logo

Malicious 7-Zip site distributes installer laced with proxy tool

ID: a813d990-4324-51d1-abe2-d98c6a963ce2

STIX ID: report--a813d990-4324-51d1-abe2-d98c6a963ce2

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-02-10

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A malicious campaign uses a fake 7-Zip website (7zip.com) to distribute a trojanized installer that includes the legitimate 7-Zip binary plus three malicious components (Uphero.exe, hero.exe, hero.dll). The malware installs to C:\Windows\SysWOW64\hero, creates a SYSTEM auto-start service, alters firewall rules, profiles hosts via WMI/APIs, and enrolls infected systems as residential proxy nodes communicating with rotating hero/smshero C2 domains over Cloudflare and DoH with XOR-obfuscated control messages; researchers (Malwarebytes and independent analysts) have published IOCs and detection/mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.