Lurking Lizard trojanized 7-Zip installer campaign
Campaign
Summary
Hide ▲
Show ▼
A Lurking Lizard campaign used a trojanized 7-Zip installer to recruit devices as proxy nodes, expanding a residential-proxy operation that has run since at least August 2022. The lure exposed users on Android, macOS, and Windows to proxy malware and funneled compromised systems into the actor’s infrastructure. The same operation also used lookalike domains and fake review sites to direct traffic toward its storefronts.
Related Happenings
Popa botnet forcing consumer TV boxes to relay traffic
Malware Activity
H score76
First: 18.06.2026 20:37
Last: 18.06.2026 20:37
Sources 1
About this happening:
Popa is an Android botnet that forces consumer TV boxes and related devices into relay infrastructure, maintaining encrypted connectivity and opening tunnels on demand...
Popa botnet forcing consumer TV boxes to relay traffic
Malware ActivityAbout this happening: Popa is an Android botnet that forces consumer TV boxes and related devices into relay infrastructure, maintaining encrypted connectivity and opening tunnels on demand...
Latest development: 03.07.2026 12:35
Google disabled NetNut accounts used for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing compromised SDKs while FBI legal actions and domain seizures targeted NetNut infrastructure. The coordinated disruption was described as degrading NetNut’s proxy network and shrinking the pool of devices available to the operator.
TA4922 expanded European phishing-and-malware campaign
Campaign
H score40
First: 04.06.2026 00:45
Last: 04.06.2026 00:45
Sources 1
About this happening:
TA4922 is a China-linked cybercrime campaign that has expanded from East Asia into Europe and Africa, including the U.K., Germany, Italy, and South Africa. The...
TA4922 expanded European phishing-and-malware campaign
CampaignAbout this happening: TA4922 is a China-linked cybercrime campaign that has expanded from East Asia into Europe and Africa, including the U.K., Germany, Italy, and South Africa. The...
Residential proxy traffic evades IP reputation feeds across malicious edge sessions
Trend
H score30
First: 02.04.2026 18:21
Last: 02.04.2026 18:21
Sources 1
About this happening:
Residential proxies are increasingly treated as a carding identity-simulation stack, not a standalone anonymity tool, with actors combining them with device fingerprints...
Residential proxy traffic evades IP reputation feeds across malicious edge sessions
TrendAbout this happening: Residential proxies are increasingly treated as a carding identity-simulation stack, not a standalone anonymity tool, with actors combining them with device fingerprints...
SmartLoader trojanized Oura MCP Server delivery of StealC
Malware Activity
H score4
First: 17.02.2026 14:42
Last: 17.02.2026 14:42
Sources 1
About this happening:
SmartLoader is part of an ongoing FakeGit malware activity that used malicious GitHub repositories to deliver SmartLoader and then StealC. Island said it f...
SmartLoader trojanized Oura MCP Server delivery of StealC
Malware ActivityAbout this happening: SmartLoader is part of an ongoing FakeGit malware activity that used malicious GitHub repositories to deliver SmartLoader and then StealC. Island said it f...
Timeline
-
09.07.2026 07:01 1 articles · 13d ago
Lurking Lizard residential proxy operation uses trojanized 7-Zip installers
Initial DisclosureCybersecurity researchers disclosed a Lurking Lizard residential proxy operation that has run since at least August 2022, using more than 230 lookalike domains and trojanized 7-Zip installers on 7zip[.]com to recruit compromised devices as proxy nodes. The same infrastructure also impersonates IPIDEA, SmartProxy (now Decodo), IP Royal, 911Proxy, and WireVPN, and uses fake review sites and wrong-domain lookalikes to drive traffic to scam storefronts.
Show sources
- Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes — thehackernews.com — 09.07.2026 07:01