FeedNetwork & InfrastructureWireVPN service linked to years-long residential proxy opera...
Network & InfrastructureCyber Insider
8.0CRITICAL

WireVPN service linked to years-long residential proxy operation

📅 7 July 2026 at 18:09 UTC📰 Cyber InsiderView original source ↗
WireVPN service linked to years-long residential proxy operation

A VPN service with more than one million Android downloads is at the center of a long-running operation that allegedly recruits victims' devices into a residential proxy network. The Infoblox investigation began after researchers analyzed the infrastructure behind a malicious installer distributed through the typosquatted 7zip[.]com domain. Instead of finding a single malware campaign, they … The post WireVPN service linked to years-long residential proxy operation appeared first on CyberInsider.

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

A residential proxy operation, tracked as Lurking Lizard, has been active since at least 2022, using WireVPN as a public-facing brand to recruit victims' devices into its network. The operation is likely run by a Chinese threat actor and controls multiple stages of the ecosystem.

⚙️Technical Details
Affected Systems
WindowsmacOSAndroidiOS
Attack Vectors
Fake software distributionTyposquatted domain (7zip[.]com)Residential proxy network
💥Impact Assessment
Severity: high
Who Is at Risk
Users of WireVPN service with Android appUsers of iOS app published under WIRE LTDUsers of Windows application with wire.exe and upwire.exe executablesSeverity: high
🛡️Recommended Actions
1Download software only from official sources
2Carefully verify domains before installing VPNs, utilities, or other security-related applications
3Monitor for suspicious activity on infected devices
📦Affected Products
WireVPN serviceiOS app published under WIRE LTD

Read the full article

This is a curated summary. The complete article is available at Cyber Insider.

Read on Cyber Insider
← Back to feed