hacker-news · Crawled Jul 9, 2026
Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
2 IoCs
Read original article ↗
AI Summary
A threat actor named Lurking Lizard has been operating a malicious residential proxy business since at least August 2022, using trojanized installers and fake mobile apps to recruit devices into a proxy botnet. The actor leverages lookalike domains, including '7zip[.]com', and impersonates legitimate proxy services to drive traffic to scam storefronts. Compromised devices are used to funnel third-party traffic, creating risks for users whose IP addresses may be abused for cyberattacks.
AI-extracted · verify before operational use