A fake 7-Zip website (7zip.com) has been distributing trojanized installers that convert infected Windows machines into residential proxy nodes. The malware, signed with a revoked certificate, installs a functional 7-Zip alongside hidden components (Uphero.exe, hero.exe, hero.dll) that establish system-level persistence,

7m read timeFrom malwarebytes.com
Post cover image
Table of contents
“I’m so sick to my stomach”A trojanized installer masquerading as legitimate softwareAbuse of trusted distribution channelsExecution flow: from installer to persistent proxy serviceFunctional goal: residential proxy monetizationShared tooling across multiple fake installersRotating infrastructure and encrypted transportEvasion and anti‑analysis featuresDefensive guidanceResearcher attribution and community analysisClosing thoughtsIndicators of Compromise (IOCs)

Sort: