Executive Summary
In early 2026, cybersecurity researchers uncovered a campaign by the threat actor 'Lurking Lizard,' which distributed trojanized 7-Zip installers via the domain '7zip[.]com.' These malicious installers covertly transformed compromised devices into nodes within a residential proxy network, allowing attackers to route illicit traffic through unsuspecting users' IP addresses. The operation, dating back to at least August 2022, involved over 230 lookalike domains and impersonated major proxy providers to expand its reach.
This incident highlights the growing trend of cybercriminals exploiting legitimate software and services to build extensive proxy networks, complicating detection and mitigation efforts. The use of residential proxies enables threat actors to mask their activities, posing significant challenges for cybersecurity defenses and emphasizing the need for heightened vigilance against such deceptive tactics. (fbi.gov)
Why This Matters Now
The Lurking Lizard campaign underscores the urgent need for organizations and individuals to scrutinize software sources and remain vigilant against deceptive tactics that compromise devices for malicious proxy networks. As cybercriminals increasingly exploit legitimate-looking software to build extensive proxy infrastructures, the risk of undetected malicious activities escalates, necessitating enhanced cybersecurity measures and awareness. (fbi.gov)
Attack Path Analysis
The Lurking Lizard threat actor initiated the attack by distributing trojanized 7-Zip installers through lookalike domains, leading to the installation of proxy malware on victims' devices. Upon execution, the malware established persistence and potentially escalated privileges to maintain control. The compromised devices were then integrated into a residential proxy network, allowing the attacker to route malicious traffic through them. The malware maintained communication with command and control servers to receive instructions and updates. While specific data exfiltration activities are not detailed, the proxy functionality suggests potential misuse of victims' network resources. The overall impact included unauthorized use of victims' devices and networks, potentially implicating them in malicious activities.
Kill Chain Progression
Initial Compromise
Description
Lurking Lizard distributed trojanized 7-Zip installers via lookalike domains, leading to malware installation on victims' devices.
MITRE ATT&CK® Techniques
External Proxy
System Binary Proxy Execution
Masquerading
Application Layer Protocol
User Execution: Malicious File
Phishing: Spearphishing Attachment
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – User Authentication and Authorization
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Fake 7-Zip installers creating residential proxy botnets threaten software distribution integrity, requiring enhanced egress security and zero trust segmentation for development environments.
Telecommunications
Residential proxy networks compromise telecom infrastructure through encrypted traffic manipulation, demanding multicloud visibility controls and east-west traffic security across service provider networks.
Financial Services
Malicious proxy botnets enable data exfiltration bypassing traditional perimeters, necessitating threat detection capabilities and compliance with PCI/HIPAA encryption requirements for customer protection.
Internet
End-to-end residential proxy operations using 230+ lookalike domains exploit internet infrastructure, requiring cloud firewall controls and anomaly detection for service provider protection.
Sources
- Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodeshttps://thehackernews.com/2026/07/fake-7-zip-installers-turn-devices-into.htmlVerified
- Fake 7-Zip downloads are turning home PCs into proxy nodeshttps://www.malwarebytes.com/blog/threat-intel/2026/02/fake-7-zip-downloads-are-turning-home-pcs-into-proxy-nodesVerified
- Fake 7-Zip download infects PCs with proxy-building malwarehttps://www.windowscentral.com/microsoft/windows/downloaded-7-zip-from-the-wrong-site-that-installer-mightve-turned-your-pc-into-a-proxy-botVerified
- Fake 7-Zip website distributes trojanized installer, turns PCs into proxy nodeshttps://www.scworld.com/brief/fake-7-zip-website-distributes-trojanized-installer-turns-pcs-into-proxy-nodesVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to exploit compromised devices for unauthorized network activities, thereby reducing the potential blast radius.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to establish unauthorized communications would likely be constrained, reducing the scope of initial compromise.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be constrained, reducing the scope of control over compromised devices.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally would likely be constrained, reducing the potential for further compromise.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to maintain command and control would likely be constrained, reducing the effectiveness of remote instructions.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate data would likely be constrained, reducing the misuse of network resources.
The attacker's ability to misuse compromised devices would likely be constrained, reducing the potential for malicious activities.
Impact at a Glance
Affected Business Functions
- Internet Connectivity
- Network Security
- System Performance
Estimated downtime: 7 days
Estimated loss: $5,000
Potential exposure of personal data due to unauthorized proxy usage.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict unauthorized communications and limit malware propagation.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to unusual activities indicative of compromise.
- • Ensure Encrypted Traffic (HPE) to protect data in transit and prevent interception by malicious actors.
- • Maintain Multicloud Visibility & Control to oversee and manage security policies across diverse cloud environments.



