Uphero is a Windows proxyware malware family associated with trojanized software installers, most notably counterfeit 7-Zip packages distributed through lookalike download sites. It installs alongside a functioning copy of the advertised software to reduce suspicion, then deploys multiple components including a service manager and updater, a primary proxy payload, and a supporting library. Its core purpose is to enroll infected systems into a residential proxy network so third parties can route traffic through victims’ IP addresses for monetized abuse such as fraud, scraping, ad abuse, and anonymity laundering.
On infected hosts, Uphero establishes persistence by registering malicious components as auto-start Windows services that run with SYSTEM privileges. It modifies local firewall policy to permit its network activity, profiles the host using WMI and native Windows APIs, and transmits system and network metadata to external infrastructure. The proxy component retrieves configuration from rotating command-and-control infrastructure and opens outbound proxy connections over non-standard ports. Communications are protected or obscured through HTTPS, lightweight XOR-based message encoding, and DNS-over-HTTPS, complicating network detection.
The malware includes multiple anti-analysis and defense-evasion features, including checks for common virtualized environments, anti-debugging logic, runtime API resolution, process and environment inspection, and related host interrogation techniques. Reporting has linked Uphero to a broader multi-brand software impersonation operation using similar binaries and tactics under other application lures. The malware targets Windows systems and is best characterized as proxyware rather than a traditional interactive backdoor, although it performs substantial post-compromise host modification and remote configuration retrieval.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The operators behind 7zip[.]com distributed a trojanized installer via a lookalike domain, delivering a functional copy of 7‑Zip File Manager alongside a concealed malware payload.
The malware incorporates multiple layers of sandbox and analysis evasion: Process enumeration, registry probing, and environment inspection
“enumerates… network configuration… communicates with iplogger[.]org via a dedicated reporting endpoint”
The malware incorporates multiple layers of sandbox and analysis evasion: Process enumeration, registry probing, and environment inspection
“the malware enumerates system characteristics including hardware identifiers, memory size, CPU count, disk attributes, and network configuration.”
“The infected host is enrolled as a residential proxy node, allowing third parties to route traffic through the victim’s IP address.”
“The infected host is enrolled as a residential proxy node, allowing third parties to route traffic through the victim’s IP address.”
In their Reddit post, the user described installing the file first on a laptop and later transferring it via USB to a newly built desktop.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Installed as a Windows service with SYSTEM privileges for persistence; part of a fake 7-Zip installer bundle used to convert infected hosts into residential proxy nodes and maintain long-term access.
Dropped by trojanized software installers (e.g., fake 7-Zip). Installs as a Windows service (SYSTEM), modifies firewall rules, profiles the host via WMI/Windows APIs, and enrolls the victim as a residential proxy node. Uses rotating “smshero”-themed C2 domains, TLS-encrypted HTTPS, DNS-over-HTTPS (Google), and lightweight XOR-obfuscated control messages; includes anti-analysis checks for VMs/debuggers.
A trojanized component dropped by a fake 7-Zip installer that acts as a service manager and update loader, installs into SysWOW64, registers persistence as a Windows service under SYSTEM privileges, manipulates firewall rules, and supports a residential proxy monetization operation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.