Back to news
Cybersecurity Alert
July 29, 2026 by EmailMeNow IT Consulting

Fake 7-Zip Site Distributes Installer That Turns PCs Into Proxy Nodes

7zip.com impersonates 7-zip.org and ships a trojanized installer that enrolls PCs as residential proxy nodes. Of 16 registered lookalikes we scanned, several (7zip.org, 7-zip.com, 7-zip.net) are brand-owned mirrors/forwards — the lure still scores 29% vs 36% for the project; none at the 100% ideal.

Source: BleepingComputer

NewsMalwareProxywareTyposquattingSoftware Supply Chain7-ZipCybersquatCybersecurity
Lookalike archive-tool download lure turning a home PC into a residential proxy node

A lookalike download site is luring people who want 7-Zip into installing a working archive tool plus silent proxyware. The attacker copied the legitimate project’s pages onto 7zip.com — a dehyphen + .com swap of the real 7-zip.org — then shipped an installer that registers the victim’s machine as a residential proxy node.

BleepingComputer confirmed the malicious site while covering analysis from Malwarebytes and independent researchers. Help Net Security and Cyberinsider report the same pattern: users landed on the fake domain after a YouTube PC-build tutorial (or comment) pointed to the wrong URL.

Lookalike archive-tool download lure turning a home PC into a residential proxy node

Snapshot

FieldDetail
Legitimate project7-Zip at 7-zip.org (also mirrors/forwards: 7zip.org, 7-zip.com, 7-zip.net)
Malicious download lure7zip.com (dehyphen + TLD swap)
Malware classProxyware — enrolls host as a residential proxy node
Dropped binariesUphero.exe, hero.exe, hero.dllC:\Windows\SysWOW64\hero\
Code signingAuthenticode cert issued to Jozeal Network Technology Co., Limited (reported revoked)
Reported lure pathYouTube tutorial / comment → wrong domain → USB can spread the installer further
Related brands in same opTrojanized installers referencing HolaVPN, TikTok, WhatsApp, Wire (Malwarebytes)
Defender cueGeneric Microsoft Defender trojan alerts weeks later in the Reddit case

How the lure works

StepWhat happens
1. Wrong domainVictim searches or follows a tutorial that cites 7zip.com instead of 7-zip.org.
2. Convincing copySite clones text/structure of the real 7-Zip pages.
3. Dual payloadInstaller delivers a functional 7-Zip UI and three hidden components.
4. PersistenceServices run as SYSTEM; netsh firewall rules open paths for the proxy binaries.
5. Proxy enrollmenthero.exe pulls config from rotating smshero-themed C2 hosts and opens outbound proxy links (reported ports 1000 / 1002, XOR-obfuscated control traffic).
6. MonetizationAttackers sell residential IP egress — fraud, scraping, ad abuse — while the user thinks they only installed an archiver.

Malwarebytes manager Stefan Dasic: any system that ran installers from 7zip.com should be treated as compromised. The same operators reuse the proxyware stack across other consumer-brand download lures.

Hidden proxyware binaries converting a Windows host into a residential proxy relay

Cybersquat scan — 7-zip.org7zip.com

EmailMeNow’s cybersquat engine is built for this exact pattern: hyphenated open-source brands lose the hyphen and move to .com. On July 29, 2026 we scanned 7-zip.org (standard profile, 108 lookalikes). Variant generation ranks 7zip.com as dehyphen-tld-swap and finds 16 DNS-registered lookalikes — but not all are hostile.

Re-checked the same day: several listed names are already controlled by the project (shared Beget nameservers + identical homepage, or an HTTP forward to 7-zip.org). The cybersquat “points at brand” classifier flags 7zip.org (redirect) and 7-zip.net (A+NS overlap); 7-zip.com is the same official site content on Beget as well (byte-identical homepage / GitHub release links) even though it does not 301.

Brand-owned / project aliases (not the lure)

DomainTechniqueEvidence of brand controlNotes
7zip.orgdehyphenation301 → https://7-zip.org/; same Beget NSSafe forward — still not the bookmark people should memorize
7-zip.comtld-swapIdentical official homepage (len match, same download / GitHub release links); Beget NSProject mirror on .com — different host IP from apex
7-zip.nettld-swapIdentical homepage + A+NS overlap with 7-zip.orgProject mirror

Still treat as hostile / third-party lookalikes

LookalikeTechniqueDNS signals (DoH)Notes
7zip.comdehyphen-tld-swapNS (A often sinkholed to 0.0.0.0)Reported proxyware download lure
7zip.netdehyphen-tld-swapNS, A, MXParkLogic parking — not Beget / not project infra
7zip.onlinedehyphen-tld-swapNS, A, AAAALive unrelated site (Myanmar casino / gambling landing)
7zip.sitedehyphen-tld-swapNS, A, MXSedo parking
7-zip.devtld-swapNS, A, AAAAThird-party “free download” page (Cloudflare) — not the project homepage
7-zip.xyztld-swapNS, AThird-party Chinese “7zip官网” download marketing page
7-zip.iotld-swapNS, A, MXRegistrar-default NS; HTTP timed out in our check
7zip.io / 7zip.app / 7zip.dev / 7zip.cloud / 7-zip.appdehyphen-tld-swap / tld-swapNS (± sinkholed A/AAAA)Registered sprawl; several resolver-sinkholed — still not “owned = safe to recommend”
8-zip.orgadjacent-keyNS, AKeyboard-adjacent digit swap; parking-style response

Registration is inferred from public NS / A / AAAA / MX via Cloudflare DoH — not WHOIS. Ownership cues add HTTP redirects, shared A+NS with the monitored apex, and (for this write-up) identical project homepage content. That split matters: readers who confuse 7zip.org (project forward) with 7zip.com (lure) illustrate why tutorials must cite the exact hostname.

Track your brand at Cybersquat Domain Monitoring ($49/mo) — weekly email of newly registered lookalikes, including dehyphen-tld-swap patterns, with likely-owned (points at brand) filtered separately from domains still needing review.

What to do

AudienceAction
EveryoneDownload 7-Zip only from https://www.7-zip.org/ — bookmark it. Project-owned aliases like 7zip.org (forwards) / 7-zip.com / 7-zip.net currently mirror the official site, but do not treat search hits for 7zip.com, 7-zip.dev, or 7-zip.xyz as equivalent.
If you used 7zip.comAssume compromise: isolate the PC, rebuild or run a trusted EDR full scan, rotate passwords/tokens used on that host, check for SysWOW64\hero and unexpected Windows services.
IT / MSPBlock 7zip.com / related C2 at DNS and egress; alert on new services + sudden netsh firewall changes; prefer software deployment from verified catalogs, not end-user Google results.
Brand / OSSKeep holding the alias matrix (as 7-Zip already does for .org dehyphen + .com/.net); monitor remaining dehyphen + TLD swaps; file registrar abuse on active download lures; correct high-traffic tutorials that cite the wrong URL.

Independent cybersecurity audits

EmailMeNow domain audits on July 29, 2026. 100% is the ideal overall score — none of these reach it. Scores measure public identity / transport / website posture, not whether a given installer was trojanized.

Organization / roleDomainOverallIdentityTransportWebsiteRisk
Legitimate 7-Zip project7-zip.org36%10%15%37%Weak
Reported malicious lure7zip.com29%0%15%40%Weakest
Brand-owned forward (→ 7-zip.org)7zip.org48%50%15%37%Below Average
Brand-owned mirror (identical site)7-zip.com48%50%15%37%Below Average
Brand-owned mirror (identical site + shared infra)7-zip.net48%50%15%37%Below Average
Parked / third-party lookalike7zip.net46%35%15%39%Below Average
Unrelated live lookalike (casino landing)7zip.online28%0%15%37%Weakest
Parked lookalike (Sedo)7zip.site47%35%15%40%Below Average
Third-party download mirror7-zip.dev30%0%45%37%Weak
Research lab (source)malwarebytes.com72%90%45%45%Good

Audit links: 7-zip.org · 7zip.com · 7zip.org · 7zip.net · 7-zip.com · 7-zip.net · 7zip.online · 7zip.site · 7-zip.dev · malwarebytes.com

Domain security audit comparison for legitimate 7-Zip vs lookalike download domains

Pattern: The legitimate project’s weak identity (10%) and transport (15%) do not cause this infection — downloaders followed the wrong hostname. The project does already hold useful aliases (7zip.org, 7-zip.com, 7-zip.net), which is good defensive hygiene — but soft mail/auth posture plus the remaining parked/third-party matrix still leaves room for spoofed “update” / “download” narratives beside an already confusing name (7-zip vs 7zip). The lure domain scores 0% identity. Malwarebytes.com leads this set at 72%, still below the 100% ideal.

Website stack note

Website-tech probes on July 29, 2026 (7-zip.org, 7zip.com, update.7zip.com, malwarebytes.com):

  • 7-zip.org, 7zip.com, and update.7zip.com — no exposed CMS / PHP fingerprint (common for static or heavily stripped download sites; not a clean bill of health for the lure).
  • malwarebytes.comWordPress detected with generator version hidden (latest public WordPress train referenced as 7.0.2 at probe time). Hidden versions are normal on hardened marketing sites.

Priority actions

  1. Bookmark https://www.7-zip.org/ — refuse 7zip.com and any unfamiliar “7zip” download host; don’t confuse the project’s 7zip.org forward with the lure.
  2. Hunt C:\Windows\SysWOW64\hero\ and unexpected Windows services on machines that may have used the lure.
  3. Block known lure / C2 indicators at DNS and firewall; watch for odd outbound ports (1000 / 1002 called out in public analysis).
  4. Correct internal docs and popular tutorials that still say “7zip.com.”
  5. Monitor hyphenated product domains for dehyphen-tld-swap registrations (cybersquat monitoring).
  6. Prefer managed software deployment over end-user browser downloads for productivity tools.

Sources: BleepingComputer · Help Net Security / Malwarebytes · Cyberinsider · 7-Zip official site