Uphero is Windows proxyware deployed through trojanized software installers impersonating legitimate applications, including 7-Zip. The installer preserves the advertised application’s normal functionality while covertly installing a service-management and update component, a Go-compiled proxy agent, and a supporting library. It establishes auto-start Windows services executing with SYSTEM privileges and modifies Windows Firewall rules to permit its communications. Uphero profiles infected systems for hardware, memory, processor, disk, and network characteristics, then reports host metadata externally. Its principal function is to enroll compromised devices as residential-proxy exit nodes, allowing third parties to relay traffic through victims’ IP addresses. The malware obtains configuration from rotating command-and-control infrastructure, uses encrypted web communications and DNS-over-HTTPS, and employs XOR-obfuscated proxy control messages. It includes anti-analysis measures including virtual-machine and debugger detection, process and environment inspection, and runtime API resolution. Related activity has used similarly structured trojanized installers masquerading as other popular consumer software.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The operators behind 7zip[.]com distributed a trojanized installer via a lookalike domain, delivering a functional copy of 7‑Zip File Manager alongside a concealed malware payload.
The malware incorporates multiple layers of sandbox and analysis evasion: Process enumeration, registry probing, and environment inspection
“enumerates… network configuration… communicates with iplogger[.]org via a dedicated reporting endpoint”
The malware incorporates multiple layers of sandbox and analysis evasion: Process enumeration, registry probing, and environment inspection
“the malware enumerates system characteristics including hardware identifiers, memory size, CPU count, disk attributes, and network configuration.”
“The infected host is enrolled as a residential proxy node, allowing third parties to route traffic through the victim’s IP address.”
“The infected host is enrolled as a residential proxy node, allowing third parties to route traffic through the victim’s IP address.”
In their Reddit post, the user described installing the file first on a laptop and later transferring it via USB to a newly built desktop.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Компонент менеджмента и обновления proxyware, устанавливаемый вместе с Hero в C:\Windows\SysWOW64\hero\. Закрепляется как автоматически запускаемый SYSTEM-служба и поддерживает обновление вредоносной нагрузки независимо от исходного установщика.
Installed as a Windows service with SYSTEM privileges for persistence; part of a fake 7-Zip installer bundle used to convert infected hosts into residential proxy nodes and maintain long-term access.
Dropped by trojanized software installers (e.g., fake 7-Zip). Installs as a Windows service (SYSTEM), modifies firewall rules, profiles the host via WMI/Windows APIs, and enrolls the victim as a residential proxy node. Uses rotating “smshero”-themed C2 domains, TLS-encrypted HTTPS, DNS-over-HTTPS (Google), and lightweight XOR-obfuscated control messages; includes anti-analysis checks for VMs/debuggers.
A trojanized component dropped by a fake 7-Zip installer that acts as a service manager and update loader, installs into SysWOW64, registers persistence as a Windows service under SYSTEM privileges, manipulates firewall rules, and supports a residential proxy monetization operation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.