discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes

A new threat actor, Lurking Lizard, has been operating a malicious residential proxy business since August 2022, using fake software installers to turn victim devices into proxy nodes.

By Ravie Lakshmanan·Jul 9·thehackernews.com·3 min read

Intelligence analysis by Gemini 2.5 Flash

Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
Image: thehackernews.com

Lurking Lizard employs sophisticated tactics, including trojanized 7-Zip installers and impersonating legitimate proxy providers, to build a botnet of compromised devices. These devices are then used as residential proxy nodes, with the operation spanning victim acquisition, infrastructure, marketing, and monetization, posing significant risks to unsuspecting users.

Why it matters

This story highlights a growing and complex cybercrime trend where everyday devices are secretly co-opted into vast proxy networks, enabling attackers to mask their activities and exposing device owners to legal and security risks.

Imagine someone tricks you into installing a game on your computer, but secretly, that game also lets other people use your internet connection like a secret tunnel. These bad guys, called Lurking Lizard, trick lots of people with fake apps, turning their computers and phones into these 'tunnels.' Then, other bad guys pay Lurking Lizard to use these tunnels to hide what they're doing online, which can be naughty stuff. It's like your house is being used by strangers without you knowing, and it could cause trouble for you.

Analysis

Lurking Lizard's Deceptive Playbook

The threat actor, dubbed Lurking Lizard, has demonstrated a highly sophisticated and multi-faceted approach to building and monetizing its illicit residential proxy network. Their primary method involves luring victims with trojanized software installers, notably a fake 7-Zip application hosted on a lookalike domain, "7zip[.]com." This tactic leverages common user behavior, as individuals often seek out popular utilities, making them susceptible to cleverly disguised malware.

Beyond direct malware distribution, Lurking Lizard also engages in extensive brand impersonation, mimicking major proxy providers like IPIDEA and SmartProxy. To further legitimize their scam, they operate fake "independent" review sites, strategically driving traffic to their own fraudulent storefronts. A particularly cunning technique employed is "drop-catching," where they acquire expired domains to inherit their historical legitimacy and search engine ranking, thereby enhancing the perceived trustworthiness of their malicious infrastructure.

The Scale of Compromise and Monetization

The scale of Lurking Lizard's operation is substantial, with Infoblox identifying an infrastructure comprising over 230 lookalike domains. The campaign's reach extends across multiple operating systems, including Windows, macOS, and Android, indicating a broad targeting strategy. The use of WireVPN branding represents an evolution in their mobile targeting, with one Android app, "wirevpn - Fast Unlimited Proxy," amassing over a million downloads, though the organic nature of these downloads remains questionable.

Once victim devices are recruited into the actor-controlled proxy botnet, the network is monetized through various lookalike proxy service brands. This end-to-end operation effectively transforms unsuspecting users' devices into exit nodes, funneling third-party traffic and creating a lucrative, unlawful proxy business. The article also draws parallels to malvertising, suggesting a complex ecosystem that is difficult to dismantle due to its coordinated nature.

Elusive Solutions and Enduring Risks

The challenge in combating operations like Lurking Lizard lies in their adaptability and the inherent complexity of the residential proxy space. While Google has taken steps to degrade similar networks, such as NetNut (Popa) and IPIDEA, the article notes that "solutions are still elusive." This difficulty stems from the distributed nature of the botnets and the sophisticated methods used for victim acquisition and monetization, making it hard to pinpoint and neutralize the entire chain of command.

For unsuspecting device owners, the risks are significant. Their home IP addresses can be used as launchpads for hacking, fraud, and other unauthorized activities, potentially leading to their legitimate traffic being flagged as suspicious or blocked by service providers. The lack of clear indicators for users that their devices are compromised, especially in mobile applications, further exacerbates the problem, leaving millions vulnerable to being unwitting participants in cybercrime.

Key points

  • Lurking Lizard is a new threat actor operating a malicious residential proxy business since August 2022.
  • They use trojanized software installers, like fake 7-Zip, and impersonate legitimate proxy providers to compromise devices.
  • The operation involves over 230 lookalike domains and targets Windows, macOS, and Android devices.
  • Compromised devices are turned into proxy nodes, monetized through fake proxy service brands and review sites.
  • The illicit scheme poses significant risks to device owners, whose IP addresses can be used for unauthorized activities.
The Upside

Recent actions by major tech companies like Google, which successfully degraded the NetNut and IPIDEA residential proxy networks, demonstrate that these illicit operations can be disrupted. Continued vigilance and coordinated efforts from cybersecurity researchers and platform providers could lead to more effective takedowns and better protection for users.

The Downside

The article explicitly states that solutions to this type of unlawful proxy business are "still elusive," indicating a persistent and evolving threat. The sophisticated, multi-stage nature of Lurking Lizard's operations, coupled with the difficulty in detecting compromised devices, suggests that many users will remain vulnerable to having their devices co-opted for illicit activities.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritymalwarecybercrimebotnetthreat-intelligencedomain-abusesupply-chain

Author

Ravie Lakshmanan

Intelligence analysis by

Gemini 2.5 Flash

Published

Jul 9, 2026

Source

thehackernews.com

Share

Topics

securitymalwarecybercrimebotnetthreat-intelligencedomain-abusesupply-chain

Related

More from this desk

Aug 24·bleepingcomputer.com

Hackers target WordPress sites in miniOrange auth bypass attacks

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The vulnerabilities can be used to forge SAML responses and log in as administrators.

Aug 24·bleepingcomputer.com

TikTok reaches $400M settlement with US over COPPA violations

The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children’s Online Privacy Protection Act (COPPA).

Aug 24·bleepingcomputer.com

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

ReliaQuest confirms a failed data-theft attack after hackers impersonated a member of the security team. An attacker called multiple employees and tried to trick them into accessing a fake ReliaQuest single sign-on (SSO) page.

Aug 24·thehackernews.com

Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

U.S. agencies warn of AI-powered attacks on Siemens S7 Series PLCs as a GitLab code-injection flaw (CVE-2026-19478) faces active exploitation, alongside npm supply-chain attacks and suspected Russian espionage clusters.