Lurking Lizard ecosystem shift changes threat-actor operations
Threat Actor Meta
Summary
Hide ▲
Show ▼
The Lurking Lizard operation has been exposed as a multi-stage residential proxy business, turning compromised devices into monetizable proxy nodes and widening unauthorized-traffic risk across home and enterprise networks. The ecosystem uses 230+ lookalike domains and impersonates brands such as IPIDEA, SmartProxy/Decodo, IP Royal, 911Proxy, and WireVPN to funnel users into scam storefronts. Its activity has been traced back to at least August 2022 and spans Android, macOS, and Windows.
Related Happenings
Popa botnet forcing consumer TV boxes to relay traffic
Malware Activity
H score76
First: 18.06.2026 20:37
Last: 18.06.2026 20:37
Sources 1
About this happening:
Popa is an Android botnet that forces consumer TV boxes and related devices into relay infrastructure, maintaining encrypted connectivity and opening tunnels on demand...
Popa botnet forcing consumer TV boxes to relay traffic
Malware ActivityAbout this happening: Popa is an Android botnet that forces consumer TV boxes and related devices into relay infrastructure, maintaining encrypted connectivity and opening tunnels on demand...
Latest development: 03.07.2026 12:35
Google disabled NetNut accounts used for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing compromised SDKs while FBI legal actions and domain seizures targeted NetNut infrastructure. The coordinated disruption was described as degrading NetNut’s proxy network and shrinking the pool of devices available to the operator.
Residential proxy traffic evades IP reputation feeds across malicious edge sessions
Trend
H score30
First: 02.04.2026 18:21
Last: 02.04.2026 18:21
Sources 1
About this happening:
Residential proxies are increasingly treated as a carding identity-simulation stack, not a standalone anonymity tool, with actors combining them with device fingerprints...
Residential proxy traffic evades IP reputation feeds across malicious edge sessions
TrendAbout this happening: Residential proxies are increasingly treated as a carding identity-simulation stack, not a standalone anonymity tool, with actors combining them with device fingerprints...
Timeline
-
09.07.2026 07:01 1 articles · 13d ago
Lurking Lizard residential proxy business uses 230+ lookalike domains
Initial DisclosureCybersecurity researchers disclosed a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using more than 230 lookalike domains, trojanized 7-Zip installers on 7zip[.]com, and impersonation of proxy brands including IPIDEA, SmartProxy (now Decodo), IP Royal, and 911Proxy. Infoblox said the activity dates back to at least August 2022, and the same infrastructure also used fake review sites and other lures to recruit compromised devices as proxy nodes.
Show sources
- Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes — thehackernews.com — 09.07.2026 07:01