's phishing-as-a-service model enabled a wide range of customers to target victims across the Middle East and North Africa region. The platform's longevity and scale (201 arrests suggest extensive user base) indicate indiscriminate targeting patterns typical of PhaaS operations, likely including individuals, businesses, government entities, and financial institutions. The MENA regional focus suggests victims were primarily Arabic-speaking users, with phishing lures and infrastructure tailored to regional languages, cultural contexts, and popular online services to maximize credential theft success rates.

Historical Context

Sniper Dz represents a decade-long phishing-as-a-service operation, placing it among long-running cybercrime infrastructure platforms in the MENA region. The scale of Operation Ramz—201 arrests across 13 countries—indicates Sniper Dz achieved significant market penetration comparable to other major PhaaS platforms like 16Shop or Frappo. The INTERPOL-led disruption follows a pattern of international law enforcement targeting PhaaS infrastructure, similar to operations against BulletProofLink (2021) and other credential theft platforms. The arrest of Guedz as the primary administrator represents a significant disruption to MENA-focused phishing operations, though the extensive customer base suggests fragmentation and potential successor platforms may emerge.

Defensive Recommendations

  • Implement multi-factor authentication (MFA) across all user accounts to mitigate credential theft from phishing attacks (T1078)
  • Deploy email security gateways with URL rewriting and sandboxing to detect and block phishing attempts (T1566.002)
  • Conduct regular security awareness training focused on phishing recognition, particularly targeting MENA-specific lures and Arabic-language social engineering tactics
  • Monitor for anomalous authentication patterns including impossible travel, unusual login times, and access from known PhaaS infrastructure IP ranges
  • Establish threat intelligence sharing with regional CERTs and INTERPOL channels to receive indicators of compromise (IOCs) related to Sniper Dz infrastructure and successor platforms

---

# Geopolitical Context

Geopolitical Context

Operation Ramz represents a significant multilateral law enforcement effort targeting cybercrime-as-a-service infrastructure in the Middle East and North Africa. The dismantlement of Sniper Dz, a phishing-as-a-service platform operational for approximately ten years, underscores the maturation of regional cyber threat ecosystems and the growing capacity for coordinated international response. The scale of arrests—201 individuals across 13 countries—suggests the platform supported a distributed network of cybercriminal affiliates rather than a centralized organization. INTERPOL's leadership in this operation reflects increasing prioritization of transnational cybercrime enforcement in regions where such infrastructure has historically operated with relative impunity. The arrest of Guedz, identified as the primary administrator, may yield intelligence on customer bases, financial flows, and operational tradecraft that could inform future disruptions.

State Actor Alignment

The operation appears to target purely criminal infrastructure rather than state-sponsored activity. Phishing-as-a-service platforms typically serve financially motivated cybercriminals, though such tools can be leveraged by state-aligned actors for espionage or influence operations. No public reporting links Sniper Dz to state sponsorship or strategic intelligence objectives. The multinational law enforcement cooperation—spanning 13 MENA countries—suggests broad governmental consensus on the threat posed by this platform, which is consistent with efforts to combat transnational organized crime rather than geopolitical adversaries. Sanctions regimes do not appear relevant to this enforcement action, which relies on domestic criminal statutes and mutual legal assistance frameworks.

Business Impacty pro region

The operation may signal strengthening cybercrime enforcement capacity across MENA states, many of which have historically faced challenges in addressing digital crime infrastructure. For Europe, the disruption of a platform that likely facilitated credential theft and financial fraud targeting European entities represents a positive development, though successor services may emerge. The operation's success could encourage similar multilateral efforts in other regions where cybercrime-as-a-service models proliferate, including Eastern Europe and Southeast Asia. Private sector entities, particularly financial institutions and telecommunications providers in MENA and Europe, may experience reduced phishing activity in the near term, though displaced threat actors may migrate to alternative platforms. The intelligence gathered from seized infrastructure could support follow-on investigations into downstream criminal activity, including business email compromise and payment fraud schemes.

Forecast

If INTERPOL and participating states sustain pressure on cybercrime infrastructure in MENA, the region's appeal as a safe haven for phishing-as-a-service operations is likely to diminish, potentially displacing activity to jurisdictions with weaker enforcement. If Guedz's arrest yields actionable intelligence on customer networks and financial channels, secondary enforcement actions targeting platform users are probable within six to twelve months. However, if demand for phishing services remains robust, successor platforms are likely to emerge, potentially with enhanced operational security measures to evade detection. The operation's long-term impact will depend on whether participating states maintain investigative momentum and address underlying factors—such as limited economic opportunity and weak digital governance—that enable cybercrime ecosystems to flourish.