Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Intern arrested on espionage charges at NATO headquarters

    July 26, 2026

    France wildfire forces 220,000 evacuations as flames near Bordeaux

    July 26, 2026

    Wildfires spread in Western Canada as temperatures rise, lightning strikes

    July 26, 2026
    Facebook X (Twitter) Instagram
    Riyadh Week
    • Home
    • KSA
    • Business
    • Technology
    • Sports
    • Lifestyle
    Facebook X (Twitter) Instagram YouTube
    Riyadh Week
    Home»Technology»How fake 7-Zip software exposed a much bigger criminal proxy business
    Technology

    How fake 7-Zip software exposed a much bigger criminal proxy business

    Editorial TeamBy Editorial TeamJuly 18, 2026
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    Dr. Renée Burton, VP of Infoblox Threat Intel.

    Residential proxies are one of cybersecurity’s hottest topics, but many are not residential at all. Infoblox Threat Intel researchers traced what initially appeared to be an isolated malware campaign to a broader operation dating back several years.

    The actor, tracked as Lurking Lizard, is linked to more than 230 domains used to infect victim devices, operate proxy infrastructure, impersonate known proxy providers and market related services.

    Lurking Lizard appears to be a Chinese actor who affiliates with other proxy providers to resell access to bandwidth from compromised residential proxies. External researchers previously identified overlap between infrastructure connected to Lurking Lizard and IPIDEA, a major proxy provider that was disrupted earlier this year by a coordinated industry and law enforcement action. While there have been multiple disruptions of proxy providers this year, the ability for threat actors like Lurking Lizard to continue operating the botnet devices demonstrates how hard it remains to dismantle the malicious residential proxy market.

    The operation is vertically integrated, controlling several stages of acquisition, promotion and monetization. It builds new proxy nodes by distributing malware through lookalike domains tied to major software brands, then boosts those lures through search poisoning and online ads. One such campaign, impersonating 7-Zip, drew attention earlier this year, but this was only one visible piece of a much larger system. Infoblox Threat Intel also found that the actor sold access through lookalike domains posing as other commercial proxy services. By connecting those domains, the researchers were able to map the wider scope of the activity.

    “What matters here is not one fake installer, but the business model behind it”, said Dr. Renée Burton, VP of Infoblox Threat Intel. “When criminal services can scale by borrowing trust from consumer software, app stores and review sites, the risk moves beyond the security team. It becomes an operations, fraud and brand issue for every company online”.

    You can read the full research here.

    Image Credit: Infoblox


    Source: Tahawul Tech

    Related Posts

    32 Emirati experts participate in NEP-AI Module 1 ‘AI Foundations and AI Stack’

    July 25, 2026

    UNODA and GCF partner to implement Delegate Training Program supporting UN Global Mechanism on ICT Security 

    July 25, 2026

    BITS Pilani Dubai Campus powers UAE’s evolving research and innovation ecosystem

    July 24, 2026
    Top Posts

    Intern arrested on espionage charges at NATO headquarters

    July 26, 2026

    QBS Software Middle East embeds AI into core operations

    April 1, 2026

    Bosnia’s Barbarez cool as ice after reaching World Cup in shootout with Italy

    April 1, 2026

    Kuwaiti tanker hit by Iranian drone attack in Dubai waters

    April 1, 2026
    Don't Miss

    Intern arrested on espionage charges at NATO headquarters

    By Editorial TeamJuly 26, 2026

    BRUSSELS — Belgian authorities have arrested a Canadian intern working at NATO’s military headquarters on…

    France wildfire forces 220,000 evacuations as flames near Bordeaux

    July 26, 2026

    Wildfires spread in Western Canada as temperatures rise, lightning strikes

    July 26, 2026

    US, Russian crew returns to Earth after 8-month ISS mission

    July 26, 2026
    • KSA
    • Business
    • Technology
    • Lifestyle
    • Sports
    • Contact us
    2026. All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.