← All stories
● Covered by 1 source · 1 reportHigh impact

Lurking Lizard Uses Fake 7-Zip Installers for Malicious Proxy Operations

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Lurking Lizard operates over 230 lookalike domains
  • Uses trojanized 7-Zip installers for recruitment
  • Impersonates major proxy services to drive traffic

Discovery of Lurking Lizard

Researchers revealed details about a new threat actor called Lurking Lizard, which has been conducting operations to build a malicious residential proxy business. This entity uses an extensive network of over 230 fake domains to launch its attacks and recruit compromised devices into its proxy network.

Malicious Proxy Infrastructure

The operation employs a strategy that dates back to at least August 2022, where users are misled into downloading trojanized versions of software like 7-Zip from misleading domains such as '7zip[.]com'. The compromised devices are then used as proxy nodes in its infrastructure.

Key Operational Tactics

Lurking Lizard mimics established proxy providers like IPIDEA and SmartProxy, further amplifying its credibility by manipulating search traffic through fake independent review sites. Analysis indicates a method known as drop-catching, allowing them to acquire expired domains for legitimacy.

Broader Implications

The use of 7-Zip installers is only part of a larger campaign; similar tactics have been noted with other applications like WhatsApp and TikTok downloaders. Investigations have traced this behavior back to a China-based actor using multiple apps and services to mask their true intentions.

Concluding Notes

The proliferation of these malicious proxy networks poses a significant threat to cybersecurity, as they remain undetected and relay illegal activities. Users are advised to download software only from verified sources and be cautious with unsolicited links.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Cybersecurity researchers identified Lurking Lizard, a malicious entity using fake 7-Zip installers to recruit devices into a residential proxy network. Operating since at least August 2022, it exploits expired domains and other major proxy providers to generate traffic and evade detection.