Hero is a Windows proxyware malware family used to convert infected systems into residential proxy nodes for third-party traffic relaying and monetization. It has been observed distributed through trojanized software installers, notably counterfeit installers masquerading as legitimate applications such as 7-Zip, while preserving expected application functionality to reduce user suspicion. Related distribution lures have also impersonated other popular software brands, indicating a broader multi-brand installation campaign.
On infected hosts, Hero deploys multiple components including a primary proxy payload and supporting service and library modules. It establishes persistence by registering Windows services configured to start automatically and run with SYSTEM privileges. The malware modifies local firewall policy to permit its network activity, profiles the host using WMI and native Windows APIs, and collects system characteristics including hardware, CPU, memory, disk, and network information. It communicates with rotating command-and-control infrastructure over encrypted channels, retrieves configuration data, and opens outbound proxy connections on non-standard ports to relay traffic through the victim machine.
Hero incorporates multiple defense-evasion and anti-analysis measures, including virtualization and debugger checks, runtime API resolution, environment inspection, and use of DNS-over-HTTPS to reduce visibility for conventional DNS monitoring. Control traffic has been observed using lightweight obfuscation in addition to HTTPS transport. The malware’s operational purpose is consistent with residential proxy abuse, enabling downstream use cases such as fraud, scraping, ad abuse, and anonymity laundering rather than conventional interactive remote access. Associated binaries and infrastructure suggest a unified operation spanning several software-brand impersonation themes.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
“Traffic analysis shows a lightweight XOR‑encoded protocol (key 0x70) used to obscure control messages.”
The operators behind 7zip[.]com distributed a trojanized installer via a lookalike domain, delivering a functional copy of 7‑Zip File Manager alongside a concealed malware payload.
The malware incorporates multiple layers of sandbox and analysis evasion: Process enumeration, registry probing, and environment inspection
“enumerates… network configuration… communicates with iplogger[.]org via a dedicated reporting endpoint”
The malware incorporates multiple layers of sandbox and analysis evasion: Process enumeration, registry probing, and environment inspection
Using WMI and native Windows APIs, the malware enumerates system characteristics including hardware identifiers, memory size, CPU count, disk attributes, and network configuration.
Traffic analysis shows a lightweight XOR-encoded protocol (key 0x70) used to obscure control messages.
The hero.exe component retrieves configuration data from rotating “smshero”-themed command-and-control domains, then establishes outbound proxy connections on non-standard ports such as 1000 and 1002.
“traffic routed through Cloudflare infrastructure with TLS‑encrypted HTTPS sessions.”
The malware also uses DNS-over-HTTPS via Google’s resolver, reducing visibility for traditional DNS monitoring and complicating network-based detection.
“The infected host is enrolled as a residential proxy node, allowing third parties to route traffic through the victim’s IP address.”
In their Reddit post, the user described installing the file first on a laptop and later transferring it via USB to a newly built desktop.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Residential proxy malware delivered via a trojanized 7-Zip installer; persists via SYSTEM-level Windows services, modifies firewall rules via netsh, profiles the host, uses HTTPS C2 (often Cloudflare-fronted), XOR-obfuscates control messages (key 0x70), uses DNS-over-HTTPS, and opens outbound proxy connections on non-standard ports (e.g., 1000/1002) to relay third-party traffic through the victim IP.
Main proxy payload component used to turn infected hosts into residential proxy nodes. Retrieves configuration from rotating C2 domains, establishes proxy connections on non-standard ports (e.g., 1000/1002), and uses XOR-obfuscated control messaging; traffic is routed via Cloudflare and carried over TLS/HTTPS, with DNS-over-HTTPS to reduce defender visibility.
The primary Go-compiled payload delivered via the fake 7-Zip installer. It profiles the host, communicates with themed C2 domains over encrypted channels, uses XOR-obfuscated control traffic, persists as a Windows service, and converts infected systems into residential proxy nodes for third-party traffic routing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.