Lurking Lizard is a cybercriminal threat actor operating a malicious end-to-end residential proxy business active since at least August 2022. The group is tracked for using trojanized software, lookalike domains, fake storefronts, and fake review sites to recruit victim devices into a proxy network and monetize those devices’ bandwidth by reselling access to third parties. Available evidence suggests the actor is likely China-based, based on domain registration patterns and related infrastructure artifacts, although public attribution remains at the level of assessed origin rather than confirmed state sponsorship. The actor’s operations center on impersonation of legitimate software and services. Lurking Lizard has used counterfeit installers and branded applications themed as popular utilities, VPN products, messaging-related tools, and social-media downloaders. A notable campaign used a fake 7-Zip installer to covertly install proxyware while preserving enough expected functionality to reduce user suspicion and discourage removal. More recent activity has used the WireVPN brand across desktop and mobile ecosystems, indicating an evolution from simple trojanized installers toward broader multi-platform distribution. Lurking Lizard appears to control a large supporting ecosystem of more than 230 domains. This infrastructure has included malware delivery sites, fake proxy-provider storefronts, and fabricated “independent” review portals designed to steer customers toward actor-controlled services. The group has impersonated well-known proxy brands including IPIDEA, Smartproxy, IP Royal, and 911Proxy. The operation has also used drop-catch techniques to acquire expired domains with residual reputation and search visibility, improving the credibility and discoverability of malicious lures. Infrastructure analysis links the actor’s campaigns through repeated reuse of backend services, similar API structures, common deployment workflows, shared tracking artifacts, and consistent payload-delivery patterns. Public reporting has also tied multiple malware families and lure themes together through shared telemetry mechanisms embedded in samples. These overlaps support the assessment that the fake software campaigns, proxy storefronts, and review-site ecosystem are components of a single coordinated criminal enterprise rather than unrelated activity clusters. On victim systems, Lurking Lizard’s malware has been observed establishing persistence and modifying host configuration to support long-term operation. Reported behaviors include use of firewall-rule changes and registry-based persistence, along with staged updater components. Traffic analysis of WireVPN-associated software indicates behavior inconsistent with a conventional privacy VPN client and more consistent with proxy-node or exit-node functionality, including maintaining numerous concurrent connections and participating in distributed traffic forwarding. This suggests the actor’s software is designed to convert infected or deceived users’ devices into rentable residential proxy nodes. The group’s business model appears to span the full residential proxy lifecycle: acquiring victims, maintaining the proxy pool, marketing access through impersonated brands, and generating demand through fake reviews and storefronts. Reporting also indicates the actor may blend bandwidth from compromised devices with upstream proxy supply, increasing the scale and apparent legitimacy of its offerings. Mobile app-store presence and code-signing use further indicate an effort to exploit trust mechanisms and broaden distribution. Lurking Lizard is best characterized as a financially motivated cybercriminal actor specializing in covert proxy monetization, brand impersonation, and large-scale abuse of consumer devices for residential proxy services. Known aliases are limited in the available reporting, and Lurking Lizard is the primary recognized name for the cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
22 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates a criminal residential proxy business by distributing trojanized software such as fake 7-Zip and WireVPN-branded apps, enrolling victim devices as residential proxy nodes, and monetizing them through fake proxy storefronts and review sites.
Operates an end-to-end malicious residential proxy business, recruiting victim devices through trojanized installers, mobile apps, lookalike domains, and fake review sites, then monetizing the resulting proxy botnet through scam proxy storefronts.
Operates a large-scale fraudulent residential proxy ecosystem using drop-caught expired domains, fake software installers, and a disguised proxy application to turn victim devices and internet connections into proxy exit nodes without consent.
Operates a long-running residential proxy monetization scheme using fake software installers and apps, including fake 7-Zip installers and the WireVPN app, to turn victim devices into proxy nodes and resell their bandwidth.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.