Fake 7-Zip Installers Turn Devices Into Residential Proxy

Fake 7-Zip Installers Turn Devices Into Residential Proxy

Information:

  7-Zip is a highly popular, free, and open-source file archiver tool used globally to compress and decompress files. It features a high compression ratio via its primary .7z format and integrates strong AES-256 encryption. Because it is a staple utility software downloaded by millions of users, it has become a prime target for cybercriminals seeking to leverage its trusted reputation to distribute malware.

Incident:

  Threat intelligence firm Infoblox disclosed operations by a China-based actor dubbed "Lurking Lizard," which has managed a sophisticated, end-to-end illicit residential proxy business since at least August 2022.

The adversary utilized over 230 lookalike domains to deceive users. Specifically, they hosted a trojanized 7-Zip installer on 7zip[.]com (exploiting users who mistyped the legitimate URL 7-zip.org). Victims were frequently driven to these sites through search engines and malicious links embedded in online video tutorials.

Incident:

  Beyond 7-Zip, the infrastructure also distributed fake variants of WhatsApp, deceptive YouTube/TikTok downloaders, and WireVPN installers. The threat targets Windows, macOS, and Android platforms (including a rogue Android app that amassed over 1 million downloads).

  Once executed, the malware silently turns the victim's device into an exit node within a residential proxy botnet. The compromised bandwidth and IP addresses are then bundled and monetized through the actor's proxy storefronts, which are promoted using fake independent review sites.

Recommendation: 

-Always download 7-Zip directly from its official website: 7-zip.org. If you are unsure, uninstall and reinstall the program.

-Refrain from downloading utility tools via links listed under video descriptions, forums, or unofficial blogs.

-Be vigilant about unexpected high bandwidth usage or active network connections running in the background when the device is idle.

-Ensure reliable anti-malware solutions are deployed and system updates are regularly maintained to detect trojanized executables.

The important things is Security systems. We must concern and monitor as usual.
For more information please contact
Email :sales@inetms.co.th
065 149 2822 (Ms.Suphatson )
063 204 4534 (Ms.Atsamaphorn)
065 929 6330 (Ms.Kansinee)
092 257 6902 (Ms.Narusorn)
063 197 7510 (Mr.Yanotai)
065 725 7405 (Ms.Nattharini)
065 725 7405 (Ms.Donraya)

References:

-https://thehackernews.com/2026/07/fake-7-zip-installers-turn-devices-into.html

Weekly Interesting CVE

NO.

CVE Name

Published Date

Last Update

Device/Appplication/OS Target

Attack Type

CVSS
Severity Rating

Detail

Solution

Reference

1

CVE-2026-53167

25/6/2026

4/7/2026

Linux Kernel with FUSE driver without patch

Information Disclosure

7

The FUSE_NOTIFY_RETRIEVE function may leak data into user-space, which could potentially be used by an attacker to gain system control.

Update Linux Kernel to the latest version with the security patch

https://app.opencve.io/cve/CVE-2026-53167

2

CVE-2026-39808

1/7/2026

3/7/2026

Google Chrome (versions prior to 150.0.7871.46)

Heap Buffer Overflow

8.3

Heap buffer overflow in Skia graphics engine, allowing attackers to escape the browser sandbox and execute arbitrary code on the OS.

Upgrade Chrome to version 150.0.7871.46 or later.

https://app.opencve.io/cve/?page=10&product=chatbot_for_wordpress_by_collect.chat_%E2%9A%A1%EF%B8%8F&vendor=collectchat

3

CVE-2026-13368

2/7/2026

2/7/2026

WatchGuard Fireware OS (versions 11.0-11.12.4, 12.0-12.12, 2025.1-2026.2)

Race condition

9.2

LDAP authentication flaw in Mobile VPN, allowing remote attackers into the iked process.

Update Fireware OS to version 2026.3 or higher.

https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00023

 4

CVE-2026-45499

2/7/2026

3/7/2026

Microsoft Azure OpenAI

Server-side request forgery (SSRF)

9.9

Allows attackers to trigger the system to call internal endpoints for privilege escalation and unauthorized data access.

Update to the latest version as announced via official Azure channels.

https://app.opencve.io/cve/CVE-2026-45499

5

CVE-2026-24266

1/7/2026

1/7/2026

NVIDIA Triton Inference Server for Linux (versions 0.0 - 26.03)

Use-after-free

5.9

Attackers can send malformed requests to trigger a Use-after-free vulnerability, causing a server process crash and Denial of Service.

Install patch or update software per NVIDIA's instructions.

https://o3.security/vulnerability/CVE-2026-24266

Malware News or Campaign IOC/IOA | EN

No

Campaign Name

Detection Date

Attack

Type

 

Description

 

Mitigation/Remediation

1

RustDuck botnet rapidly evolves with migration to Rust​

01/07/2026​

Malware

QiAnXin XLab researchers have identified RustDuck, a rapidly evolving botnet that is transitioning from C to Rust, making its malware more difficult to analyze while continuously enhancing its evasion capabilities.​

RustDuck targets IoT devices such as routers, IP cameras, and Android set-top boxes, as well as exposed servers running applications like ThinkPHP and Jenkins. It exploits both recent and older vulnerabilities, including CVE-2017-17215.​

The malware employs advanced anti-analysis techniques to detect sandbox and debugging environments and secures its command-and-control (C2) communications using ChaCha20-Poly1305 and AES-GCM encryption with frequently rotating keys.​

Although RustDuck is not currently the largest botnet, its rapid evolution, use of Rust, and advanced evasion techniques make it a significant emerging threat that security teams should closely monitor.​

  • Avoid downloading files or executing commands from untrusted sources.​
  • Keep systems and applications up to date​
  • Strengthen user security awareness​

Ref: https://www.scworld.com/brief/rustduck-botnet-rapidly-evolves-with-migration-to-rust

 

14 July 2026

Viewed 69 time

Engine by shopup.com