CyberWire Intel Briefing
CyberWire Intel Briefing

Sep 19, 2026 · 30 min

Lurking Lizard turns fake installers into proxy infrastructure

All about that proxy. [Research Saturday]

The investigation shows how one operation can recruit victims, control residential proxy nodes, and monetize stolen bandwidth through a connected campaign ecosystem.

3 key takeaways
  1. 1Fake installers, lookalike domains, and reviews helped Lurking Lizard turn compromised devices into residential proxy nodes.
  2. 2DNS research and an embedded IP logger connected more than 230 domains and multiple campaigns to shared infrastructure.
  3. 3The operation stands out for controlling nearly every stage, from victim acquisition and malware delivery to proxy-service monetization.

Don't miss

Burton explains how researchers connected the fake 7-Zip and WireVPN campaigns through an embedded IP logger and shared infrastructure.

The brief

Renée Burton discusses Infoblox research into Lurking Lizard, whose fake installers, reviews, VPNs, and lookalike domains recruit devices into residential proxy networks.

Residential proxies can support legitimate web access and scraping, but compromised residential IP addresses also enable credential stuffing and other abuse.

DNS research and an IP logger embedded in the malware linked the fake 7-Zip campaign to WireVPN and more than 230 domains sharing infrastructure.

The unusual finding is operational breadth: one actor appears to attract victims, control proxy infrastructure, and market access to stolen bandwidth as an integrated business.

Burton’s defensive advice is practical: use trusted download sources, watch for typo domains, and treat common utilities as potential attack surfaces.

Listen to the full episode and explore every guest, topic, and moment on PodLume.