Fake Installers, Fake Reviews, Fake Services – Real Proxies, Real Victims
ID: 1b468991-ec59-576f-80cf-e19125a73473
STIX ID: report--1b468991-ec59-576f-80cf-e19125a73473
Feed Name: Infoblox Threat Intel Blog
Lurking Lizard runs an end-to-end malicious residential proxy business that trojanizes installers and apps (e.g., fake 7-Zip, WireVPN variants) to recruit victim devices as proxy nodes, then monetizes access via lookalike proxy storefronts and review sites. The investigation links over 230 domains and multi-year activity through WHOIS patterns, shared APIs, an IPLogger beacon, consistent deployment fingerprints, and overlapping hosting, indicating a high-scale, persistent operation that repurposes compromised hosts as exit nodes rather than legitimate VPN endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
