Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
A new threat actor, Lurking Lizard, has been operating a malicious residential proxy business since August 2022, using fake software installers to turn victim devices into proxy nodes.
Intelligence analysis by Gemini 2.5 Flash

Lurking Lizard employs sophisticated tactics, including trojanized 7-Zip installers and impersonating legitimate proxy providers, to build a botnet of compromised devices. These devices are then used as residential proxy nodes, with the operation spanning victim acquisition, infrastructure, marketing, and monetization, posing significant risks to unsuspecting users.
Imagine someone tricks you into installing a game on your computer, but secretly, that game also lets other people use your internet connection like a secret tunnel. These bad guys, called Lurking Lizard, trick lots of people with fake apps, turning their computers and phones into these 'tunnels.' Then, other bad guys pay Lurking Lizard to use these tunnels to hide what they're doing online, which can be naughty stuff. It's like your house is being used by strangers without you knowing, and it could cause trouble for you.
Analysis
Lurking Lizard's Deceptive Playbook
The threat actor, dubbed Lurking Lizard, has demonstrated a highly sophisticated and multi-faceted approach to building and monetizing its illicit residential proxy network. Their primary method involves luring victims with trojanized software installers, notably a fake 7-Zip application hosted on a lookalike domain, "7zip[.]com." This tactic leverages common user behavior, as individuals often seek out popular utilities, making them susceptible to cleverly disguised malware.
Beyond direct malware distribution, Lurking Lizard also engages in extensive brand impersonation, mimicking major proxy providers like IPIDEA and SmartProxy. To further legitimize their scam, they operate fake "independent" review sites, strategically driving traffic to their own fraudulent storefronts. A particularly cunning technique employed is "drop-catching," where they acquire expired domains to inherit their historical legitimacy and search engine ranking, thereby enhancing the perceived trustworthiness of their malicious infrastructure.
The Scale of Compromise and Monetization
The scale of Lurking Lizard's operation is substantial, with Infoblox identifying an infrastructure comprising over 230 lookalike domains. The campaign's reach extends across multiple operating systems, including Windows, macOS, and Android, indicating a broad targeting strategy. The use of WireVPN branding represents an evolution in their mobile targeting, with one Android app, "wirevpn - Fast Unlimited Proxy," amassing over a million downloads, though the organic nature of these downloads remains questionable.
Once victim devices are recruited into the actor-controlled proxy botnet, the network is monetized through various lookalike proxy service brands. This end-to-end operation effectively transforms unsuspecting users' devices into exit nodes, funneling third-party traffic and creating a lucrative, unlawful proxy business. The article also draws parallels to malvertising, suggesting a complex ecosystem that is difficult to dismantle due to its coordinated nature.
Elusive Solutions and Enduring Risks
The challenge in combating operations like Lurking Lizard lies in their adaptability and the inherent complexity of the residential proxy space. While Google has taken steps to degrade similar networks, such as NetNut (Popa) and IPIDEA, the article notes that "solutions are still elusive." This difficulty stems from the distributed nature of the botnets and the sophisticated methods used for victim acquisition and monetization, making it hard to pinpoint and neutralize the entire chain of command.
For unsuspecting device owners, the risks are significant. Their home IP addresses can be used as launchpads for hacking, fraud, and other unauthorized activities, potentially leading to their legitimate traffic being flagged as suspicious or blocked by service providers. The lack of clear indicators for users that their devices are compromised, especially in mobile applications, further exacerbates the problem, leaving millions vulnerable to being unwitting participants in cybercrime.
Key points
- Lurking Lizard is a new threat actor operating a malicious residential proxy business since August 2022.
- They use trojanized software installers, like fake 7-Zip, and impersonate legitimate proxy providers to compromise devices.
- The operation involves over 230 lookalike domains and targets Windows, macOS, and Android devices.
- Compromised devices are turned into proxy nodes, monetized through fake proxy service brands and review sites.
- The illicit scheme poses significant risks to device owners, whose IP addresses can be used for unauthorized activities.
Recent actions by major tech companies like Google, which successfully degraded the NetNut and IPIDEA residential proxy networks, demonstrate that these illicit operations can be disrupted. Continued vigilance and coordinated efforts from cybersecurity researchers and platform providers could lead to more effective takedowns and better protection for users.
The article explicitly states that solutions to this type of unlawful proxy business are "still elusive," indicating a persistent and evolving threat. The sophisticated, multi-stage nature of Lurking Lizard's operations, coupled with the difficulty in detecting compromised devices, suggests that many users will remain vulnerable to having their devices co-opted for illicit activities.



