Skip to content
Return to Infoblox Homepage

Infoblox Threat Intel

Lurking Lizard

Lurking Lizard is a financially motivated threat actor that has operated a full-stack malicious residential proxy business since at least August 2022. The actor distributes trojanized software installers, including a fake 7-Zip utility, to silently enroll victim devices as nodes in a for-rent proxy network.
DNS analysis revealed 230+ actor-controlled domains impersonating popular software, VPN services, and residential proxy providers including IPIDEA, SmartProxy, and 911Proxy. The actor also runs fake proxy review sites to drive traffic to its own network. Infrastructure evidence and WHOIS data point to a likely Chinese origin.

Lurking Lizard

  • Operating since: August 2022
  • Infoblox discovered: January 2026
  • Infoblox published: July 2026
  • Prevalence: Uncommon
Infoblox Threat Actor - Lurking Lizard

Threat actor resources

Blog

Infoblox Threat Intel
July 7, 2026

Fake Installers, Fake Reviews, Fake Services - Real Proxies, Real Victims

Learn how a threat actor runs an end-to-end residential proxy business using lookalike domains, fake software downloads, and a connection to Chinese IPIDEA.

Read more
Back To Top