# Lurking Lizard's $M Industrial Residential Proxy Scheme: From Fake 7-Zip to a Global Botnet


A sophisticated China-based threat actor codenamed Lurking Lizard has been operating a sprawling criminal residential proxy business since at least August 2022, leveraging more than 230 lookalike domains, trojanized software installers, and counterfeit review sites to compromise over 773,000 devices worldwide. The operation represents a textbook example of end-to-end cybercriminal infrastructure designed to monetize compromised endpoints by funneling third-party internet traffic through victims' devices—often without their knowledge or consent.


## The Threat


The most visible manifestation of Lurking Lizard's operation emerged earlier this year when researchers detected a campaign distributing a trojanized 7-Zip installer through a domain spoofing the legitimate file compression utility. Users searching for or clicking links to "7zip[.]com"—a subtle misspelling of the actual open-source project at 7-zip.org—unknowingly downloaded malware that transformed their computers into nodes in a criminal proxy botnet.


Once installed, the malware quietly recruits victims' devices as residential proxy exit nodes, enabling the threat actor to:


  • Route third-party traffic through compromised machines, masking the true origin of requests
  • Monetize infected endpoints by selling access to cybercriminals, fraudsters, and other malicious actors
  • Evade detection and blocking by distributing traffic across thousands of legitimate residential IP addresses
  • Operate proxy services under counterfeit brands impersonating legitimate proxy providers

  • According to DNS threat intelligence firm Infoblox, the campaign has distributed fake installers for multiple applications beyond 7-Zip, including WhatsApp, TikTok/YouTube downloaders, and VPN clients—with mobile variants reaching 1 million downloads across Android and iOS platforms.


    ## Background and Context


    ### The Lurking Lizard Operation


    Lurking Lizard's infrastructure encompasses a carefully orchestrated ecosystem spanning victim acquisition, proxy hosting, fake marketing sites, and monetization channels. Infoblox first detected the broader network through analysis of 230+ registered domains, all exhibiting common fingerprints suggesting centralized control.


    Timeline of Activity:

  • August 2022: Initial activity detected
  • January 2026: Google dismantles IPIDEA infrastructure (a legitimate-appearing proxy service that Lurking Lizard was impersonating)
  • 2026 (ongoing): Expansion into mobile platforms and multi-OS trojans

  • ### Infrastructure: The Domain Drop-Catching Technique


    One of Lurking Lizard's most insidious tactics involves domain drop-catching—acquiring expired domain names to inherit their search rankings, accumulated trust signals, and historical reputation. This allows the threat actor to present itself with apparent legitimacy. For example:


  • The actor purchased 7zip[.]com (note the .com rather than .org), exploiting minor spelling variations to catch users making typos or relying on imprecise search results
  • WHOIS analysis and infrastructure fingerprinting suggest the actor has systematically acquired dozens of similar mistyped or recently-expired domains from legitimate proxy services

  • ### Impersonated Services


    Lurking Lizard maintains fake storefronts and marketing materials imitating established proxy providers:


    | Legitimate Service | Fake Variant | Status |

    |---|---|---|

    | IPIDEA | Multiple clones | Infrastructure dismantled by Google (Jan 2026) |

    | SmartProxy (now Decodo) | Lookalike domains | Still operational |

    | IP Royal | Counterfeit sites | Still operational |

    | 911Proxy | Fake review/comparison pages | Still operational |


    ## Technical Details


    ### The Infection Chain


    The attack chain follows a predictable but effective pattern:


    1. Luring: Victims are directed to malicious installers through:

    - Tutorial content and how-to guides linking to fake download pages

    - Organic search results (leveraging domain legitimacy from drop-catching)

    - Lookalike domain names exploiting minor spelling variations

    - Fake "independent" review sites run by the threat actor


    2. Infection: Trojans masquerading as legitimate software execute malware that:

    - Installs quietly without user awareness

    - Establishes persistence mechanisms to survive reboots

    - Connects to command-and-control (C2) infrastructure

    - Begins routing third-party traffic through the victim's device


    3. Monetization: Compromised devices are pooled and sold as:

    - Residential proxy services (sold under fake brand names)

    - IP pool access for fraud, credential stuffing, and account takeover campaigns

    - Traffic forwarding for click fraud and ad fraud schemes


    ### Cross-Platform Expansion


    Recent analysis uncovered the threat actor expanding beyond desktop Windows systems:


  • Android variants: A mobile app called "wirevpn - Fast Unlimited Proxy," allegedly developed by UK-based WEILAI NETWORK TECHNOLOGY CO., LIMITED, has accumulated 1+ million downloads
  • macOS targets: Separate trojanized installers for macOS systems
  • Multi-protocol C2: The same infrastructure (tracked via IPLogger URL fingerprinting) serves fake installers for multiple applications and operating systems

  • Note: It remains unclear whether mobile variants include the same residential proxy node functionality or serve a different purpose (data harvesting, credential theft, etc.).


    ### Infrastructure Fingerprinting


    Forensic analysis by Proxyway revealed troubling overlap between Lurking Lizard's fake SmartProxy network and Google's dismantled IPIDEA infrastructure:


  • 773,087 unique IP addresses attributed to SmartProxy appear in the IPIDEA dataset (16.2 million IPs)
  • This suggests either direct IP reselling or infrastructure inheritance following IPIDEA's takedown
  • The overlap indicates Lurking Lizard may have acquired or assumed control of portions of IPIDEA's botnet following Google's enforcement action

  • ## Implications


    ### Who Is at Risk?


  • Consumers downloading software: Users seeking legitimate utilities (7-Zip, VPN clients, media tools) are the primary target vector
  • Organizations with inadequate endpoint controls: Networks without robust application whitelisting or behavioral detection may harbor these trojans undetected
  • Enterprises relying on legitimate residential proxy services: Legitimate proxy business models are being delegitimized by criminal activity operating under their brands
  • Victims of upstream crimes: Devices recruited into the botnet become exit nodes for:
  • - Fraud schemes (account takeover, credential stuffing, click fraud)

    - Malware distribution

    - Spam and phishing campaigns

    - Botnets used for DDoS or ransomware delivery


    ### Business Impact


    The operation demonstrates a $M-scale criminal proxy-as-a-service (PaaS) business model comparable to established malware marketplaces. By lowering barriers to entry for attackers seeking residential IP pools, Lurking Lizard enables:


  • Wave-2 abuse: Criminals purchasing access can scale attacks without managing infrastructure
  • Attribution obfuscation: Attacks originating from residential proxies are harder to trace than datacenter IPs
  • Compliance violations: Organizations whose customers are victimized may face regulatory action for inadequate security posture

  • ## Recommendations


    ### For Endpoint Users


    1. Download only from official sources: Use direct downloads from vendor websites or official app stores, never from third-party sites or tutorial pages

    2. Verify domain spelling: Legitimate 7-Zip is at 7-zip.org, not 7zip.com

    3. Enable automatic updates: Keep OS, browsers, and security software current

    4. Use reputable VPN/proxy services: If proxy tools are needed, purchase from established vendors with transparency reports and security audits


    ### For Organizations


    1. Deploy application whitelisting: Restrict execution to known-good software; catch trojans masquerading as legitimate tools

    2. Monitor egress traffic: Watch for suspicious outbound connections to proxy C2 infrastructure or unusual data exfiltration

    3. Behavioral detection: Alert on processes attempting to establish persistence or modify network settings

    4. DNS filtering: Block known malicious domains and drop-caught lookalike domains

    5. Audit trusted vendors: Verify that software downloads and updates originate from legitimate sources (HTTPS with valid certs, signed binaries)


    ### For Security Researchers & Law Enforcement


    1. Coordinate on domain takedowns: Domain registrars should implement drop-catching detection to prevent abuse

    2. Track infrastructure evolution: Monitor for indicators of compromise (IoCs) from dismantled services like IPIDEA resurfacing under new branding

    3. Cross-border collaboration: Attribute and pursue China-based operators engaging in criminal proxy monetization

    4. ISP coordination: Residential proxy networks should implement abuse reporting mechanisms and rapid takedown procedures


    ---


    ## HackWire Analysis


    Lurking Lizard's operation exposes a critical blind spot in how we regulate residential proxy markets. Legitimate proxy services have become essential infrastructure for security researchers, privacy advocates, and businesses protecting against regional censorship—but the criminalization of proxies remains muddled. This campaign is a reminder that when legitimate services lack meaningful abuse reporting, law enforcement, and brand protection mechanisms, the criminal alternative becomes indistinguishable to the average user.


    The timing is particularly telling: Lurking Lizard expanded aggressively *after* Google dismantled IPIDEA infrastructure in January 2026. Rather than disrupting the ecosystem, takedowns appear to be shuffling players rather than eliminating demand. The 773,000+ IP overlap between fake SmartProxy and dismantled IPIDEA infrastructure suggests Lurking Lizard may have inherited portions of IPIDEA's botnet, a pattern we can expect to repeat as enforcement actions occur.


    Pattern recognition matters here. This is not a new attack—proxy trojans have existed for years—but the scale (773,000+ unique IPs), sophistication (multi-OS, mobile expansion), and brazen brand impersonation suggest a mature, well-funded criminal organization. The use of drop-caught domains to game search rankings and fake review sites mirrors malvertising tactics in affiliate fraud, indicating the same operational discipline.


    For defenders, the takeaway is uncomfortable: Residential proxies are now a commoditized attack vector, priced and distributed like exploit kits. Organizations can no longer assume users will avoid malicious downloads—the attack surface is deceptively simple (a trojanized file). Endpoint controls must assume device compromise is inevitable; network monitoring for proxy-like egress patterns becomes essential.


    The criminal proxy business model will persist as long as there's demand for IP spoofing. Law enforcement's best lever is supply-side intervention at domain registrars and hosting providers, combined with cross-border cooperation to pursue operators. Until that happens, users should treat any unsolicited proxy or VPN offer as potentially malicious.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)