[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Business Email Compromise](https://unit42.paloaltonetworks.com/category/business-email-compromise/ "Business Email Compromise")  
  [Business Email Compromise](https://unit42.paloaltonetworks.com/category/business-email-compromise/)

# Investigating Infrastructure and Tactics of Phishing-as-a-Service Platform Sniper Dz

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 10 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Code to Cloud Platform icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/prisma_RGB_logo_Icon_Color.png)Code to Cloud Platform](https://unit42.paloaltonetworks.com/product-category/code-to-cloud-platform/ "Code to Cloud Platform")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")[![Prisma Cloud icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/prisma_RGB_logo_Icon_Color.png)Prisma Cloud](https://unit42.paloaltonetworks.com/product-category/prisma-cloud/ "Prisma Cloud")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Shehroze Farooqi](https://unit42.paloaltonetworks.com/author/shehroze-farooqi/)
  * [Howard Tong](https://unit42.paloaltonetworks.com/author/howard-tong/)
  * [Alex Starov](https://unit42.paloaltonetworks.com/author/alex-starov/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:September 24, 2024

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Business Email Compromise](https://unit42.paloaltonetworks.com/category/business-email-compromise/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [PhaaS](https://unit42.paloaltonetworks.com/tag/phaas/)
  * [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/)
  * [Phishing as a service](https://unit42.paloaltonetworks.com/tag/phishing-as-a-service/)
  * [Phishing Kit](https://unit42.paloaltonetworks.com/tag/phishing-kit/)
  * [Proxy Server](https://unit42.paloaltonetworks.com/tag/proxy-server/)
  * [Sniper Dz](https://unit42.paloaltonetworks.com/tag/sniper-dz/)
  * [Telegram](https://unit42.paloaltonetworks.com/tag/telegram/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/phishing-platform-sniper-dz-unique-tactics/?pdf=download&lg=en&_wpnonce=279fa6c5e6 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/phishing-platform-sniper-dz-unique-tactics/?pdf=print&lg=en&_wpnonce=279fa6c5e6 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Investigating%20Infrastructure%20and%20Tactics%20of%20Phishing-as-a-Service%20Platform%20Sniper%20Dz&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fphishing-platform-sniper-dz-unique-tactics%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fphishing-platform-sniper-dz-unique-tactics%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fphishing-platform-sniper-dz-unique-tactics%2F&title=Investigating%20Infrastructure%20and%20Tactics%20of%20Phishing-as-a-Service%20Platform%20Sniper%20Dz "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fphishing-platform-sniper-dz-unique-tactics%2F&text=Investigating%20Infrastructure%20and%20Tactics%20of%20Phishing-as-a-Service%20Platform%20Sniper%20Dz "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fphishing-platform-sniper-dz-unique-tactics%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Investigating%20Infrastructure%20and%20Tactics%20of%20Phishing-as-a-Service%20Platform%20Sniper%20Dz%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fphishing-platform-sniper-dz-unique-tactics%2F "Share in Mastodon")

## **Executive Summary**

We have been monitoring a widely popular phishing-as-a-service (PhaaS) platform named Sniper Dz that primarily targets popular social media platforms and online services. A large number of phishers could be using this platform to launch phishing attacks, since the group behind this kit has thousands of subscribers on its Telegram channel. Our research revealed over 140,000 phishing websites associated with the Sniper Dz PhaaS platform over the past year.

For prospective phishers, Sniper Dz offers an online admin panel with a catalog of phishing pages. Phishers can either host these phishing pages on Sniper Dz-owned infrastructure or download Sniper Dz phishing templates to host on their own servers. Surprisingly, Sniper Dz PhaaS offers these services free of charge to phishers -- perhaps because Sniper Dz also collects victim credentials stolen by phishers who use the platform to compensate for the cost of service.

Sniper Dz uses a unique approach of hiding phishing content behind a public proxy server to launch live phishing attacks. The criminals behind this platform auto-setup the proxy server to load phishing content that is hosted on their server. We believe this approach could be useful in protecting their infrastructure from detection.

Criminals using Sniper Dz often abuse legitimate software-as-a-service (SaaS) platforms to host phishing websites. When establishing their infrastructure, these phishers include popular brand names, trends and even sensitive topics as keywords to lure victims into opening and using their phishing pages. After stealing credentials from a victim, this infrastructure can redirect the victim to malicious advertisements including distribution of potentially unwanted applications or programs (PUA or PUP) like rogue browser installers.

Palo Alto Networks customers are better protected from the threats discussed in this article through our [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall)'s [Advanced URL Filtering](https://docs.paloaltonetworks.com/advanced-url-filtering) and [Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security) subscriptions.

If you think you might have been compromised or have an urgent matter, contact the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html).

| **Related Unit 42 Topics** | [**Phishing Kit**](https://unit42.paloaltonetworks.com/tag/phishing-kit/), **[Business Email Compromise (BEC)](https://unit42.paloaltonetworks.com/category/business-email-compromise/)** |
|----------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|

## **Sniper Dz PhaaS Platform**

Sniper Dz is a PhaaS platform that allows prospective phishers to launch phishing attacks. Sniper Dz offers an admin panel to generate phishing pages.

Gaining access to this admin panel requires creating an account with an email address. Once users (or phishers) create an account, they can access a wide variety of phishing pages targeting popular brands.

Sniper Dz provides two different methods to launch live phishing attacks.

1. Phishing pages hosted on Sniper Dz infrastructure
2. Downloadable phishing templates to host on one's own infrastructure

### **Phishing Pages Hosted on Sniper Dz Infrastructure**

Sniper Dz can host phishing pages on its own infrastructure and provide customized links pointed to those pages. Figure 1 shows the Sniper Dz admin panel page that shares temporary links pointing to live phishing pages for different brands customized for the registered user. In this way, a prospective phisher does not have to set up a web server to host phishing websites and use Sniper Dz's infrastructure to launch phishing attacks.
![Screenshot of the Sniper Dz admin panel. The Page tab is open and there is also a Links tab. The main focus is on screenshots of multiple websites with some information redacted. There are recommended links that can be copied and pasted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-744234-136850-1.png) Figure 1. Sniper Dz admin panel to launch phishing attacks on Sniper Dz-hosted infrastructure.

Content for these live phishing pages is hidden behind proxy servers to prevent detection, which we will explain in more detail later in this article.

### **Downloadable Phishing Templates**

Sniper Dz also enables phishers to download phishing page templates offline as HTML files and host them on their own servers. Figure 2 shows the page to download phishing templates of numerous target brands. Prospective phishers can simply pick a target brand, download the associated phishing page, and deploy it on their own servers.
![Screenshot of Sniper Dz website interface displaying various options for template page setups, customizable buttons for data management, and different user account status panels, all depicted in a dark mode theme.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-749977-136850-2.png) Figure 2. List of downloadable phishing template pages from the Sniper Dz site.

### **Is This Really a Free-of-Charge PhaaS Platform?**

Surprisingly, Sniper Dz offers both phishing attack options free of charge. Normally, PhaaS platforms and phishing kit authors charge money. Setting up a live phishing attack using PhaaS platforms can cost hundreds of dollars in monthly subscription fees, as seen with the [Caffeine PhaaS](https://securityintelligence.com/articles/phishing-as-a-service-makes-us-jittery/) or the [Darcula PhaaS.](https://www.darkreading.com/endpoint-security/-darcula-phishing-as-a-service-operation-bleeds-victims-worldwide)

Why does Sniper Dz provide PhaaS free of charge? Perhaps because Sniper Dz collects victim credentials stolen by phishers who use their platform to compensate for the cost of service.

Sniper Dz leaves a backdoor inside the phishing page for tracking and collecting stolen credentials as we describe later in this article. Providing this service for free allows Sniper Dz to register more phishers and obtain more stolen credentials. There are no free lunches.

## **Infrastructure and Tactics**

This section highlights key infrastructure and tactics employed by Sniper Dz. We describe evasion tactics such as hiding phishing content behind public proxy servers and obfuscating phishing content. We also show how Sniper Dz uses a centralized infrastructure to collect victim credentials stolen by other phishers and to track victims.

### **Hiding Phishing Content Behind Public Proxy Servers**

Sniper Dz abuses a legitimate public proxy server (proxymesh\[.\]com) to hide its phishing content. Threat actors often abuse, take advantage of or subvert legitimate products for malicious purposes. This does not imply that the legitimate product is flawed or malicious.

The group behind Sniper Dz configures this proxy server to automatically load phishing content from its own server without direct communications. This technique can help Sniper Dz to protect its backend servers, since the victim's browser or a security crawler will see the proxy server as being responsible for loading the phishing payload.

Figure 3 shows how Sniper Dz uses a public proxy server to hide requests to its web server (dev-cdn370\[.\]pantheonsite\[.\]io) hosting phishing content. The entry point is a disposable decoy phishing page that attackers could distribute to victims through emails or social media platforms. When a victim opens this page, it returns a script to automatically configure the proxy server.
![Flowchart explaining a phishing attack via a proxy server setup, involving a decoy page, public server, and a web server hosting phishing content. Major steps include victim opening phishing webpage, proxy server configuration, and delivery of phishing content. Logo of Palo Alto Networks and Unit 42 appear at the bottom.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-754830-136850-3.png) Figure 3. Workflow of hiding phishing content behind a public proxy server.

Figure 4 shows part of the HTML content of a decoy phishing page that also includes this script to auto-configure the proxy server. The page includes an HTTP POST request form to proxymesh\[.\]com/web/index.php.
![Screenshot of HTML and JavaScript code related to a form element on the 'proxymesh.com' website. The code includes functions for encoding URLs and adding event listeners to a form. Two sections are highlighted in red boxes.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-758477-136850-4.png) Figure 4. An example of HTML code from a decoy webpage used to load phishing content from a proxy server.

This form mimics the request to load an input URL using a proxy provided by proxymesh\[.\]com. The JavaScript code snippet at the bottom assigns the "url" field of this form to the location of the phishing content, then it auto-submits the form to request content from the specified URL.

Eventually, the proxy server loads content from the web server hosting phishing content. As a result, the victim browser loads the phishing content through the proxy server without initiating a request to the web server hosting the phishing content. To detect such backend web servers hiding behind public proxy servers, defenders need to extract destination URLs by analyzing the scripts on the phishing pages.

To the best of our knowledge, we are the first to report this behavior of hiding backend server hosting phishing content behind public proxy servers.

### **Obfuscating Phishing Template Code**

The contents of phishing template pages are heavily obfuscated. Figure 5 shows code from an example of a phishing page with obfuscated JavaScript to render the HTML script.
![Screenshot of computer code written in JavaScript displayed in a text editor, with various functions and strings visible. At the bottom, two sections are highlighted within red boxes.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-762496-136850-5.png) Figure 5. Obfuscated JavaScript snippets of a phishing page.

For example, it uses String.fromCharCode and unescape functions that we find attackers commonly use for obfuscating content. This obfuscation allows it to hide HTML code and critical infrastructure endpoints like the exfiltration URL.

### **Centralized Infrastructure to Exfiltrate Credentials**

These phishing pages exfiltrate credentials to a centralized infrastructure that Sniper Dz owns. Figure 6 shows a Google Chrome debugger console view of the exfiltration URL raviral\[.\]com/k\_fac.php where email and password are exfiltrated in parameters email and pass.

![Screenshot of response headers, request headers, and form data for a Netflix login page, highlighting the fields for email and password.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-767099-136850-6.png) Figure 6. Stolen credentials are exfiltrated to the endpoint raviral\[.\]com/k\_fac.php that Sniper Dz controls. By exfiltrating credentials to a centralized infrastructure it owns, Sniper Dz can harvest credentials from all of its clients' victims, including those who fell prey to its phishing templates hosted on other servers.

For phishers, stolen credentials of victims are displayed on the admin panel as shown in Figure 7. The admin panel shows the following information from the time the credentials were exfiltrated:

* Username
* Password
* Template name
* Date and time
* Victim's IP address and country

![A screenshot showing a web browser interface for "sniperdz.com" titled 'VICTIMS'. The screen displays a table with columns such as Id, Scama name, User name and more. Two entries are visible from the United States, and the interface includes navigation buttons and functionality for searching, downloading, and removing entries. There are more options and tools in the left sidebar.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-773078-136850-7.png) Figure 7. Admin panel showing stolen credentials of victim along with additional information such as victim's IP address, country and time.

### **Tracking Victims and Phishing Templates**

Sniper Dz tracks its victims by embedding custom JavaScript and analytics services. Figure 8 shows a custom tracking script for raviral\[.\]com/host\_style/style/js-track/track.js included on a phishing page.
![A screenshot displaying a segment of HTML code with references to Netflix and other generic script elements. The last line has a section highlighted by a red box.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-777725-136850-8.png) Figure 8. Example of a script included on a phishing page to track victims.

This script in turn loads a tracker from a legitimate analytics service. We surmise that these scripts allow Sniper Dz to track victims that visit both PhaaS links hosted on Sniper Dz infrastructure as well as offline phishing templates hosted by phishers on their own infrastructure.

## **Phishing Attacks Using Sniper Dz**

Since last year, we have discovered over 140,000 phishing webpages associated with the Sniper Dz PhaaS platform. Figure 9 shows the discovery of these websites since July 2023.
![Line graph displaying fluctuations in the number of URLs. The y-axis is on a logarithmic scale from 1 to 10,000, and the x-axis shows dates from July 1, 2023, to July 1, 2024. Logo of Palo Alto Networks and Unit 42.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/chart-1.png) Figure 9. Discovery of live phishing pages authored by Sniper Dz in the past year.

Sniper Dz has remained active throughout this period. While its activity peaked in late 2023, we observed a surge in their activity starting in July 2024. Geographically, these phishing websites primarily target web users in the US.

Sniper Dz could have thousands of phishers as customers who are using its PhaaS platform to launch these phishing attacks. For example, Sniper Dz operates a Telegram channel t\[.\]me/JokerDzV2 for customer support that had 7,156 subscribers in August 2024 as shown in Figure 10.

![Promotional image for Telegram channel "Sniper Dz" which features a logo with a stylized sniper image and the text "sniperdz.com". The channel has 7 followers. There is a "View in Telegram" button and a "Download" button at the top.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-786658-136850-10.png) Figure 10. Telegram channel t\[.\]me/JokerDzV2 for Sniper Dz. In fact, one of the tutorial videos on this Telegram channel at

* t\[.\]me/JokerDzV2/19

had 72,600 views in August 2024 as shown in Figure 10. A large number of Telegram channel subscribers and video views indicate that a substantial number of prospective phishers could be using the Sniper Dz PhaaS platform.
![Social media post from "Sniper Dz" displaying an error message saying "Media is too big" with a button labeled "VIEW IN TELEGRAM". Includes a link to Telegram, a view count, and a timestamp indicating November 10, 2020, at 02:29.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-790855-136850-11.png) Figure 11. Tutorial video to launch phishing attacks using Sniper Dz.

### **Abusing Legitimate SaaS Platforms to Launch Phishing Attacks**

Most of the Sniper Dz phishing pages we have detected are hosted on legitimate SaaS platforms. [Attackers commonly target legitimate SaaS platforms](https://unit42.paloaltonetworks.com/platform-abuse-phishing/) because the good reputation of legitimate domains can help threat actors evade detection from security crawlers. Blogspot was the most popular target among legitimate SaaS platforms.

Blogspot appears to be more popular because the Sniper Dz admin panel offers an easy way to convert phishing templates to the Blogger format as shown below in Figure 12. Sniper Dz also provides a tutorial guide to enter converted phishing pages into Blogger for hosting on Blogspot.
![Screenshot of a software application menu, labeled "SNIPERDZ" at the top. The menu includes icons and text for various options including Home, Victims, Scams, Change Password, Scam Encrypter, Convert To Blogger, and Tutorials. The Convert To Blogger option is highlighted with an XML tag indicating its format, and some options have additional labels like 'Offline', 'Beta', and 'Pro'.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-794249-136850-12.png) Figure 12. Sniper Dz admin panel offers a feature to convert a phishing page into a Blogger template.

### **Using Brand Names or Trends/Events as Keywords in Hostnames**

Sniper Dz authored phishing pages use keywords in hostnames that match popular brand names and trends or events, including sensitive political events. These deceptive hostnames can lure victims to these phishing pages and fall prey to phishing attacks.

### **Malicious Redirects and PUP Distribution**

Sniper Dz phishing pages can redirect users to other Sniper Dz owned websites like raviral\[.\]com after a victim is fooled into giving away login credentials. Attackers proliferate the raviral\[.\]com website with malicious advertisements and distribute PUA/PUP-like, suspiciously labeled ad blockers and other browser extensions.

During one of our test runs, the website triggered download of an installer for a rogue browser named Artificus as shown in Figure 13. Artificus is known for its intrusive behavior and we have also [reported on it for being distributed by malicious advertisers](https://unit42.paloaltonetworks.com/apateweb-scareware-pup-delivery-campaign/).
![Download instructions for Artifactus software displayed on a webpage. Two options are shown: "Download Now" to start the download and "Run the Setup" for installation instructions.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-796802-136850-13.png) Figure 13. Webpage distributing a rogue browser named Artificus.

## **Conclusion**

This article provides an in-depth investigation of an online PhaaS platform named Sniper Dz. Our study finds that a large number of phishers could be using this platform. We have discovered 140,000 phishing websites in the past year that we can attribute to this PhaaS.

We describe a unique technique employed by Sniper Dz to hide backend servers hosting phishing content behind public proxy servers. This technique allows Sniper Dz to protect its hosting infrastructure from security crawlers. Sniper Dz also uses more commonly known techniques to evade detections such as obfuscating phishing content and abusing legitimate SaaS platforms to host phishing pages.

We also found that Sniper Dz phishing pages exfiltrate victim credentials and track them through a centralized infrastructure. This could be helping Sniper Dz collect victim credentials stolen by phishers who use their PhaaS platform.

We hope this blog helps our readers to stay protected from the harmful effects of this phishing campaign. Palo Alto Networks customers are better protected from the threats discussed in this article through our [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall)'s [Advanced URL Filtering](https://docs.paloaltonetworks.com/advanced-url-filtering) and [Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security) subscriptions.

If you think you might have been compromised or have an urgent matter, get in touch with the[Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America Toll-Free: 866.486.4842 (866.4.UNIT42)
* EMEA: +31.20.299.3130
* APAC: +65.6983.8730
* Japan: +81.50.1790.0200

Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Acknowledgments

We'd like to thank the entire Unit 42 team for supporting us with this post. Special thanks to Bradley Duncan, Lysa Myers and Adnan Ahmed for their invaluable input on this blog.

## **Indicators of Compromise**

Sniper Dz PhaaS Platform:

* Sniperdz\[.\]com

Physical location of phishing webpages concealed using proxy servers:

* dev-cdn370.pantheonsite.io

Centralized exfiltration endpoint:

* raviral\[.\]com/k\_fac.php

Embedded tracker script:

* raviral\[.\]com/host\_style/style/js-track/track.js

Telegram support channel:

* t\[.\]me/JokerDzV2

Sniper Dz platform tutorial video:

* t\[.\]me/JokerDzV2/19

Redirection to Sniper Dz-owned websites:

* raviral\[.\]com

Examples of phishing websites generated using Sniper Dz:

* 6627c220b5daa507c6cca1c5--votedme\[.\]netlify.app
* automaticgiveaway\[.\]000webhostapp\[.\]com
* Climbing-green-botany\[.\]glitch\[.\]me
* facebookbusiness0078\[.\]blogspot.be
* free-fire-reward-garena-bd-nepazl\[.\]epizy\[.\]com
* freefirefff\[.\]github\[.\]io
* ff-rewards-redeem-codes-org\[.\]github.io
* instagram-cutequeen57\[.\]netlify.app
* pubg-tournament-official\[.\]github.io/free-fire-reedeem-code
* v0tingsystem\[.\]github\[.\]io

Examples of Sniper Dz Live phishing pages hosted on their own infrastructure:

* pro\[.\]riccardomalisano\[.\]com/about/z1to.html?u=ff-insta/?i=\[Redacted\_For\_Anonymity\]
* pro\[.\]riccardomalisano\[.\]com/about/z2to.html?u=ff-reward/?i=\[Redacted\_For\_Anonymity\]
* pro\[.\]riccardomalisano\[.\]com/about/z2to.html?u=ff-spiner/?i=\[Redacted\_For\_Anonymity\]
* pro\[.\]riccardomalisano\[.\]com/about/z1to.html?u=eb-log/?i=\[Redacted\_For\_Anonymity\]
* pro\[.\]riccardomalisano\[.\]com/about/z1to.html?u=s-mobi/?i=\[Redacted\_For\_Anonymity\]

Legitimate public proxy service abused to hide phishing content:

* proxymesh\[.\]com
  Back to top

### Tags

* [PhaaS](https://unit42.paloaltonetworks.com/tag/phaas/ "PhaaS")
* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")
* [Phishing as a service](https://unit42.paloaltonetworks.com/tag/phishing-as-a-service/ "phishing as a service")
* [Phishing Kit](https://unit42.paloaltonetworks.com/tag/phishing-kit/ "Phishing Kit")
* [Proxy Server](https://unit42.paloaltonetworks.com/tag/proxy-server/ "Proxy Server")
* [Sniper Dz](https://unit42.paloaltonetworks.com/tag/sniper-dz/ "Sniper Dz")
* [Telegram](https://unit42.paloaltonetworks.com/tag/telegram/ "Telegram")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Inside SnipBot: The Latest RomCom Malware Variant](https://unit42.paloaltonetworks.com/snipbot-romcom-malware-variant/ "Inside SnipBot: The Latest RomCom Malware Variant")

### Table of Contents

* 

### Related Articles

* [The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "article - table of contents")
* [Russian Global Webmail Espionage](https://unit42.paloaltonetworks.com/russian-webmail-espionage/ "article - table of contents")
* [Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector](https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/ "article - table of contents")

## Related Business Email Compromise Resources

![Pictorial representation of a group of individuals discussing an idea with a whiteboard.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/02_Listicle_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) February 3, 2026 [#### Why Smart People Fall For Phishing Attacks](https://unit42.paloaltonetworks.com/psychology-of-phishing/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/psychology-of-phishing/ "Why Smart People Fall For Phishing Attacks")  
  ![Pictorial representation of a IUAM ClickFix generator. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen, indicating malware.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/10/03_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) October 8, 2025 [#### The ClickFix Factory: First Exposure of IUAM ClickFix Generator](https://unit42.paloaltonetworks.com/clickfix-generator-first-of-its-kind/)

* [Bash](https://unit42.paloaltonetworks.com/tag/bash/ "bash")

* [ClickFix](https://unit42.paloaltonetworks.com/tag/clickfix/ "ClickFix")

* [Phishing Kit](https://unit42.paloaltonetworks.com/tag/phishing-kit/ "Phishing Kit")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/clickfix-generator-first-of-its-kind/ "The ClickFix Factory: First Exposure of IUAM ClickFix Generator")  
  ![Pictorial representation of phishing bait using AI. A luminous cube labeled "AI" centrally placed on a futuristic circuit board landscape with glowing blue lights and connections.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/03_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 19, 2025 [#### Fashionable Phishing Bait: GenAI on the Hook](https://unit42.paloaltonetworks.com/genai-phishing-bait/)

* [GenAI](https://unit42.paloaltonetworks.com/tag/genai/ "GenAI")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/genai-phishing-bait/ "Fashionable Phishing Bait: GenAI on the Hook")  
  ![Pictorial representation of social engineering. Digital illustration of four human profiles connected by glowing neural network lines against a dark background, symbolizing connectivity and technology.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/cover-1920x900-no-blades-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-report-white-1.svg)Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/) July 30, 2025 [#### 2025 Unit 42 Global Incident Response Report: Social Engineering Edition](https://unit42.paloaltonetworks.com/2025-unit-42-global-incident-response-report-social-engineering-edition/)

* [Agent Serpens](https://unit42.paloaltonetworks.com/tag/agent-serpens/ "Agent Serpens")

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ClickFix](https://unit42.paloaltonetworks.com/tag/clickfix/ "ClickFix")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/2025-unit-42-global-incident-response-report-social-engineering-edition/ "2025 Unit 42 Global Incident Response Report: Social Engineering Edition")  
  ![Pictorial representation of homograph attacks. 3D illustration of an open laptop displaying an envelope icon on the screen, accompanied by a smartphone and tablet, all set against a dark background with neon lighting.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/01_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 25, 2025 [#### The Ηоmоgraph Illusion: Not Everything Is As It Seems](https://unit42.paloaltonetworks.com/homograph-attacks/)

* [GenAI](https://unit42.paloaltonetworks.com/tag/genai/ "GenAI")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/homograph-attacks/ "The Ηоmоgraph Illusion: Not Everything Is As It Seems")  
  ![Pictorial representation of the ransomware landscape. Digital artwork of a disintegrating U.S. dollar bill with pixelated effects on a cyber-inspired background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-report-white-1.svg)Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/) April 23, 2025 [#### Extortion and Ransomware Trends January-March 2025](https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/)

* [BianLian](https://unit42.paloaltonetworks.com/tag/bianlian/ "BianLian")

* [Akira ransomware](https://unit42.paloaltonetworks.com/tag/akira-ransomware/ "Akira ransomware")

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/ "Extortion and Ransomware Trends January-March 2025")  
  ![Pictorial representation of a QR code phishing campaign. Digital artwork of a futuristic, glowing shield disintegrating into small particles, set against a dark blue, speckled background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/03/09_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) April 1, 2025 [#### Evolution of Sophisticated Phishing Tactics: The QR Code Phenomenon](https://unit42.paloaltonetworks.com/qr-code-phishing/)

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")

* [Social engineering](https://unit42.paloaltonetworks.com/tag/social-engineering/ "social engineering")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/qr-code-phishing/ "Evolution of Sophisticated Phishing Tactics: The QR Code Phenomenon")  
  ![An Asian woman examining data on multiple computer screens in a high-tech digital environment, surrounded by visual representations of data and code. Lens flare is prominent across the image.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/02/07_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) February 28, 2025 [#### JavaGhost's Persistent Phishing Attacks From the Cloud](https://unit42.paloaltonetworks.com/javaghost-cloud-phishing/)

* [AWS](https://unit42.paloaltonetworks.com/tag/aws/ "AWS")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/javaghost-cloud-phishing/ "JavaGhost’s Persistent Phishing Attacks From the Cloud")  
  ![Pictorial representation of a European phishing campaign. A digital artwork depicting a glowing, futuristic shield disintegrating into small fragments against a shimmering blue background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/12/09_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 18, 2024 [#### Effective Phishing Campaign Targeting European Companies and Organizations](https://unit42.paloaltonetworks.com/european-phishing-campaign/)

* [EMEA](https://unit42.paloaltonetworks.com/tag/emea/ "EMEA")

* [Manufacturing](https://unit42.paloaltonetworks.com/tag/manufacturing/ "Manufacturing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/european-phishing-campaign/ "Effective Phishing Campaign Targeting European Companies and Organizations")  
  ![A pictorial representation of a campaign like BeaverTail. Digital globe with interconnected network lines and data streams on a futuristic interface, symbolizing global connectivity and information technology advancements.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/01_Nation-State-cyberattacks_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) November 14, 2024 [#### Fake North Korean IT Worker Linked to BeaverTail Video Conference App Phishing Attack](https://unit42.paloaltonetworks.com/fake-north-korean-it-worker-activity-cluster/)

* [North Korea](https://unit42.paloaltonetworks.com/tag/north-korea/ "North Korea")

* [Lazarus](https://unit42.paloaltonetworks.com/tag/lazarus/ "Lazarus")

* [BeaverTail](https://unit42.paloaltonetworks.com/tag/beavertail/ "BeaverTail")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/fake-north-korean-it-worker-activity-cluster/ "Fake North Korean IT Worker Linked to BeaverTail Video Conference App Phishing Attack")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
