Cybersecurity researchers have identified a China-based threat actor known as Lurking Lizard that operates an extensive, end-to-end malicious residential proxy business using over 230 deceptive lookalike domains.
Key Points
- Lurking Lizard has been active since August 2022, recruiting compromised devices into a proxy botnet via trojanized installers for software like 7-Zip and WireVPN.
- The actor impersonates legitimate proxy providers like IPIDEA and SmartProxy while utilizing fake review sites to drive traffic to its own illicit storefronts.
- Attackers employ "drop-catching" to acquire expired domains, leveraging their established history and legitimacy to deceive users and distribute malware.
- A mobile application titled "wirevpn - Fast Unlimited Proxy," linked to the campaign, has reportedly amassed over 1 million downloads on Android devices.
- The operation functions as a full-lifecycle business, managing everything from the initial infection of victim devices to the final monetization of proxy access.