A lookalike download site is luring people who want 7-Zip into installing a working archive tool plus silent proxyware. The attacker copied the legitimate project’s pages onto 7zip.com — a dehyphen + .com swap of the real 7-zip.org — then shipped an installer that registers the victim’s machine as a residential proxy node.
BleepingComputer confirmed the malicious site while covering analysis from Malwarebytes and independent researchers. Help Net Security and Cyberinsider report the same pattern: users landed on the fake domain after a YouTube PC-build tutorial (or comment) pointed to the wrong URL.

Snapshot
| Field | Detail |
|---|---|
| Legitimate project | 7-Zip at 7-zip.org (also mirrors/forwards: 7zip.org, 7-zip.com, 7-zip.net) |
| Malicious download lure | 7zip.com (dehyphen + TLD swap) |
| Malware class | Proxyware — enrolls host as a residential proxy node |
| Dropped binaries | Uphero.exe, hero.exe, hero.dll → C:\Windows\SysWOW64\hero\ |
| Code signing | Authenticode cert issued to Jozeal Network Technology Co., Limited (reported revoked) |
| Reported lure path | YouTube tutorial / comment → wrong domain → USB can spread the installer further |
| Related brands in same op | Trojanized installers referencing HolaVPN, TikTok, WhatsApp, Wire (Malwarebytes) |
| Defender cue | Generic Microsoft Defender trojan alerts weeks later in the Reddit case |
How the lure works
| Step | What happens |
|---|---|
| 1. Wrong domain | Victim searches or follows a tutorial that cites 7zip.com instead of 7-zip.org. |
| 2. Convincing copy | Site clones text/structure of the real 7-Zip pages. |
| 3. Dual payload | Installer delivers a functional 7-Zip UI and three hidden components. |
| 4. Persistence | Services run as SYSTEM; netsh firewall rules open paths for the proxy binaries. |
| 5. Proxy enrollment | hero.exe pulls config from rotating smshero-themed C2 hosts and opens outbound proxy links (reported ports 1000 / 1002, XOR-obfuscated control traffic). |
| 6. Monetization | Attackers sell residential IP egress — fraud, scraping, ad abuse — while the user thinks they only installed an archiver. |
Malwarebytes manager Stefan Dasic: any system that ran installers from 7zip.com should be treated as compromised. The same operators reuse the proxyware stack across other consumer-brand download lures.

Cybersquat scan — 7-zip.org → 7zip.com
EmailMeNow’s cybersquat engine is built for this exact pattern: hyphenated open-source brands lose the hyphen and move to .com. On July 29, 2026 we scanned 7-zip.org (standard profile, 108 lookalikes). Variant generation ranks 7zip.com as dehyphen-tld-swap and finds 16 DNS-registered lookalikes — but not all are hostile.
Re-checked the same day: several listed names are already controlled by the project (shared Beget nameservers + identical homepage, or an HTTP forward to 7-zip.org). The cybersquat “points at brand” classifier flags 7zip.org (redirect) and 7-zip.net (A+NS overlap); 7-zip.com is the same official site content on Beget as well (byte-identical homepage / GitHub release links) even though it does not 301.
Brand-owned / project aliases (not the lure)
| Domain | Technique | Evidence of brand control | Notes |
|---|---|---|---|
7zip.org | dehyphenation | 301 → https://7-zip.org/; same Beget NS | Safe forward — still not the bookmark people should memorize |
7-zip.com | tld-swap | Identical official homepage (len match, same download / GitHub release links); Beget NS | Project mirror on .com — different host IP from apex |
7-zip.net | tld-swap | Identical homepage + A+NS overlap with 7-zip.org | Project mirror |
Still treat as hostile / third-party lookalikes
| Lookalike | Technique | DNS signals (DoH) | Notes |
|---|---|---|---|
7zip.com | dehyphen-tld-swap | NS (A often sinkholed to 0.0.0.0) | Reported proxyware download lure |
7zip.net | dehyphen-tld-swap | NS, A, MX | ParkLogic parking — not Beget / not project infra |
7zip.online | dehyphen-tld-swap | NS, A, AAAA | Live unrelated site (Myanmar casino / gambling landing) |
7zip.site | dehyphen-tld-swap | NS, A, MX | Sedo parking |
7-zip.dev | tld-swap | NS, A, AAAA | Third-party “free download” page (Cloudflare) — not the project homepage |
7-zip.xyz | tld-swap | NS, A | Third-party Chinese “7zip官网” download marketing page |
7-zip.io | tld-swap | NS, A, MX | Registrar-default NS; HTTP timed out in our check |
7zip.io / 7zip.app / 7zip.dev / 7zip.cloud / 7-zip.app | dehyphen-tld-swap / tld-swap | NS (± sinkholed A/AAAA) | Registered sprawl; several resolver-sinkholed — still not “owned = safe to recommend” |
8-zip.org | adjacent-key | NS, A | Keyboard-adjacent digit swap; parking-style response |
Registration is inferred from public NS / A / AAAA / MX via Cloudflare DoH — not WHOIS. Ownership cues add HTTP redirects, shared A+NS with the monitored apex, and (for this write-up) identical project homepage content. That split matters: readers who confuse 7zip.org (project forward) with 7zip.com (lure) illustrate why tutorials must cite the exact hostname.
Track your brand at Cybersquat Domain Monitoring ($49/mo) — weekly email of newly registered lookalikes, including dehyphen-tld-swap patterns, with likely-owned (points at brand) filtered separately from domains still needing review.
What to do
| Audience | Action |
|---|---|
| Everyone | Download 7-Zip only from https://www.7-zip.org/ — bookmark it. Project-owned aliases like 7zip.org (forwards) / 7-zip.com / 7-zip.net currently mirror the official site, but do not treat search hits for 7zip.com, 7-zip.dev, or 7-zip.xyz as equivalent. |
If you used 7zip.com | Assume compromise: isolate the PC, rebuild or run a trusted EDR full scan, rotate passwords/tokens used on that host, check for SysWOW64\hero and unexpected Windows services. |
| IT / MSP | Block 7zip.com / related C2 at DNS and egress; alert on new services + sudden netsh firewall changes; prefer software deployment from verified catalogs, not end-user Google results. |
| Brand / OSS | Keep holding the alias matrix (as 7-Zip already does for .org dehyphen + .com/.net); monitor remaining dehyphen + TLD swaps; file registrar abuse on active download lures; correct high-traffic tutorials that cite the wrong URL. |
Independent cybersecurity audits
EmailMeNow domain audits on July 29, 2026. 100% is the ideal overall score — none of these reach it. Scores measure public identity / transport / website posture, not whether a given installer was trojanized.
| Organization / role | Domain | Overall | Identity | Transport | Website | Risk |
|---|---|---|---|---|---|---|
| Legitimate 7-Zip project | 7-zip.org | 36% | 10% | 15% | 37% | Weak |
| Reported malicious lure | 7zip.com | 29% | 0% | 15% | 40% | Weakest |
Brand-owned forward (→ 7-zip.org) | 7zip.org | 48% | 50% | 15% | 37% | Below Average |
| Brand-owned mirror (identical site) | 7-zip.com | 48% | 50% | 15% | 37% | Below Average |
| Brand-owned mirror (identical site + shared infra) | 7-zip.net | 48% | 50% | 15% | 37% | Below Average |
| Parked / third-party lookalike | 7zip.net | 46% | 35% | 15% | 39% | Below Average |
| Unrelated live lookalike (casino landing) | 7zip.online | 28% | 0% | 15% | 37% | Weakest |
| Parked lookalike (Sedo) | 7zip.site | 47% | 35% | 15% | 40% | Below Average |
| Third-party download mirror | 7-zip.dev | 30% | 0% | 45% | 37% | Weak |
| Research lab (source) | malwarebytes.com | 72% | 90% | 45% | 45% | Good |
Audit links: 7-zip.org · 7zip.com · 7zip.org · 7zip.net · 7-zip.com · 7-zip.net · 7zip.online · 7zip.site · 7-zip.dev · malwarebytes.com

Pattern: The legitimate project’s weak identity (10%) and transport (15%) do not cause this infection — downloaders followed the wrong hostname. The project does already hold useful aliases (7zip.org, 7-zip.com, 7-zip.net), which is good defensive hygiene — but soft mail/auth posture plus the remaining parked/third-party matrix still leaves room for spoofed “update” / “download” narratives beside an already confusing name (7-zip vs 7zip). The lure domain scores 0% identity. Malwarebytes.com leads this set at 72%, still below the 100% ideal.
Website stack note
Website-tech probes on July 29, 2026 (7-zip.org, 7zip.com, update.7zip.com, malwarebytes.com):
7-zip.org,7zip.com, andupdate.7zip.com— no exposed CMS / PHP fingerprint (common for static or heavily stripped download sites; not a clean bill of health for the lure).malwarebytes.com— WordPress detected with generator version hidden (latest public WordPress train referenced as 7.0.2 at probe time). Hidden versions are normal on hardened marketing sites.
Priority actions
- Bookmark
https://www.7-zip.org/— refuse7zip.comand any unfamiliar “7zip” download host; don’t confuse the project’s7zip.orgforward with the lure. - Hunt
C:\Windows\SysWOW64\hero\and unexpected Windows services on machines that may have used the lure. - Block known lure / C2 indicators at DNS and firewall; watch for odd outbound ports (1000 / 1002 called out in public analysis).
- Correct internal docs and popular tutorials that still say “7zip.com.”
- Monitor hyphenated product domains for dehyphen-tld-swap registrations (cybersquat monitoring).
- Prefer managed software deployment over end-user browser downloads for productivity tools.
Related trackers
- Cybersquat Domain Monitoring
- Surfside Beach BEC lookalike domains
- ClickLock macOS stealer
- CrashStealer CrashReporter impersonation
- Breach monitoring resources
Sources: BleepingComputer · Help Net Security / Malwarebytes · Cyberinsider · 7-Zip official site