From 7-Zip to Proxy Botnet: Anatomy of a Modern Multi-Stage Malware Campaign

Summary:

Cyber attackers are increasingly using trusted software to compromise individuals and organizational systems. In this campaign, attackers distributed a trojanized version of the popular 7-Zip utility through a convincing-looking website, prompting victims to unknowingly install malware alongside the legitimate application. Once executed, the malware established command-and-control (C2) communications, enrolled infected devices into a residential proxy network, and enabled unauthorized network traffic and data exfiltration. By combining social engineering, typosquatted domains, and stealthy network communications, the campaign demonstrates how routine software downloads can become a high-risk initial access vector, emphasizing the importance of software validation, continuous network monitoring, and user awareness in detecting and preventing compromise.

Technical Description:

The campaign leverages a trojanized installer masquerading as the legitimate 7-Zip application, distributed through a convincing typosquatted domain that closely imitates the official software website. While the installer delivers a functional version of the legitimate application to avoid raising suspicion, it also deploys additional malicious components that are absent from the genuine software package. These components establish persistence on the compromised host and initiate encrypted communications with attacker-controlled infrastructure, allowing the malware to receive configuration updates and maintain long-term access. The use of trusted software branding, search engine manipulation, and lookalike domains significantly increases the likelihood of successful compromise while reducing user suspicion.

Unlike conventional malware focused solely on data theft or ransomware deployment, this campaign primarily enables proxyware functionality by transforming compromised systems into nodes within a residential proxy network. Infected devices communicate with command-and-control (C2) infrastructure using encrypted channels and non-standard ports, facilitating the relay of third-party network traffic while blending into legitimate outbound communications. This capability allows threat actors to obscure the origin of malicious activities, evade security controls, and potentially support additional cybercriminal operations such as phishing, credential attacks, malware distribution, and anonymized access to online services. The campaign demonstrates a shift toward stealthy, service-oriented malware designed to monetize compromised endpoints while maintaining a low operational profile. The technical details of the attack campaign are discussed further below.

Delivery and Infection Chain:

The campaign uses social engineering and domain impersonation to distribute a trojanized 7-Zip installer. Attackers leveraged the typosquatted domain 7zip[.]com, which closely resembles the legitimate 7-zip[.]org, and promoted it through search engine results, tutorial websites, and YouTube videos. Victims unknowingly downloaded a functional version of 7-Zip bundled with hidden malicious payloads, allowing the installation to appear legitimate while silently compromising the system.

The infection chain was identified as follows:

  • A user is lured to a typosquatted website (e.g., 7zip[.]com) through search engine results, tutorial content, or other social engineering techniques and downloads a trojanized version of the 7-Zip installer.
  • Upon execution, the installer deploys both a legitimate, functional copy of 7-Zip and additional malicious payloads (e.g., Uphero.exe, hero.exe, and hero.dll), allowing the installation to appear normal while silently compromising the system.
  • The malicious components establish persistence and initiate encrypted communications with attacker-controlled command-and-control (C2) infrastructure to retrieve configuration data and operational instructions.
  • The infected device is enrolled into a residential proxy network, where it maintains periodic beaconing and communicates over encrypted channels and non-standard ports (e.g., TCP ports 1000 and 1002) to receive updates and relay proxy traffic.
  • The compromised system functions as a proxy node under the attackers' control, enabling unauthorized traffic relaying, potential data exfiltration, and support for additional malicious activities while remaining operational with minimal impact on the user's normal use of the device.

Technical Capabilities:

The malware exhibits several capabilities designed to support stealth, persistence, and long-term operation. It establishes encrypted communications with attacker-controlled infrastructure using HTTPS and SSL/TLS while utilizing non-standard ports, including TCP ports 1000 and 1002, to facilitate proxy communications and evade conventional network monitoring. The malware performs periodic beaconing to multiple rotating C2 domains, retrieves configuration updates, and maintains persistent outbound connectivity using low-and-slow communication patterns.

Beyond command-and-control functionality, the malware converts compromised systems into residential proxy nodes capable of routing third-party network traffic. Open-source reporting indicates that the proxy protocol employs XOR encoding to obscure control messages, making network analysis more difficult. The malware also supports sustained data transfers that resemble low-volume exfiltration, allowing attackers to blend malicious activity with legitimate network traffic while maintaining operational resilience through multiple fallback domains and rotating infrastructure.

Attribution and Evolution:

Security researchers have attributed the campaign to the threat actor Lurking Lizard, believed to operate from China based on infrastructure analysis, WHOIS records, and operational patterns. The group has evolved from distributing fake software installers to operating a broader residential proxy ecosystem that includes counterfeit VPNs, messaging applications, fake proxy providers, review websites, and drop-caught domains to enhance the legitimacy and reach of its malicious infrastructure.

Active Campaign and Geographic Spread:

Observed throughout January 2026, the campaign affected organizations across the Americas (AMS), Europe, the Middle East and Africa (EMEA), and Asia-Pacific and Japan (APJ), targeting sectors including healthcare, manufacturing, education, and information technology. Its distributed command-and-control infrastructure, rotating "smshero"-themed domains, and globally hosted proxy endpoints demonstrate a resilient and opportunistic operation capable of sustaining a large-scale residential proxy network.

Conclusion:

The fake 7-Zip campaign highlights how threat actors are increasingly abusing trusted software and familiar user behavior to gain initial access while minimizing suspicion. By combining software impersonation, stealthy malware deployment, and residential proxy functionality, the campaign demonstrates the need for strict software validation, user awareness, and continuous monitoring to detect and contain sophisticated threats before they establish long-term persistence.

Impact:

The campaign transforms compromised systems into residential proxy nodes, allowing attackers to relay unauthorized traffic through legitimate enterprise and residential IP addresses. This exposes organizations to operational, legal, and reputational risks while creating opportunities for persistent command-and-control, data exfiltration, secondary payload delivery, and other malicious activities. Its stealthy use of trusted software and encrypted communications makes detection and incident response significantly more challenging.

IOC and Context Details:

Topics Details
Tactic Name Initial Access, Persistence, Command and Control, Exfiltration
Technique Name Exploit Public-Facing Application, Web Protocols, External Proxy, Encrypted Channel, Exfiltration Over C2 Channel, Scheduled Transfer, Automated Exfiltration, Non-Standard Port
Sub Technique Name External Proxy, Web Protocols, Exfiltration to Cloud Storage
Attack Type Trojanized Software Installer
Targeted Applications Fake installers impersonating 7-Zip, WireVPN, WhatsApp, TikTok Downloader, and YouTube Downloader.
Region Impacted Americas (AMS), Europe, Middle East & Africa (EMEA), Asia-Pacific & Japan (APJ)
Industry Impacted Healthcare, Manufacturing, Education, Information & Communication Technology (ICT)
IOC's Domains:
7zip[.]com
flux[.]smshero[.]co
neo[.]herosms[.]co
nova[.]smshero[.]ai
zest[.]hero-sms[.]ai
soc[.]hero-sms[.]co
pulse[.]herosms[.]cc
glide[.]smshero[.]cc
prime[.]herosms[.]vip

IP Addresses:
172.96.115[.]226
79.127.221[.]47
84.17.37[.]1
CVE NA

Recommended Actions:

  • Download software only from official vendor websites and verify the URL to avoid typosquatted or impersonated domains before installation.
  • Verify the authenticity of software installers by validating digital signatures and cryptographic hashes where available.
  • Implement application allowlisting to restrict the execution of unauthorized or untrusted software within the environment.
  • Continuously monitor network traffic for indicators of compromise, including beaconing behavior, connections to rare domains, and communications over non-standard ports such as TCP 1000 and 1002.
  • eploy Endpoint Detection and Response (EDR) and Network Detection and Response (NDR) solutions to detect malicious processes, persistence mechanisms, command-and-control communications, and anomalous outbound activity.
  • Block or monitor known malicious domains, IP addresses, and indicators of compromise (IOCs) associated with the campaign using firewalls, DNS filtering, and threat intelligence feeds.
  • Conduct regular security awareness training to educate users on the risks of downloading software from unofficial sources, search engine advertisements, and third-party tutorial websites.
  • Maintain an effective vulnerability and incident response program, including regular endpoint scans, threat hunting, and prompt investigation of suspicious network activity to identify and contain potential compromises early.

Reference:

https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/