Lurking Lizard is a cybercriminal threat actor operating a malicious end-to-end residential proxy business active since at least August 2022. The actor uses trojanized software, lookalike domains, fake storefronts, and fake review sites to recruit victim devices into a proxy network and monetize those devices by selling access to their bandwidth and IP space. Activity attributed to this actor includes counterfeit installers masquerading as legitimate software such as 7-Zip, downloader tools, VPN-themed applications, and the later WireVPN brand across desktop and mobile platforms. The operation is notable for controlling multiple stages of the criminal proxy lifecycle: victim acquisition, malware delivery, backend management, branding, traffic generation, and resale of proxy access. Lurking Lizard has impersonated well-known proxy and software brands and has used drop-caught or lookalike domains to inherit trust and search visibility. Investigators linked more than 230 domains to the ecosystem and connected campaigns through shared WHOIS patterns, common backend API structures, repeated deployment workflows, and reused telemetry artifacts. On infected systems, the actor’s software preserves enough expected functionality to reduce user suspicion while covertly enrolling the device as a residential proxy node. Observed Windows variants established persistence and modified firewall settings. More recent WireVPN-branded samples showed behavior inconsistent with a conventional VPN client and more consistent with proxyware or an exit-node client, including maintaining numerous concurrent connections to distributed hosts. The actor has also used valid code-signing certificates issued to registered companies, which likely improved trust and reduced friction during installation. Available evidence indicates Lurking Lizard is likely China-based, with attribution supported by domain registration patterns and related registration artifacts. The actor’s dominant motivation is financial gain through commercialization of compromised-device bandwidth rather than espionage or disruptive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
22 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates a criminal residential proxy business by distributing trojanized software such as fake 7-Zip and WireVPN-branded apps, enrolling victim devices as residential proxy nodes, and monetizing them through fake proxy storefronts and review sites.
Operates an end-to-end malicious residential proxy business, recruiting victim devices through trojanized installers, mobile apps, lookalike domains, and fake review sites, then monetizing the resulting proxy botnet through scam proxy storefronts.
Operates a large-scale fraudulent residential proxy ecosystem using drop-caught expired domains, fake software installers, and a disguised proxy application to turn victim devices and internet connections into proxy exit nodes without consent.
Operates a long-running residential proxy monetization scheme using fake software installers and apps, including fake 7-Zip installers and the WireVPN app, to turn victim devices into proxy nodes and resell their bandwidth.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.