logo

Fake Installers, Fake Reviews, Fake Services – Real Proxies, Real Victims

ID: 1b468991-ec59-576f-80cf-e19125a73473

STIX ID: report--1b468991-ec59-576f-80cf-e19125a73473

Feed Name: Infoblox Threat Intel Blog

Threat Score
78/100

Date Published: 2026-07-07

Date Updated: 2026-07-16

Author: Infoblox Threat Intel

...
...

Lurking Lizard runs an end-to-end malicious residential proxy business that trojanizes installers and apps (e.g., fake 7-Zip, WireVPN variants) to recruit victim devices as proxy nodes, then monetizes access via lookalike proxy storefronts and review sites. The investigation links over 230 domains and multi-year activity through WHOIS patterns, shared APIs, an IPLogger beacon, consistent deployment fingerprints, and overlapping hosting, indicating a high-scale, persistent operation that repurposes compromised hosts as exit nodes rather than legitimate VPN endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.