The images in this article were generated with artificial intelligence. How we publish
Cybersecurity researchers have demonstrated a sophisticated and long-term operation that turns domestic devices into a network of residential proxies for sale, a scheme that goes far beyond a single time malware: an actor, named Lurking Lizard, articulates recruitment, infrastructure, brand and monetization to provide access to legitimate IP addresses obtained from committed equipment.
The campaign uses techniques already known but tuned: creation and purchase of domains similar to real brands to take advantage of the legacy reputation (practice called drop-catching), distribution of stranded installers - for example, false copies of the 7-Zip installer -, mobile applications with credible branding and even false review sites that redirect traffic to their own "suppliers" of proxy. In addition, there are infrastructure and overlap crossings with legitimate or questioned services from the residential proxies market such as IPIDEA, SmartProxy and NetNut, which complicates powers and demolitions.

The practical damage to the device owner is double: first, your team goes on to routing third-party traffic without notice, which can degrade performance, increase data and energy consumption, and leave incriminating entries in records; second, that malicious or suspicious traffic can cause blockages or sanctions by suppliers and services, up to legal implications if IP addresses are used in attacks.
The resilience and scope of this operation are explained by its comprehensive approach: the agent is not limited to a malware campaign, but manages the entire cycle - plotting (installers, apps), "services" catalogue with apparent marks, and marketing through false reviews - which provides a constant source of PIs and the ability to monetize them scalably. Analysts also highlight the use of legitimate third-party services like lures to distribute malware and confuse research.
For domestic users the recommendation is clear and practical: distrust installers and apps outside official stores and always check that domains match exactly the marks (with correct scripts, characters and extensions). Review application permissions, avoid installing anonymous source utilities, keep the router system and firmware up-to-date, and use recognized malware solutions. If you notice unusual network behavior - sudden latency, unexplained data consumption or constant outgoing connections - disconnect the network device and do a deep scanning; if appropriate, restore to factory values the equipment or router and change administrative credentials.

For companies and service providers, the situation requires additional measures: monitoring and blocking suspicious residential proxies patterns, integrating threat lists and intelligence feeds into filtering systems, and working with registry and cloud platforms to accelerate domain demolitions and malicious infrastructure closures. It is also recommended to implement the detection of abnormal behaviour on the network and to require stricter safety controls to integrators or manufacturers who can incorporate third-party SDKs into their devices.
The security community and regulators are still looking for effective responses to these types of criminal ecosystems that imitate legitimate business models. In the meantime, it is useful to follow the publications of the intelligence and response teams and use public resources to keep them informed; for example, you can consult general reports and alerts at Infoblox and in Google Security Blog to understand similar tactics and mitigation actions that great ecosystem actors are taking.
In short, Lurking Lizard and related operations show that the border between malicious advertising, branding and residential proxies services is becoming more and more diffuse. The defence requires combining individual digital hygiene, network technical controls and collaboration between companies, registrators and authorities to close the circuit that feeds those illicit markets and protect users who unknowingly provide their connections as a third party tool.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...