mediumMalware

Lurking Lizard Fake 7-Zip Installer Residential Proxy Campaign

First seen Jul 9, 2026 · Updated Jul 9, 2026

residential-proxyfake-installertrojanized-softwaremalvertisingdns-abuseagent-relevant

A threat actor dubbed Lurking Lizard has been running a residential proxy business since at least August 2022 using more than 230 lookalike domains that distribute trojanized software installers, including fake 7-Zip installers. Victims who download these fake installers unknowingly turn their devices into residential proxy exit nodes, which are then resold for anonymized traffic routing, potentially including malicious or fraudulent activity.

Technical Analysis

The Lurking Lizard operation uses typosquatted and lookalike domains impersonating legitimate software distribution sites (e.g., 7-Zip) to trick users into downloading trojanized installers. Once executed, the installers silently deploy proxyware components that enroll the compromised host into a residential proxy network, allowing the operators to monetize the device's bandwidth and IP reputation for third-party traffic relay. The campaign leverages DNS infrastructure at scale (230+ domains) to evade takedown and blocklisting, and Infoblox's DNS threat intelligence was used to uncover the pattern of registrations and traffic. Hosts compromised in this manner—including developer workstations or servers running automated build/download pipelines—could see their egress IPs abused for proxying traffic from other malicious actors, and if such a host also runs AI agents or LLM tool-use pipelines that fetch dependencies or make outbound API calls, the compromised proxy layer could intercept, redirect, or degrade agent network traffic, and any credentials or API keys used by agents on that host are at risk of exposure through the installed malware.

Affected Systems

Windows systems where users download 7-Zip or other utility software from unofficial/lookalike domains rather than official sources; general end-user and enterprise workstations without application allowlisting or download source verification

Indicators of Compromise

  • 230+ lookalike domains impersonating legitimate software distribution sites (specific domain list not disclosed in source)
  • Fake 7-Zip installer executables (file hashes not disclosed in source)
  • Proxyware/residential-proxy client payloads dropped post-installation

Remediation Steps

  1. 1

    Verify download sources

    Only download software such as 7-Zip from official vendor websites or verified package managers; block or flag lookalike/typosquatted domains via DNS filtering.

  2. 2

    Deploy DNS threat intelligence

    Use DNS security solutions (e.g., Infoblox or equivalent) to detect and block newly registered lookalike domains associated with this campaign.

  3. 3

    Application allowlisting

    Enforce application control policies to prevent execution of unsigned or unverified installers on endpoints, especially on hosts running automated or agent-driven workflows.

  4. 4

    Monitor for proxyware behavior

    Inspect endpoints for unexpected outbound proxy traffic, unfamiliar background processes, or unusual bandwidth usage indicative of residential proxy client installation.

  5. 5

    Credential and API key rotation

    Rotate any credentials or API keys stored on hosts suspected of compromise, particularly on systems that run AI agents or automated pipelines with outbound network access.

Industries Most Exposed

TechnologyConsumerEnterprise ITSoftware Distribution

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.