INTEL_REPORT
The Hacker News · published 7/9/2026, 4:01:49 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes Cybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using an infrastructure comprising more than 230 lookalike domains. The activity dates back to at least August 2022, according to DNS threat intelligence firm Infoblox. Once such campaign, observed earlier this year, involved the Fake 7-Zip Insta…
https://thehackernews.com/2026/07/fake-7-zip-installers-turn-devices-into.html
sha256:483654138fabb582ba880b940965fda6ea88fd64f9e997154e772a1f13cbafe0
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.