Hero is Windows residential proxyware deployed through trojanized software installers distributed from a typosquatted imitation of the 7-Zip download site. The installer retains functional 7-Zip software while installing a Go-based proxy agent, a service/update-management component, and a supporting library. It persists as automatically started Windows services running under SYSTEM privileges and modifies Windows Firewall rules to permit its communications. Hero profiles infected systems for hardware, memory, processor, storage, and network information, then transmits host metadata externally. The proxy agent obtains configuration from rotating command-and-control infrastructure, uses DNS-over-HTTPS and encrypted web traffic, and establishes outbound proxy sessions over non-standard ports. Its primary purpose is to enroll compromised Windows systems as residential-proxy exit nodes, allowing third parties to route traffic through victims' IP addresses. The malware also incorporates virtualization and debugger checks, process and environment inspection, runtime API resolution, and encoded control communications to hinder analysis and detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
“Traffic analysis shows a lightweight XOR‑encoded protocol (key 0x70) used to obscure control messages.”
The operators behind 7zip[.]com distributed a trojanized installer via a lookalike domain, delivering a functional copy of 7‑Zip File Manager alongside a concealed malware payload.
The malware incorporates multiple layers of sandbox and analysis evasion: Process enumeration, registry probing, and environment inspection
“enumerates… network configuration… communicates with iplogger[.]org via a dedicated reporting endpoint”
The malware incorporates multiple layers of sandbox and analysis evasion: Process enumeration, registry probing, and environment inspection
Using WMI and native Windows APIs, the malware enumerates system characteristics including hardware identifiers, memory size, CPU count, disk attributes, and network configuration.
Traffic analysis shows a lightweight XOR-encoded protocol (key 0x70) used to obscure control messages.
The hero.exe component retrieves configuration data from rotating “smshero”-themed command-and-control domains, then establishes outbound proxy connections on non-standard ports such as 1000 and 1002.
“traffic routed through Cloudflare infrastructure with TLS‑encrypted HTTPS sessions.”
The malware also uses DNS-over-HTTPS via Google’s resolver, reducing visibility for traditional DNS monitoring and complicating network-based detection.
“The infected host is enrolled as a residential proxy node, allowing third parties to route traffic through the victim’s IP address.”
In their Reddit post, the user described installing the file first on a laptop and later transferring it via USB to a newly built desktop.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Основной Go-компонент троянизированного установщика 7-Zip. Собирает сведения о системе, получает конфигурацию с C2-инфраструктуры, использует обфусцированный XOR-трафик и превращает заражённый Windows-хост в выходной узел residential-proxy-сети.
Residential proxy malware delivered via a trojanized 7-Zip installer; persists via SYSTEM-level Windows services, modifies firewall rules via netsh, profiles the host, uses HTTPS C2 (often Cloudflare-fronted), XOR-obfuscates control messages (key 0x70), uses DNS-over-HTTPS, and opens outbound proxy connections on non-standard ports (e.g., 1000/1002) to relay third-party traffic through the victim IP.
Main proxy payload component used to turn infected hosts into residential proxy nodes. Retrieves configuration from rotating C2 domains, establishes proxy connections on non-standard ports (e.g., 1000/1002), and uses XOR-obfuscated control messaging; traffic is routed via Cloudflare and carried over TLS/HTTPS, with DNS-over-HTTPS to reduce defender visibility.
The primary Go-compiled payload delivered via the fake 7-Zip installer. It profiles the host, communicates with themed C2 domains over encrypted channels, uses XOR-obfuscated control traffic, persists as a Windows service, and converts infected systems into residential proxy nodes for third-party traffic routing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.