Fake 7-Zip downloads are turning home PCs into proxy nodes
A convincing lookalike of the popular 7-Zip archiver site has been serving a trojanized installer that silently converts victims' machines into residential proxy nodes. The fake site, 7zip[.]com, distributes a functional copy of 7-Zip alongside concealed malware. The malware deploys three components: Uphero.exe (service manager), hero.exe (proxy payload), and hero.dll (supporting library). It establishes persistence through Windows services, manipulates firewall rules, and profiles the host system. The primary function is to enroll infected hosts as residential proxy nodes, allowing third parties to route traffic through victims' IP addresses. This campaign appears to be part of a broader operation with similar tactics used for other fake installers. The malware incorporates multiple evasion techniques and uses encrypted communications.
Pulse ID: 698d9d85f511c437a687cbad
Pulse Link: https://otx.alienvault.com/pulse/698d9d85f511c437a687cbad
Pulse Author: AlienVault
Created: 2026-02-12 09:29:41
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#7Zip #CyberSecurity #ICS #InfoSec #Mac #Malware #OTX #OpenThreatExchange #Proxy #RAT #Trojan #Windows #ZIP #bot #AlienVault