Home ยท Wiki ยท Entities & Threat Actors
type: entity ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [cybercrime-group, c2, loader] ยท confidence: medium ยท affected_sectors: [technology] ยท au_impact: false

Lurking Lizard

Lurking Lizard is a residential proxy business operation disclosed by Infoblox that uses trojanized software installers โ€” particularly fake 7-Zip installer executables โ€” to turn victims' devices into residential proxy nodes without their knowledge.

Operation

  • 230+ lookalike domains distributing trojanized installers
  • Victims download fake 7-Zip installers from search-engine-optimized malware sites
  • Infected devices become part of a residential proxy network
  • Activity dating to at least August 2022 (raw/digests/Cyber-Digest-2026-07-10)

Comparison: NetNut

This operation mirrors the commercial residential proxy model used by Netnut (taken down by FBI in July 2026), but operates at a smaller scale and without a publicly-traded parent company.

Related Pages

  • Netnut Takedown โ€” FBI takedown of a similar, larger residential proxy operation
  • Wp Shellstorm โ€” Another operation using compromised infrastructure