hacker-news · Crawled Jul 9, 2026

Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes

2 IoCs
Read original article ↗

AI Summary

A threat actor named Lurking Lizard has been operating a malicious residential proxy business since at least August 2022, using trojanized installers and fake mobile apps to recruit devices into a proxy botnet. The actor leverages lookalike domains, including '7zip[.]com', and impersonates legitimate proxy services to drive traffic to scam storefronts. Compromised devices are used to funnel third-party traffic, creating risks for users whose IP addresses may be abused for cyberattacks.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
Domain 7zip[.]com Details →
Domain iplogger[.]com Details →