Lurking Lizard the operation that turns your home devices into residential proxies for sale

Author: Published 3 min de lectura 200 reading

The images in this article were generated with artificial intelligence. How we publish

Cybersecurity researchers have demonstrated a sophisticated and long-term operation that turns domestic devices into a network of residential proxies for sale, a scheme that goes far beyond a single time malware: an actor, named Lurking Lizard, articulates recruitment, infrastructure, brand and monetization to provide access to legitimate IP addresses obtained from committed equipment.

The campaign uses techniques already known but tuned: creation and purchase of domains similar to real brands to take advantage of the legacy reputation (practice called drop-catching), distribution of stranded installers - for example, false copies of the 7-Zip installer -, mobile applications with credible branding and even false review sites that redirect traffic to their own "suppliers" of proxy. In addition, there are infrastructure and overlap crossings with legitimate or questioned services from the residential proxies market such as IPIDEA, SmartProxy and NetNut, which complicates powers and demolitions.

Lurking Lizard the operation that turns your home devices into residential proxies for sale
Image generated with IA.

The practical damage to the device owner is double: first, your team goes on to routing third-party traffic without notice, which can degrade performance, increase data and energy consumption, and leave incriminating entries in records; second, that malicious or suspicious traffic can cause blockages or sanctions by suppliers and services, up to legal implications if IP addresses are used in attacks.

The resilience and scope of this operation are explained by its comprehensive approach: the agent is not limited to a malware campaign, but manages the entire cycle - plotting (installers, apps), "services" catalogue with apparent marks, and marketing through false reviews - which provides a constant source of PIs and the ability to monetize them scalably. Analysts also highlight the use of legitimate third-party services like lures to distribute malware and confuse research.

For domestic users the recommendation is clear and practical: distrust installers and apps outside official stores and always check that domains match exactly the marks (with correct scripts, characters and extensions). Review application permissions, avoid installing anonymous source utilities, keep the router system and firmware up-to-date, and use recognized malware solutions. If you notice unusual network behavior - sudden latency, unexplained data consumption or constant outgoing connections - disconnect the network device and do a deep scanning; if appropriate, restore to factory values the equipment or router and change administrative credentials.

Lurking Lizard the operation that turns your home devices into residential proxies for sale
Image generated with IA.

For companies and service providers, the situation requires additional measures: monitoring and blocking suspicious residential proxies patterns, integrating threat lists and intelligence feeds into filtering systems, and working with registry and cloud platforms to accelerate domain demolitions and malicious infrastructure closures. It is also recommended to implement the detection of abnormal behaviour on the network and to require stricter safety controls to integrators or manufacturers who can incorporate third-party SDKs into their devices.

The security community and regulators are still looking for effective responses to these types of criminal ecosystems that imitate legitimate business models. In the meantime, it is useful to follow the publications of the intelligence and response teams and use public resources to keep them informed; for example, you can consult general reports and alerts at Infoblox and in Google Security Blog to understand similar tactics and mitigation actions that great ecosystem actors are taking.

In short, Lurking Lizard and related operations show that the border between malicious advertising, branding and residential proxies services is becoming more and more diffuse. The defence requires combining individual digital hygiene, network technical controls and collaboration between companies, registrators and authorities to close the circuit that feeds those illicit markets and protect users who unknowingly provide their connections as a third party tool.

Coverage

Related

More news on the same subject.