Researchers said the Lurking Lizard operation has used trojanized software, lookalike domains, fake review sites, and impersonated proxy brands since at least 2022 to turn victim devices into residential proxy nodes. One prominent lure was a counterfeit 7-Zip installer hosted on 7zip[.]com, but investigators also tied the activity to fake installers for WhatsApp, TikTok, YouTube downloader tools, and other software through shared WHOIS records, DNS pivots, backend infrastructure, and a hardcoded IPLogger URL. The campaign is linked to more than 230 domains and appears to run a full proxy business that infects victims and then resells their bandwidth and IP addresses.
The operation later expanded under the WireVPN brand across Windows, macOS, Android, and iOS, including mobile apps distributed through Google Play and the Apple App Store; one Android app reportedly surpassed 1 million downloads. Testing found the software behaved more like proxyware or an exit-node client than a legitimate VPN, contacting numerous unrelated IP addresses and opening many simultaneous connections, while valid code-signing certificates helped it appear trustworthy. Researchers assessed the actor is likely China-based, citing registration data and related artifacts, and warned that the infrastructure supports both victim acquisition and the marketing and sale of fraudulent proxy services.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The activity later evolved into a WireVPN-branded offering distributed across Windows, macOS, Android, iOS, Google Play, and the Apple App Store. Reports said the Android app had more than 1 million downloads and testing showed behavior more consistent with proxy exit-node abuse than a legitimate VPN.
An early-2026 campaign used a trojanized 7-Zip installer hosted on 7zip[.]com to infect users and enroll their devices into the proxy network. Investigators later linked this lure to the broader Lurking Lizard ecosystem through shared infrastructure and tracking artifacts.
Researchers said the Lurking Lizard operation has been active since at least August 2022, using trojanized installers, lookalike domains, and fake brands to turn victim devices into residential proxy nodes and monetize their bandwidth.
Infoblox disclosed a report detailing the Lurking Lizard operation, linking more than 230 domains, fake installers, fake review sites, and impersonated proxy services to a single end-to-end malicious residential proxy business. The report also assessed the actor as likely China-based based on registration and infrastructure artifacts.
A Japanese SOC reported that in January 2026 the unofficial 7zip[.]com site pointed Windows x64 and x86 downloads to a suspicious installer that dropped files into C:\Windows\SysWOW64\hero and registered hero.exe as a SYSTEM-starting Helper Service. The malicious download links were reportedly changed back to the official 7-zip.org site on 2026-01-26.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethehackernews.com
Open sourcecyberveille.ch
Open sourcecryptika.com
Open sourceinfoblox.com
Open sourceqiita.com
Open sourcewizsafe.iij.ad.jp
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.