Episode

All about that proxy. [Research Saturday]

Podcast
CyberWire Daily
Published
Sep 19, 2026
Duration seconds
1543
Processing state
not_requested
Canonical source
https://thecyberwire.com/podcasts/research-saturday/442/notes
Audio
https://pdst.fm/e/pdrl.fm/85df76/traffic.megaphone.fm/CYBW5049211197.mp3
JSON
/v1/public/podcasts/cyberwire-daily-454880/episodes/all-about-that-proxy-research-saturday
Markdown
/podcast/cyberwire-daily-454880/all-about-that-proxy-research-saturday.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/cyberwire-daily-454880/episodes/all-about-that-proxy-research-saturday/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/cyberwire-daily-454880/all-about-that-proxy-research-saturday.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Today we are joined by Dr. Renée Burton, VP of Threat Intelligence at Infoblox, discussing their work on Lurking Lizard, "Fake Installers, Fake Reviews, Fake Services – Real Proxies, Real." The research uncovers Lurking Lizard, a threat actor that has operated since at least 2022 by using fake software installers, VPNs, and lookalike domains to secretly turn victims’ devices into residential proxy nodes. Researchers identified more than 230 related domains and connected seemingly separate campaigns—including fake 7-Zip, downloader tools, and WireVPN—through shared infrastructure, tracking URLs, deployment patterns, and APIs. The investigation suggests the actor runs an end-to-end proxy operation, recruiting compromised devices and then monetizing their bandwidth through proxy services and fake review sites, with WireVPN appearing to be the latest evolution of the campaign. The research and executive brief can be found here: Fake Installers, Fake Reviews, Fake Services - Real Proxies, Real Victims Learn more about your ad choices. Visit megaphone.fm/adchoices