Malicious residential proxies are evolving into a standalone undergound industry

Analytics2026-07-21, 10:48
Infoblox investigated the operations of Lurking Lizard — an operator of malicious residential proxy networks that route traffic through IP addresses of real user devices. The research began with a campaign launched in early 2026 that distributed a fake 7-Zip installer. Once installed, the device became a proxy node available for rent.
Later, Infoblox linked the campaign to an infrastructure active since at least August 2022, and identified over 230 related domains mimicking popular software download sites. The key feature is that the operator controlled several parts of the ecosystem:
• distributed apps that connected compromised devices to the proxy pool upon installation; • built websites imitating legitimate proxy services; • sold access to infected devices for traffic redirection; • launched platforms hosting seemingly independent positive reviews of its services.
According to Infoblox, the operator established "an end-to-end malicious proxy business": from acquiring devices and managing infrastructure to marketing and selling access. The operator not only maintains its own pool of compromised devices but also buys access to residential IP addresses from larger providers. Around 2 million active IPv4 addresses belonging to smartproxy[.]org significantly overlapped with the IPIDEA network, which Google disrupted in early 2026.
Researchers stress that malicious residential proxies are no longer just an extra way to monetize infected devices but have become an independent underground business. The main commodity is access to real users' IP addresses, which helps conceal malicious activity behind seemingly legitimate traffic sources.
Vendors
Infoblox
Google
Smartproxy[.]Org
Ipidea
Products
7-Zip
Ipidea Network