
Sep 19, 2026 · 30 min
Lurking Lizard turns fake installers into proxy infrastructure
All about that proxy. [Research Saturday]
The investigation shows how one operation can recruit victims, control residential proxy nodes, and monetize stolen bandwidth through a connected campaign ecosystem.
- 1Fake installers, lookalike domains, and reviews helped Lurking Lizard turn compromised devices into residential proxy nodes.
- 2DNS research and an embedded IP logger connected more than 230 domains and multiple campaigns to shared infrastructure.
- 3The operation stands out for controlling nearly every stage, from victim acquisition and malware delivery to proxy-service monetization.
Don't miss
Burton explains how researchers connected the fake 7-Zip and WireVPN campaigns through an embedded IP logger and shared infrastructure.
The brief
Renée Burton discusses Infoblox research into Lurking Lizard, whose fake installers, reviews, VPNs, and lookalike domains recruit devices into residential proxy networks.
Residential proxies can support legitimate web access and scraping, but compromised residential IP addresses also enable credential stuffing and other abuse.
DNS research and an IP logger embedded in the malware linked the fake 7-Zip campaign to WireVPN and more than 230 domains sharing infrastructure.
The unusual finding is operational breadth: one actor appears to attract victims, control proxy infrastructure, and market access to stolen bandwidth as an integrated business.
Burton’s defensive advice is practical: use trusted download sources, watch for typo domains, and treat common utilities as potential attack surfaces.