Threat Intelligence

That 7-Zip Installer Turned Your Computer into a Criminal Proxy Node 

That 7-Zip Installer Turned Your Computer into a Criminal Proxy Node 

Something we track in the Adversary Operations Group is residential proxy networks. Infoblox uncovered an operation they call Lurking Lizard, running since at least August 2022, that uses fake software installers to conscript devices as proxy nodes. There are more than 230 lookalike domains, including fake review sites and Trojanized installers for 7-Zip, WhatsApp, TikTok tools, and a VPN called WireVPN. Security Affairs confirmed the WireVPN Android app has over 1 million downloads and is signed with a valid code signing certificate issued to a UK-registered entity. 

The Infection 

The most visible campaign used a fake 7-Zip installer on 7zip[.]com, a domain that catches traffic from people mistyping the real 7-zip[.]org. The installer works as expected. It also silently enrolls the device as a proxy node. Infoblox found the malware installed files named hero.exe and uphero.exe into C:\Windows\SysWOW64\hero. The WireVPN variant uses wire.exe and upwire.exe into C:\Windows\SysWOW64\wire. Same structure, different name. 

When Infoblox analyzed WireVPN’s network behaviour, it did not look like a VPN. Instead of a single stable tunnel to a fixed endpoint, the client maintained multiple concurrent connections across a broad set of globally distributed hosts. Other people’s traffic exits through the IP address of whoever installed the app. 

The Business 

Lurking Lizard runs every layer of the operation. They acquire victims through Trojanized installers. They run the proxy infrastructure. They market access through fake storefronts impersonating IPIDEA, SmartProxy, and 911Proxy. They run fake independent review sites to drive traffic to their own storefronts. 

The actor uses drop-catching: acquiring recently expired domains to inherit their search engine rankings. They exploit incorrectly referenced domain names at scale. The IPLogger URL hxxps://iplogger[.]com/mnWD appeared across multiple distinct payloads spanning years, linking the 7-Zip campaign to WhatsApp lures, TikTok downloaders, and WireVPN samples. 

 WHOIS registration data points toward China. A registrant name of Cheng Li linked the fake 7-Zip domain to the cluster of lookalike proxy service domains. A phone number in the registration data placed the registrant in Wuhan, China. 

The Wider Problem 

This is one operation in a larger ecosystem. Google recently disrupted the NetNut network, which turned at least 2 million smart TVs and streaming boxes into proxy nodes. Malwarebytes documented the same 7-Zip campaign in February 2026. The residential proxy industry is not a collection of isolated malware campaigns. It is an industrial-scale ecosystem where multiple actors compete for the same pool of compromised devices. 

Sources 

The Hacker News: Fake 7-Zip Installers Turn Devices into Residential Proxy Nodes, 9 Jul 2026 – https://thehackernews.com/2026/07/fake-7-zip-installers-turn-devices-into.html 

Security Affairs: Fake VPN and 7-Zip Apps Turn Victims into Residential Proxy Nodes, 9 Jul 2026 – https://securityaffairs.com/194990/malware/fake-vpn-and-7-zip-apps-turn-victims-into-residential-proxy-nodes.html