Cyber attackers are increasingly using trusted software to compromise individuals and organizational systems. In this campaign, attackers distributed a trojanized version of the popular 7-Zip utility through a convincing-looking website, prompting victims to unknowingly install malware alongside the legitimate application. Once executed, the malware established command-and-control (C2) communications, enrolled infected devices into a residential proxy network, and enabled unauthorized network traffic and data exfiltration. By combining social engineering, typosquatted domains, and stealthy network communications, the campaign demonstrates how routine software downloads can become a high-risk initial access vector, emphasizing the importance of software validation, continuous network monitoring, and user awareness in detecting and preventing compromise.
The campaign leverages a trojanized installer masquerading as the legitimate 7-Zip application, distributed through a convincing typosquatted domain that closely imitates the official software website. While the installer delivers a functional version of the legitimate application to avoid raising suspicion, it also deploys additional malicious components that are absent from the genuine software package. These components establish persistence on the compromised host and initiate encrypted communications with attacker-controlled infrastructure, allowing the malware to receive configuration updates and maintain long-term access. The use of trusted software branding, search engine manipulation, and lookalike domains significantly increases the likelihood of successful compromise while reducing user suspicion.
Unlike conventional malware focused solely on data theft or ransomware deployment, this campaign primarily enables proxyware functionality by transforming compromised systems into nodes within a residential proxy network. Infected devices communicate with command-and-control (C2) infrastructure using encrypted channels and non-standard ports, facilitating the relay of third-party network traffic while blending into legitimate outbound communications. This capability allows threat actors to obscure the origin of malicious activities, evade security controls, and potentially support additional cybercriminal operations such as phishing, credential attacks, malware distribution, and anonymized access to online services. The campaign demonstrates a shift toward stealthy, service-oriented malware designed to monetize compromised endpoints while maintaining a low operational profile. The technical details of the attack campaign are discussed further below.
Delivery and Infection Chain:
The campaign uses social engineering and domain impersonation to distribute a trojanized 7-Zip installer. Attackers leveraged the typosquatted domain 7zip[.]com, which closely resembles the legitimate 7-zip[.]org, and promoted it through search engine results, tutorial websites, and YouTube videos. Victims unknowingly downloaded a functional version of 7-Zip bundled with hidden malicious payloads, allowing the installation to appear legitimate while silently compromising the system.
The infection chain was identified as follows:
Technical Capabilities:
The malware exhibits several capabilities designed to support stealth, persistence, and long-term operation. It establishes encrypted communications with attacker-controlled infrastructure using HTTPS and SSL/TLS while utilizing non-standard ports, including TCP ports 1000 and 1002, to facilitate proxy communications and evade conventional network monitoring. The malware performs periodic beaconing to multiple rotating C2 domains, retrieves configuration updates, and maintains persistent outbound connectivity using low-and-slow communication patterns.
Beyond command-and-control functionality, the malware converts compromised systems into residential proxy nodes capable of routing third-party network traffic. Open-source reporting indicates that the proxy protocol employs XOR encoding to obscure control messages, making network analysis more difficult. The malware also supports sustained data transfers that resemble low-volume exfiltration, allowing attackers to blend malicious activity with legitimate network traffic while maintaining operational resilience through multiple fallback domains and rotating infrastructure.
Attribution and Evolution:
Security researchers have attributed the campaign to the threat actor Lurking Lizard, believed to operate from China based on infrastructure analysis, WHOIS records, and operational patterns. The group has evolved from distributing fake software installers to operating a broader residential proxy ecosystem that includes counterfeit VPNs, messaging applications, fake proxy providers, review websites, and drop-caught domains to enhance the legitimacy and reach of its malicious infrastructure.
Active Campaign and Geographic Spread:
Observed throughout January 2026, the campaign affected organizations across the Americas (AMS), Europe, the Middle East and Africa (EMEA), and Asia-Pacific and Japan (APJ), targeting sectors including healthcare, manufacturing, education, and information technology. Its distributed command-and-control infrastructure, rotating "smshero"-themed domains, and globally hosted proxy endpoints demonstrate a resilient and opportunistic operation capable of sustaining a large-scale residential proxy network.
Conclusion:
The fake 7-Zip campaign highlights how threat actors are increasingly abusing trusted software and familiar user behavior to gain initial access while minimizing suspicion. By combining software impersonation, stealthy malware deployment, and residential proxy functionality, the campaign demonstrates the need for strict software validation, user awareness, and continuous monitoring to detect and contain sophisticated threats before they establish long-term persistence.
The campaign transforms compromised systems into residential proxy nodes, allowing attackers to relay unauthorized traffic through legitimate enterprise and residential IP addresses. This exposes organizations to operational, legal, and reputational risks while creating opportunities for persistent command-and-control, data exfiltration, secondary payload delivery, and other malicious activities. Its stealthy use of trusted software and encrypted communications makes detection and incident response significantly more challenging.
https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/