Cybersecurity researchers at Infoblox have uncovered a threat actor tracked as Lurking Lizard, operating an end-to-end malicious residential proxy business since at least August 2022. The actor uses over 230 lookalike domains to distribute trojanized installers, including a fake 7-Zip installer hosted on ‘7zip[.]com’, which covertly recruits compromised devices as proxy nodes.
Lurking Lizard impersonates major proxy providers such as IPIDEA, SmartProxy (now Decodo), IP Royal, and 911Proxy, and runs fake review sites to drive traffic to scam storefronts. The actor also uses drop-catching—acquiring expired domains to inherit their legitimacy—and exploits incorrectly referenced domain names (e.g., ‘7zip[.]com’ instead of ‘7-zip[.]org’).
Further analysis reveals the same infrastructure serves fake installers for 7-Zip, WhatsApp, TikTok/YouTube downloaders, and WireVPN, targeting Android, macOS, and Windows. One Android app, ‘wirevpn – Fast Unlimited Proxy’ by WEILAI NETWORK TECHNOLOGY CO., LIMITED, has over 1 million downloads. The operation monetizes victim devices through a proxy botnet, with lookalike proxy brands and fake review sites driving traffic.
This discovery follows Google’s takedown of the NetNut (Popa) residential proxy network, which compromised at least 2 million devices via malware-laced SDKs. The parallels highlight the growing complexity of residential proxy abuse and the challenges in mitigating such threats.
CVEs: CVE-2026-55200, CVE-2026-46817
Attack groups: Lurking Lizard
Malware: WireVPN
Companies: Infoblox, IPIDEA, SmartProxy, Decodo, IP Royal, 911Proxy, WEILAI NETWORK TECHNOLOGY CO., LIMITED, Proxyway, HeroSMS, Google, NetNut, Popa
Original source: thehackernews.com