CyberWire Daily - All about that proxy. [Research Saturday]
Episode Date: September 19, 2026Today we are joined by Dr. Renée Burton, VP of Threat Intelligence at Infoblox, discussing their work on Lurking Lizard, "Fake Installers, Fake Reviews, Fake Services – Real Proxies, Real." The res...earch uncovers Lurking Lizard, a threat actor that has operated since at least 2022 by using fake software installers, VPNs, and lookalike domains to secretly turn victims’ devices into residential proxy nodes. Researchers identified more than 230 related domains and connected seemingly separate campaigns—including fake 7-Zip, downloader tools, and WireVPN—through shared infrastructure, tracking URLs, deployment patterns, and APIs. The investigation suggests the actor runs an end-to-end proxy operation, recruiting compromised devices and then monetizing their bandwidth through proxy services and fake review sites, with WireVPN appearing to be the latest evolution of the campaign. The research and executive brief can be found here: Fake Installers, Fake Reviews, Fake Services - Real Proxies, Real Victims
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
So what happens when an AI agent isn't malicious, but still does something it shouldn't?
I recently sat down with Cal Al-Dubabe, principal technologist at Rubrik, to talk about why agentic AI is challenging the way security teams think about detection, permissions, and recovery.
If your organization is deploying AI agents, this conversation will help you think differently about where the
risks are and how to prepare when things go wrong. Listen to our full conversation at explore.
thecyberwire.com slash rubric. Social engineering attacks look trustworthy, a routine request,
an internal email, a familiar face on a call, but Dopple sees through the disguise.
Their AI-native platform detects and disrupts attacks across every channel, trains employees to
recognize deepfakes and deception and investigates every fish to take down the campaign behind it.
They fight relentlessly to protect your business, brand, and people.
Dopple, outpacing what's next in social engineering.
Learn more at doppel.com. That's do p-p-p-el.com.
Hello everyone and welcome to the CyberWire's Research Saturday.
I'm Dave Bittner, and this is our weekly conversation with researchers and analysts
tracking down the threats and vulnerabilities,
solving some of the hard problems
and protecting ourselves
in a rapidly evolving cyberspace.
Thanks for joining us.
So we've been talking a lot this year
about residential proxies.
And when we were looking at some of the threats related to that,
we saw what appeared to be infrastructure shared
by a bunch of lookalikes to residential proxies themselves.
That's Dr. Renner.
Burtain, VP of threat intelligence at InfoBlocks.
The research we're discussing today is titled fake installers, fake reviews, fake services, real proxies, real victims.
And then at the same time, almost simultaneously within a week or so of each other,
there was an article about 7-Zip malware, which turned out to be what they call proxyware.
So its main function was to join residential proxy.
and that it was using a lookalike domain called 7Zip.com.
And it was showing up in people's searches.
There was a YouTube video that recommended people go to 7Zip.com and download it.
And in fact, it was this residential proxy malware.
And we went to look at that and they were the same infrastructure.
So it was like, this is crazy town, right?
Like how do we have this many domains that,
are really clear lookalikes to major tech things like Seven-Zip,
and there were a handful of others,
as well as the well-known proxy services that are out there selling things.
And that was where we're like, okay, now we have to dig in
and see whether our algorithms are wrong.
Like, do these things not really belong together?
Or if they do belong together, wow, this is weird.
Yeah.
Well, just for clarity, what does the real 7Zip do?
Yeah, so the real 7Zip is 7Zip.org, and it's open source,
open source is the right word, but it's a well-known archiver.
And so people were looking at it as a way, you know, it's a compression thing.
People talk about zipping files up or I send you a compressed file.
So 7-Zip is the compressor utility.
Yeah.
Yeah.
And I guess it is open source.
I just checked myself.
I think it's open source, you know,
in the sexuality.
So the research describes pulling on the DNS thread.
Can you unpack that for us?
Why was that an important aspect of this?
Yeah, for us, that really was the piece that brought these things together.
So we ended up seeing other researchers reporting in isolated ways on
this actor, they didn't have the full, you know, the full scope of it because they're not
seeing that DNS aspect of it. But so for instance, there was the 7 Zip reporting, which,
which was done that was really great about the proxyware. And then there is a lookalike to a proxy
service called Smart Proxy that was also reported about and how that was really a fake front.
So when we're looking at it, when I say pulling on the DNS thread, what we try to do is figure out what is, we try to figure out what domains are owned by the same actor.
And we do that in a bunch of different ways.
And we look at IP addresses.
We look at registrations.
We look at timing of events.
We look at like combinations of names, all this kind of stuff.
And in this particular set, so then we have like buckets.
And when we go to look at, say, 7Zip.com, we will also see, in our own tooling, we'll see, I think these things, you know, it's kind of like your Amazon, I think these things also belong to this actor.
And what it showed us was, you know, I think smartproxy.org, again, the fake site, is the same actor as 7Zip.com.
And that was like, well, that's crazy, because those two things really are kind of the same and different.
they're both proxy stuff, but they're different, right, at the same time.
So that's when we're saying the DNS thread, that's really what we're talking about.
This infrastructure appears to be the same actor.
And am I right here that one suspicious domain eventually became over 200 related domains?
Exactly, yeah.
So if you take that 7Zip.com, that was the initial one from this particular one.
There are several, yeah, several hundred.
I don't know the exact number now.
they're still alive and they keep registering stuff.
Yeah.
Well, help me understand the business model here.
One of the interesting ideas in the report is that this actor isn't just distributing malware.
They're operating what you all describe as an end-to-end proxy business.
What exactly does that mean?
As far as we can tell, so if you think about amortizing your risk from a business portfolio
perspective, you're going to have these isolated businesses.
and at the same time, you want to be able to drive traffic.
So in the residential proxy world, that means I need to have nodes.
I need to have devices that are willing to have traffic run through them,
whether they're consenting or not.
So they're an Android TV.
They may or may or may not even know that they bought this TV,
they turned it on, and now it's been registered as part of a residential proxy.
So you need some way to get access to those nodes.
And there's only kind of a couple of ways of doing that, right?
Either you are already preloaded as they have been in some of these TVs.
There was reporting on LG in particular, I think in the last week or so.
Or you've convinced someone to download the software onto their TV or their phone or whichever it is or laptop,
which serves the same purpose.
So one way or another, you've got to get software down somewhere on a device,
preferably in a residence, that is going to be willing to be a transmitting
for people who are buying proxy stuff.
So that's one part of their business.
And for them, they may do it in multiple ways,
but the one way we know that they do it right now is that they do malware.
So they do this fake seven-zipped utility.
And we saw signs of them doing other types of utilities as well.
They do these VPN apps.
So the one we saw most recently was branded wire VPN.
The world of apps is complicated.
You can have things that are named very similar to each other,
and they may or may not be related.
But the one right now that we saw that is definitely the same as 7.com,
7ZIP.com, was branded wire VPN,
and there's lots of those like that.
So that's your, like, access part of your business.
The VPNs is probably the single, I don't know if it's, well, outside of TVs, which is single biggest, but it's a really big avenue for residential proxies because basically people want to get access to free streaming TV or other illegal things they're not supposed to do.
So they downloaded this, quote, VPN, and it's really a residential proxy service.
So that's the
I guess you'd call that the supply type, right?
That's the get the nodes side.
And then the other,
they'd really have three pillars,
but another major pillar is
if I'm a residential proxy service,
I want to sell access now
to those nodes that I've acquired.
So if we take any one of the major,
you know, there's lots of big companies
in this world.
So IPIDA,
was one that was actioned. Chinese one actioned by Google and law enforcement. Net nut proxy is another
one recently action by law enforcement. Those guys are selling access to these proxy notes. So they're
selling access to the software, wherever it is on these devices. And Lurking Lizard was also doing that.
The difference between them and say NetNut in an IPA idea is that they're selling access.
again through lookalike domains
that are faking
the other proxy providers
so it's kind of wild
there isn't a real smart proxy
and yet these guys have
a domain called smart proxy
and they sell access
through this fake version
kind of wild
so just to back up for a second
just to make sure that I'm
completely clear here. I mean, when I hear the term residential proxy, I guess the first thing that
comes to mind for me is someone's home computer. You know, you mentioned TVs, and the report suggests
that it's not always people's home computers. Can you give us a quick rundown of the basics here?
What are we talking about when we say residential proxy? Yeah, I think that it's a term that made
sense at the time, and it's certainly not my, you know, Resonist property is not my area of
expertise, so I always end up deferring to them. But we kind of think about it as something that's
happening in residences. And the reason for it is the reason residential IP addresses, so people
like your house or my house are useful, is because more often you can get access to content that way,
whether that be like you're going to do, you're a big web scraper. If you're using residential IPs,
rather than coming out of, say, Amazon,
you're more likely to not be blocked and get access.
Or, like, we use residential proxies as a security company
to be able to access bad stuff
that the threat actors will try to prevent us from accessing.
So the concept is I'm routing traffic
through someone else's IP address
in order to cover, essentially, for my activities.
Someone will object to my use of the word cover,
but you're routing so that it looks like it's someone else.
We'll be right back.
And there are legit residential proxy markets that are on the up and up?
Sure, yeah.
I mean, a lot of us use them for sure.
I think almost, I don't know, any security company who doesn't use them.
Every AI company is using them.
That's how they're gaining access.
Again, someone's going to argue with broad brush strokes,
but the way you do web scraping,
you know,
the way you do web scraping
is through these kinds of,
these kinds of things
because they're not going to let you scrape
out of,
you know,
Amazon.
And criminals use it in a huge way
to do things like credential stuffing.
And then the misnomer is that
they're called residential proxies,
but they're definitely not all residences.
You know,
we see them in like 65% of our enterprise customers.
And that's because,
in a large part, people have their phones inside of their workplace now, their laptop moves between
their home and their workplace, and then the Android TV box problem, which has really blown up
the residential proxy space. Every enterprise has TVs. They're everywhere. Yeah. Let's continue
down the pathway of the investigation here. I mean, there were some interesting clues along the way
one that caught my eye, there was an IPLogger URL that was embedded in the malware.
That was an important clue, wasn't it?
Oh, yeah.
That IP logger, and there are various, there's multiple companies who do this type of service.
It's one of my absolute favorite techniques for tracking threat actors.
So these are free services.
And so you go on to IPLogger.com and you say, I want to track, you know,
visitors, I'm tracking website visitors, to my site. And then as a result of that, you're given a
unique code that is, you know, essentially now an IPlogger.com URL that's unique to you,
just like the Bitley link, right? Like it's a bitly would be a short link and it's not how
it operates exactly, but it's very, very similar. I went on, I got a free link, now I have a
shortened link. I put that shortened link or the IPLogger link in my website and then when someone
visits it, it hits that endpoint, and it gives the visitor's IP address over to me,
and it logs it. These service, I created an account, and now I can see who my IP,
who the IP of my visitors are. And criminals use these to, to determine what they're going to do
with traffic, like for a funneling purpose, whether they're going to give them the real bad traffic
or whether they're going to give them a decoy. So, and then other people use it for, like,
deciding on what service they're going to give them,
depending on the geo of, you know,
whether it's legal there or what kind of,
what kind of service they're going to do.
So that's what this malware,
this proxy, they call, you know, proxyware,
but it's really malware.
Let's be real here.
It's just a different,
it's a special kind of malware.
That's what it had in it, right?
It had this special URL,
and it's literally just like a Bentley link, right?
So it, because everyone's familiar with Bitley,
that link is unique.
That link goes to a specific URL and it doesn't go anywhere else.
It belongs to whoever set it up.
So what happened in this case was that exact link was in multiple applications that the researchers found in the research, which allows you to track, you know, for whatever reason, it didn't happen at random.
Somebody who owns this link had it put in all of these different applications.
or it's a really big conspiracy theory.
Right.
Somebody coincidentally put your link into their malware.
Well, the report talks about how things evolve.
And the fake 7-Zip campaign turns into this wire VPN thing.
What happened there?
Yeah, it seems like these actors over time have used, I forget what some of the other utilities,
but they've used other utilities besides seven zip in the past.
And just like normal actors, they have campaigns, so they had a seven zip campaign.
And the campaign when we were writing was a wire VPN app, which was available on the Apple store and the Play Store.
And again, it's, you know, it's branded that way.
So the question is, what is it exactly?
Well, it's branded this way with a wire VPN.
And that particular code, we had multiple samples of that code that we were able to acquire,
which matched all the branding, also had this exact same IPlogger.
Dot co link inside of it.
There were some other aspects of it that were the same as well, but that was definitely a link
between those two things.
And then maybe they would move on to something else, right?
It could be a different VPN name.
could be a different utility that you're going to mock.
The report talks about more than a million Android downloads,
but also noted you couldn't independently verify those numbers.
Regardless of the exact count,
what does it tell you about the potential reach of this ecosystem?
Oh, yeah, it's very large.
They're obviously super clever.
These lookalikes are really, really good lookalikes.
And so they're able to, you know, be able to get traffic just through natural things.
Like one of the things with the 7Zip that was so interesting is that there was organic traffic because people make typos.
So there, I can't remember.
I think it was Reddit, right?
But there were just organic threads over time where human beings had typed 7Zip.com instead of 7Zip.org,
which then allows this sort of organic thing to happen.
And when I'm doing a search for 7Zip, then I got this Reddit thread, and it says to go here.
And so I go there and I get the malware in that way.
And the same thing happens in this VPN environment, which there are lots of copies of these different types of residential VPNs.
Lots of people want access to free streaming, to illegal gambling, to all kinds of illegal activity or free.
I want access to the World Cup.
And as a result of that, I download an app like this one that was called YRVPN.
And that's why you see a million, you know, we can't independently verify it,
but it is what the Google Play Store says.
So do you mean that Google is correct?
One of the things that struck me reading through the research is that this actor seems
to control nearly every stage of the operation, from attracting the victims to marketing the
proxy services. How unusual is that? I've never seen that before. I've definitely never seen.
What we do see in the, particularly in the ad tech sort of traffic distribution system world,
particularly coming out in Eastern Europe, they'll call it the arbitrage. Traffic arbitrage world
is another word that they use for it. Now, they have a established way in which you grow your business.
And it's not a secret. I mean, they,
they publish the advice on it. So you start as an arbitrage team. And then as you grow,
the main thing you want to do is build out separate, isolated businesses, which basically amortizes
risk against you in case someone, you know, law enforcement or someone else interrupts part of your
business. The rest of your businesses can continue to operate. You get legal teams. You make
yourself to be a real commercial entity. Those are all things that are advised in that world,
in that kind of traffic arbitrage ad tech world of Eastern Europe.
And these guys are Chinese actors,
but it is a very similar concept that they seem to be doing, right?
They're acquiring traffic through the malware distribution,
through the search engine, they're buying these domains,
and then separate of that, they're selling access to those traffic.
And we never found a real proxy review site.
We couldn't find one that actually worked,
but they have a ton of domains more than 20
that were things like best proxies ever, right?
Dot work, a typical kind of review site sort of things.
So it sure seems like that kind of model.
And I've never seen that.
Again, we see it all the time in that Eastern European Arbitrarch world.
That is a standard model.
But I have never seen it outside of that model.
And, you know, certainly not in the residential proxy world.
Yeah.
What are your recommendations for defenders here?
What are the takeaway lessons?
There's a couple, right? So one is really being aware that these typos, these typos can persist in a lot of ways that we don't even think about, right? And not only in an accidental way, but, you know, if they're actually selling ads and trying to sell traffic, really need to make sure that when you go to download some sort of utility like 7 Zip or all the other ones that we would want to get access to, like we might want, we might want, we want, we want, we want,
WireShark, right, in the cyber world.
Make sure that we're getting it from the right location.
And then putting in policies, putting in policies within your enterprise and enforcing them of not allowing free VPNs, for example.
Like all of that stuff is residential proxies.
And it means that those devices are utilizing, from an enterprise perspective, utilizing the enterprises.
IP addresses and their bandwidth and their reputation in order to act on someone else's
behalf, which, yeah, is no bueno.
Right, right.
Our thanks to Dr. Renee Burton from Info blocks for joining us.
The research is titled fake installers, fake reviews, fake services, real proxies, real victims.
We'll have a link in the show notes.
And that's Research Saturday, brought to you.
by N2K CyberWire.
We'd love to know what you think of this podcast.
Your feedback ensures we deliver the insights
that keep you a step ahead
in the rapidly changing world of cybersecurity.
If you like our show,
please share a rating and review
in your favorite podcast app.
Please also fill out the survey in the show notes
or send an email to Cyberwire at N2K.com.
This episode was produced by Liz Stokes.
We're mixed by Elliot Peltzman and Trey Hester.
Our executive producer is Jennifer Ibin,
Peter Kilpe is our publisher, and I'm Dave Bittner.
Thanks for listening.
We'll see you back here next time.
