Malicious 7-Zip site distributes installer laced with proxy tool
嗯,用户让我用中文总结一篇文章,控制在100字以内,而且不需要特定的开头。首先,我需要仔细阅读文章内容,抓住主要信息。 文章讲的是一个假的7-Zip网站在传播一个被植入木马的安装程序。这个木马会把用户的电脑变成住宅代理节点。住宅代理网络利用家庭用户的设备来路由流量,目的是绕过封锁和进行恶意活动,比如 credential stuffing、钓鱼和分发恶意软件。 用户是在按照YouTube教程下载7-Zip的时候误入了这个恶意网站。恶意网站的结构和真实网站很像,甚至使用了合法工具的文本和结构。安装程序被分析后发现它会释放三个恶意文件,并创建自动启动的服务。此外,防火墙规则也被修改以允许这些文件建立连接。 进一步分析发现,这个恶意软件的主要功能是代理软件,将感染的主机注册为住宅代理节点。它还使用了动态C2域名和Cloudflare基础设施来隐藏活动,并检查虚拟化平台以避免被分析。 总结下来,主要内容包括:假网站、木马安装程序、变成代理节点、恶意活动、技术细节以及用户建议。我需要把这些信息浓缩到100字以内,确保涵盖关键点。 </think> 一个假冒7-Zip官网传播了植入木马的安装程序,该木马可将用户电脑变为住宅代理节点用于恶意活动。攻击者通过仿冒7-zip.org创建虚假网站诱导用户下载恶意软件,并利用动态C2域名和Cloudflare隐藏行踪。 2026-2-10 19:15:15 Author: www.bleepingcomputer.com(查看原文) 阅读量:5 收藏

Malicious 7-zip site pushes malware that turns devices into proxies

A fake 7-Zip website is distributing a trojanized installer of the popular archiving tool that turns the user’s computer into a residential proxy node.

Residential proxy networks use home user devices to route traffic with the goal of evading blocks and performing various malicious activities such as credential stuffing, phishing, and malware distribution.

The new campaign became better known after a user reported that they downloaded a malicious installer from a website impersonating the 7-Zip project while following instructions in a YouTube tutorial on building a PC system. BleepingComputer can confirm that the malicious website, 7zip[.]com, is still live.

Wiz

The threat actor registered the domain 7zip[.]com (still live at the time of writing) that can easily trick users into thinking they landed on the site of the legitimate tool.

Furthermore, the attacker copied the text and mimicked the structure of the original 7-Zip website located at 7-zip.org.

Malicious website dropping the trojanized 7-Zip
Malicious website dropping the trojanized 7-Zip
Source: BleepingComputer

The installer file was analyzed by researchers at cybersecurity company Malwarebytes, who found that it is digitally signed with a now-revoked certificate originally issued to Jozeal Network Technology Co., Limited.

The malicious copy also contains the 7-Zip program, thus providing the regular functions of the tool. However, the installer drops three malicious files:

  1. Uphero.exe – service manager and update loader
  2. hero.exe – main proxy payload
  3. hero.dll – support library

These files are placed in the ‘C:\Windows\SysWOW64\hero\’ directory, and an auto-start Windows service running as SYSTEM is created for the two malicious executables.

Additionally, firewall rules are modified using ‘netsh’ to allow the binaries to establish inbound and outbound connections.

Eventually, the host system is profiled with Microsoft's Windows Management Instrumentation (WMI) and Windows APIs to determine the hardware, memory, CPU, disk, and network characteristics. The collected data is then sent to ‘iplogger[.]org.’

"While initial indicators suggested backdoor‑style capabilities, further analysis revealed that the malware’s primary function is proxyware," Malwarebytes explains about the malware’s operational goal.

“The infected host is enrolled as a residential proxy node, allowing third parties to route traffic through the victim’s IP address.”

According to the analysis, hero.exe pulls config from rotating “smshero”-themed C2 domains, then opens outbound proxy connections on non-standard ports such as 1000 and 1002. Control messages are obfuscated using a lightweight XOR key.

Malwarebytes found that the campaign is larger than the 7-Zip lure and also uses trojanized installers for HolaVPN, TikTok, WhatsApp, and Wire VPN.

The malware uses a rotating C2 infrastructure built around hero/smshero domains, with traffic going through the Cloudflare infrastructure and carried over TLS-encrypted HTTPs.

It also relies on DNS-over-HTTPS via Google’s resolver, which reduces visibility for defenders monitoring standard DNS traffic.

The malware also checks for virtualization platforms such as VMware, VirtualBox, QEMU, Parallels, as well as for debuggers, to identify when it’s being analyzed.

Malwarebytes' investigation started after noticing research from independent security researchers who analyzed the malware and uncovered its true purpose. Researcher Luke Acha discovered the purpose of the Uphero/hero malware.

The xor-based communication protocol was reverse-engineered and decoded by s1dhy, who confirmed the proxy behavior. Digital forensics and incident response (DFIR) engineer Andrew Danis connected the fake 7-Zip installer to the larger campaign impersonating multiple software brands.

Malwarebytes lists indicators of compromise (domains, file paths, IP addresses) and host-related data observed during their analysis.

Users are recommended to avoid following URLs from YouTube videos or promoted search results, and instead bookmark the download portal domains for the software they use often.

tines

The future of IT infrastructure is here

Modern IT infrastructure moves faster than manual workflows can handle.

In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.


文章来源: https://www.bleepingcomputer.com/news/security/malicious-7-zip-site-distributes-installer-laced-with-proxy-tool/
如有侵权请联系:admin#unsafe.sh