Fake 7-Zip Installers Turn Devices Into Residential Proxy

Information:
7-Zip is a highly popular, free, and open-source file archiver tool used globally to compress and decompress files. It features a high compression ratio via its primary .7z format and integrates strong AES-256 encryption. Because it is a staple utility software downloaded by millions of users, it has become a prime target for cybercriminals seeking to leverage its trusted reputation to distribute malware.
Incident:
Threat intelligence firm Infoblox disclosed operations by a China-based actor dubbed "Lurking Lizard," which has managed a sophisticated, end-to-end illicit residential proxy business since at least August 2022.

The adversary utilized over 230 lookalike domains to deceive users. Specifically, they hosted a trojanized 7-Zip installer on 7zip[.]com (exploiting users who mistyped the legitimate URL 7-zip.org). Victims were frequently driven to these sites through search engines and malicious links embedded in online video tutorials.
Incident:
Beyond 7-Zip, the infrastructure also distributed fake variants of WhatsApp, deceptive YouTube/TikTok downloaders, and WireVPN installers. The threat targets Windows, macOS, and Android platforms (including a rogue Android app that amassed over 1 million downloads).
Once executed, the malware silently turns the victim's device into an exit node within a residential proxy botnet. The compromised bandwidth and IP addresses are then bundled and monetized through the actor's proxy storefronts, which are promoted using fake independent review sites.
Recommendation:
-Always download 7-Zip directly from its official website: 7-zip.org. If you are unsure, uninstall and reinstall the program.
-Refrain from downloading utility tools via links listed under video descriptions, forums, or unofficial blogs.
-Be vigilant about unexpected high bandwidth usage or active network connections running in the background when the device is idle.
-Ensure reliable anti-malware solutions are deployed and system updates are regularly maintained to detect trojanized executables.
The important things is Security systems. We must concern and monitor as usual.
For more information please contact
Email :sales@inetms.co.th
065 149 2822 (Ms.Suphatson )
063 204 4534 (Ms.Atsamaphorn)
065 929 6330 (Ms.Kansinee)
092 257 6902 (Ms.Narusorn)
063 197 7510 (Mr.Yanotai)
065 725 7405 (Ms.Nattharini)
065 725 7405 (Ms.Donraya)
References:
-https://thehackernews.com/2026/07/fake-7-zip-installers-turn-devices-into.html
Weekly Interesting CVE
| NO. |
CVE Name |
Published Date |
Last Update |
Device/Appplication/OS Target |
Attack Type |
CVSS |
Detail |
Solution |
Reference |
|---|---|---|---|---|---|---|---|---|---|
| 1 |
CVE-2026-53167 |
25/6/2026 |
4/7/2026 |
Linux Kernel with FUSE driver without patch |
Information Disclosure |
7 |
The FUSE_NOTIFY_RETRIEVE function may leak data into user-space, which could potentially be used by an attacker to gain system control. |
Update Linux Kernel to the latest version with the security patch |
|
| 2 |
CVE-2026-39808 |
1/7/2026 |
3/7/2026 |
Google Chrome (versions prior to 150.0.7871.46) |
Heap Buffer Overflow |
8.3 |
Heap buffer overflow in Skia graphics engine, allowing attackers to escape the browser sandbox and execute arbitrary code on the OS. |
Upgrade Chrome to version 150.0.7871.46 or later. |
|
| 3 |
CVE-2026-13368 |
2/7/2026 |
2/7/2026 |
WatchGuard Fireware OS (versions 11.0-11.12.4, 12.0-12.12, 2025.1-2026.2) |
Race condition |
9.2 |
LDAP authentication flaw in Mobile VPN, allowing remote attackers into the iked process. |
Update Fireware OS to version 2026.3 or higher. |
https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00023 |
| 4 |
CVE-2026-45499 |
2/7/2026 |
3/7/2026 |
Microsoft Azure OpenAI |
Server-side request forgery (SSRF) |
9.9 |
Allows attackers to trigger the system to call internal endpoints for privilege escalation and unauthorized data access. |
Update to the latest version as announced via official Azure channels. |
|
| 5 |
CVE-2026-24266 |
1/7/2026 |
1/7/2026 |
NVIDIA Triton Inference Server for Linux (versions 0.0 - 26.03) |
Use-after-free |
5.9 |
Attackers can send malformed requests to trigger a Use-after-free vulnerability, causing a server process crash and Denial of Service. |
Install patch or update software per NVIDIA's instructions. |
https://o3.security/vulnerability/CVE-2026-24266 |
Malware News or Campaign IOC/IOA | EN
|
No |
Campaign Name |
Detection Date |
Attack Type |
Description |
Mitigation/Remediation |
|---|---|---|---|---|---|
| 1 |
RustDuck botnet rapidly evolves with migration to Rust |
01/07/2026 |
Malware |
QiAnXin XLab researchers have identified RustDuck, a rapidly evolving botnet that is transitioning from C to Rust, making its malware more difficult to analyze while continuously enhancing its evasion capabilities. RustDuck targets IoT devices such as routers, IP cameras, and Android set-top boxes, as well as exposed servers running applications like ThinkPHP and Jenkins. It exploits both recent and older vulnerabilities, including CVE-2017-17215. The malware employs advanced anti-analysis techniques to detect sandbox and debugging environments and secures its command-and-control (C2) communications using ChaCha20-Poly1305 and AES-GCM encryption with frequently rotating keys. Although RustDuck is not currently the largest botnet, its rapid evolution, use of Rust, and advanced evasion techniques make it a significant emerging threat that security teams should closely monitor. |
|
Ref: https://www.scworld.com/brief/rustduck-botnet-rapidly-evolves-with-migration-to-rust
14 July 2026
Viewed 69 time