Skip to content
Deep Dive high FinanceCritical InfrastructureCommunicationsGovernmentprofessional-services

Lurking Lizard: How a China-Linked Cybercrime Group Built a Global Residential Proxy Network Through Fake Software

Executive Summary

A China-based cybercrime group tracked by Infoblox as Lurking Lizard has built one of the most extensive residential proxy networks documented in the threat intelligence community, using a business model that is both technically elegant and operationally durable: distribute trojanised versions of legitimate software utilities, silently enrol compromised devices as proxy nodes, and rent those nodes to criminal and potentially state-adjacent customers through a commercial-facing proxy broker interface.

The infrastructure exposed in July 2026 includes over 230 lookalike domains impersonating legitimate proxy service brands, a managed distribution pipeline for weaponised installers, and a customer-facing rental interface positioning the service as a legitimate enterprise product. The group has been operating since at least August 2022 and has maintained uninterrupted operations through multiple years of activity while evading takedowns that have disrupted comparable services.

Residential proxy networks of this kind are not purely criminal infrastructure. They serve as operational relay networks for cyber espionage actors seeking to route intrusion traffic through residential IP addresses that bypass blocklists, geofencing controls, and detection systems tuned for datacenter-originated traffic. The same infrastructure that processes commercial proxy rental traffic can host and conceal traffic from nation-state operators.

Threat Actor Profile

Lurking Lizard operates at the intersection of financially motivated cybercrime and infrastructure-as-a-service for the broader threat ecosystem. The group is assessed with moderate confidence as China-based based on language characteristics in the code, infrastructure registration patterns, and the overlap between their proxy customer base and known China-nexus threat actor infrastructure usage.

Unlike APT groups that run residential proxy infrastructure exclusively for their own operations, Lurking Lizard commercialises access. This creates a business incentive to maximise the scale and diversity of compromised IP addresses, and it means that tracking Lurking Lizard infrastructure also reveals customers — some of whom are sophisticated threat actors using commercial proxy services specifically to avoid attribution.

The group has demonstrated operational continuity through multiple years of activity, with infrastructure changes that suggest active management rather than automated or abandoned operations. They have responded to branded competitor takedowns by expanding their own lookalike domain portfolio, effectively capitalising on victim confusion following law enforcement disruptions to services like 911Proxy and similar operations.

Technical Profile: The Proxyware Supply Chain

Lurking Lizard’s operation involves three distinct components that operate as an integrated pipeline: malware distribution, device enrolment, and commercial proxy rental.

Distribution Infrastructure

The initial access mechanism relies on trojanised installers for software that users actively seek out and download: 7-Zip, WinRAR, popular VPN clients, and system utilities. The installers function correctly — they install the legitimate software the user expects — while simultaneously delivering the proxyware payload as a secondary component. This approach produces a victim who has no observable sign of infection beyond slightly elevated network activity, and who is unlikely to attribute any symptoms to the software they intentionally installed.

The distribution channels mirror legitimate software discovery paths:

  • Typosquatted and lookalike domains impersonating the official sites of targeted software projects
  • Malvertising through Google Ads and other paid search placement, inserting trojanised installers above organic search results for software download queries
  • Fake review networks that establish apparent legitimacy for the trojanised distribution sites through review aggregators and forum seeding

The 230+ lookalike domains serve multiple purposes: distributing the malware, providing an apparent legal identity for the commercial proxy service, and fragmenting the infrastructure footprint to complicate domain-level blocklisting.

Device Enrolment and Proxyware Operation

Once a device is compromised, the proxyware payload registers the device with the Lurking Lizard backend. The enrolment process exchanges device metadata — IP address, geographic location, connection type, bandwidth characteristics — with the group’s management infrastructure. From this point, the device functions as a proxy node: the backend can route external traffic through the device’s residential IP address, with each request appearing to originate from a legitimate residential subscriber.

The proxyware payload is designed for operational persistence with minimal host-side visibility:

  • It runs as a background service with a name that blends with legitimate Windows services
  • Traffic is transmitted over ports that avoid triggering basic firewall rules (443, 80) or using protocols that appear benign in traffic analysis
  • Resource consumption is managed to avoid triggering performance-based anomaly detection on the host
  • The payload updates remotely, allowing the group to modify detection evasion characteristics without requiring a new infection chain

From the victim device’s perspective, the impact is typically limited to increased network utilisation and battery drain on laptops. This keeps the infection subthreshold for many endpoint security tools and for the users themselves.

Commercial Rental Interface

Lurking Lizard sells proxy access through a commercial interface that positions the service as a legitimate enterprise data collection product. This mirrors the presentation of legal residential proxy services (providers like Bright Data, Oxylabs, and others operate legitimate proxy networks based on disclosed, consented node enrolment). The distinction is consent: legitimate providers pay node operators and require explicit opt-in; Lurking Lizard compromises devices without consent.

The commercial tier offers:

  • Rotating residential IP pools organised by country, city, and ISP
  • Session persistence options for use cases requiring sticky IPs
  • API access for programmatic proxy rotation
  • Volume-based pricing tiers typical of commercial proxy services

This commercial presentation serves two functions: it generates revenue from non-criminal customers (businesses engaged in price monitoring, ad fraud detection, and similar tasks), and it provides a plausible legitimate business cover that complicates law enforcement action relative to a purely criminal service.

Victimology and Scale

Lurking Lizard’s proxy network derives its value from geographic diversity. The group has invested in distribution channels targeting users across multiple regions, with documented presence across North America, Europe, and Asia-Pacific. Residential IP diversity — the range of ISPs and geographic locations represented in the proxy pool — is the core commercial metric, and the group’s lookalike domain portfolio and malvertising spend is calibrated to maximise that diversity.

The customer base for the proxy service spans the criminal ecosystem:

  • Credential stuffing operations using residential IPs to bypass rate limiting and geographic anomaly detection on authentication systems
  • Account takeover campaigns that appear to originate from the legitimate owner’s residential IP
  • Ad fraud requiring diverse residential IPs to simulate legitimate ad impressions
  • Web scraping that benefits from residential IPs to bypass anti-bot controls
  • Threat actor operational security — routing C2 traffic or reconnaissance through residential IPs to evade network-level detection

The last category is the most significant from a threat intelligence perspective. Several proxy services disrupted by law enforcement have revealed that nation-state actors routinely use commercial residential proxy services for operational traffic. The 911Proxy takedown in 2023 exposed customer lists that included clusters of activity consistent with state-sponsored intrusion campaigns. Lurking Lizard’s customer base should be assumed to include similar actors.

Historical Activity and Context

Lurking Lizard’s operation predates several of the major residential proxy disruptions of 2023-2025. The group likely accelerated growth during the period when 911Proxy was taken offline (July 2022) and when Rsocks was disrupted (June 2022), absorbing displaced customers from those services.

The group’s operational longevity — operating continuously since at least August 2022 — reflects several factors:

  • Commercial positioning that creates legal ambiguity around the service itself
  • Fragmented infrastructure that limits the impact of individual domain or server takedowns
  • Domestic operations in China that complicate law enforcement cooperation
  • Revenue that funds continued adaptation and re-infrastructure when components are disrupted

The July 2026 Infoblox disclosure is likely not the first exposure of Lurking Lizard infrastructure — components of their domain portfolio and installer distribution have probably appeared in earlier threat intelligence reporting under different tracking names. Attribution consolidation in the residential proxy space is difficult because the business model intentionally mirrors legitimate services.

Targeting Implications for Defenders

The primary defensive challenge posed by Lurking Lizard is not the group itself, but what their infrastructure enables. A well-resourced residential proxy network provides critical capability to threat actors across the spectrum:

For ransomware operators: Initial access through credential stuffing or brute force attacks becomes significantly harder to detect and block when conducted through rotating residential IPs. Geographic anomaly detection on authentication events — a common layered control — produces many fewer alerts when the attacker’s source IPs are distributed residential addresses in the same country as the victim organisation.

For business email compromise: Accessing compromised email accounts through a residential IP in the victim’s city or region makes session anomaly detection substantially less reliable. BEC groups routinely use residential proxy services to avoid triggering location-based conditional access policies.

For nation-state actors: Routing reconnaissance and intrusion traffic through residential IPs makes network-level detection more difficult and complicates attribution. CISA and NSA advisories on China-nexus actors have specifically noted the use of residential proxy infrastructure to complicate detection.

For credential stuffing: Authentication attacks conducted through Lurking Lizard’s proxy pool will show high IP diversity and residential address characteristics that defeat many blocklisting and rate-limiting approaches designed for datacenter traffic.

Defensive Implications

For enterprise security teams

Authentication security should not rely on IP-based geolocation as a primary control. Residential proxy networks can route traffic through IPs in any geographic location, defeating controls that block authentication from unexpected countries while permitting traffic from the user’s home country. MFA — particularly phishing-resistant FIDO2/passkey authentication — is the appropriate control layer.

Monitoring for proxyware infection should be included in endpoint detection capabilities. Indicators include:

  • Processes listening on non-standard ports or initiating outbound connections that are not associated with installed applications
  • Services with generic names that don’t correspond to known software in the environment
  • Background processes that maintain persistent TCP connections to IP addresses outside normal traffic patterns
  • Unusual network throughput on endpoints, particularly outside business hours

Software download hygiene is the primary prevention control. User education should cover the risks of downloading software from non-official sources and through search advertising — the primary distribution channel for Lurking Lizard installers. Enterprise controls should include application allowlisting or at minimum reputation-based execution controls that flag newly downloaded executables before running.

For threat intelligence teams

Lurking Lizard infrastructure should be treated as a potential indicator of a wider threat actor presence, not just a commodity criminal service. Customer traffic traversing the proxy network may include APT activity. Observed Lurking Lizard IPs in authentication logs or network traffic should prompt investigation into what those IP addresses have been attempting to access, not just the conclusion that the IP is a known proxy.

The group’s lookalike domain portfolio provides detection opportunities: blocking the documented 230+ domains at DNS resolvers prevents devices that download the trojanised installers from reaching Lurking Lizard’s backend infrastructure, disrupting enrolment even if the installer executes.

Assessment

Lurking Lizard occupies a category of threat that is structurally difficult to disrupt: a commercially viable, domestically protected service with a diverse customer base that spans criminal and potentially state-adjacent users. The July 2026 disclosure provides actionable infrastructure indicators and a cleaner attribution picture than previously existed, but operational disruption will require law enforcement action and sustained infrastructure blocklisting.

The group’s proxyware network should be treated as threat infrastructure with a longer operational lifespan than typical criminal services. Defence against their customers — the actors using the proxy pool for credential attacks, BEC, and potentially espionage activity — is more tractable than disrupting the network itself.