Infoblox Threat Intel
Lurking Lizard
Lurking Lizard is a financially motivated threat actor that has operated a full-stack malicious residential proxy business since at least August 2022. The actor distributes trojanized software installers, including a fake 7-Zip utility, to silently enroll victim devices as nodes in a for-rent proxy network.
DNS analysis revealed 230+ actor-controlled domains impersonating popular software, VPN services, and residential proxy providers including IPIDEA, SmartProxy, and 911Proxy. The actor also runs fake proxy review sites to drive traffic to its own network. Infrastructure evidence and WHOIS data point to a likely Chinese origin.
Lurking Lizard
- Operating since: August 2022
- Infoblox discovered: January 2026
- Infoblox published: July 2026
- Prevalence: Uncommon
