Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Ghost in the 7‑Zip: The Shadow of Residential P...

Sponsored · Your Podcast. Everywhere. Effortlessly. Share. Educate. Inspire. Entertain. You do you. We'll handle the rest.

Ghost in the 7‑Zip: The Shadow of Residential Proxies Creeping into Your Life

2026年5月16日に開催された「BSides Tokyo 2026」での講演資料(TLP:CLEAR バージョン)です。
イベントURL: https://bsides.tokyo

Avatar for NTT docomo Business

NTT docomo Business

May 28, 2026

More Decks by NTT docomo Business

Other Decks in Research

Transcript

  1. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. © NTT

    DOCOMO BUSINESS, Inc. All Rights Reserved. Ghost in the 7 - Zip Ryo Minakawa The Shadow of Residential Proxies Creeping into Your Life BSides Tokyo 2026
  2. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 1 TLP:

    CLEAR $ Whoami BSides Tokyo 2026 Ryo Minakawa strinsert1Na Senior Manager and CTI analyst @NTT DOCOMO BUSINESS, Inc. I’ve been living in the “ Pokémon Pokopia ” world lately. NTT Com -SIRT
  3. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 2 TLP:

    CLEAR Attention BSides Tokyo 2026 Please use the content within the scope of the TLP !! TLP: CLEAR TLP: AMBER+STRICT Approved for internet discussion Limited disclosure
  4. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 3 TLP:

    CLEAR Agenda BSides Tokyo 2026 1. Introduction 2. Inside the Fake 7 -Zip Installer Campaign 3. Pivoting Across Similar Campaigns 4. Wrap -up
  5. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 4 ©

    NTT DOCOMO BUSINESS, Inc. All Rights Reserved. Introduction BSides Tokyo 2026 1
  6. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 5 TLP:

    CLEAR Are you familiar with this incident? BSides Tokyo 2026 Fake 7 -Zip downloads are turning home PCs into proxy nodes, https://www.malwarebytes.com/blog/threat-intel/2026/02/fake-7-zip- downloads-are-turning-home-pcs-into-proxy-nodes 『非公式7-Zip Web サイトにて公開されているインストーラによる不審なファイルの展開』, https://wizsafe.iij.ad.jp/2026/01/2075/
  7. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 6 TLP:

    CLEAR Lookups on VirusTotal BSides Tokyo 2026 The impact in Japan was particularly significant from January to February this year.
  8. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 7 TLP:

    CLEAR Presentation Overview BSides Tokyo 2026 • Overview • Investigation results of the Fake 7 -Zip campaign • The campaign was not isolated; similar campaigns are still active today • These campaigns appear to be part of a broader residential proxy ecosystem • Key Takeaways • Pivot -based analysis revealed multiple related campaigns with shared infrastructure and signatures. • Provide insights into the attackers and the residential proxy ecosystem behind the campaigns
  9. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 8 ©

    NTT DOCOMO BUSINESS, Inc. All Rights Reserved. Inside the Fake 7 -Zip Installer Campaign BSides Tokyo 2026 2
  10. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 9 TLP:

    CLEAR Fake 7 -Zip Campaign Infection Chain BSides Tokyo 2026 update.7zip[.]cloud 7zip[.]com soc.hero -sms [.]co, etc. Uphero.exe hero.exe hero.dll 7zFM.exe C:\Windows \SysWOW64 \hero 1. Access landing website 2. Download request to the C2 server. 3. Download fake installer 7zInstaller.exe a 4. Drop fake 7 -zip 5. Deploy proxy tools 7. Kich proxy tool 5. Fetch configuration and registration as node Load 8. Proxy operation Proxy endpoints (Port 1000 or 1002) 6. Update request
  11. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 10 TLP:

    CLEAR Deeper Analysis - Landing Website (7zip[.]com) - BSides Tokyo 2026 2001 2025.05.26 2025 2026 2026.02.14 Shut down Redesign 2026.01.11 Fake installer distribution • 7zip[.]com appeared to be a community -run mirror of 7 -zip.org (Official Website ) • It had been continuously operated since 2001 • The reason for its sudden malicious behavior remains unclear • Possibilities include unauthorized access, domain takeover, or a change in ownership • As international media coverage increased, the site was quietly shut down on Feb 14, 2026 ……
  12. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 11 TLP:

    CLEAR Deeper Analysis - Landing Website (7zip[.]com) - BSides Tokyo 2026 ~ 2026/1/11 18:48(UTC) 2026/1/11 21:22(UTC) ~ Around 19:00 on Jan 11, 2026, the API response previously pointing to 7 -zip.org was modified to download the installer from the malicious 7zip[.]cloud domain continued until the shutdown on Feb 14. ※ According to the Internet Archive records Ref. Internet Archive, https://web.archive.org/web/20260123064211/https://www.7zip.com/api_v1
  13. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 12 TLP:

    CLEAR Deeper Analysis - Installer (Process tree) - BSides Tokyo 2026 • 7zInstaller.exe installs the legitimate 7-Zip application while executing 7zFM.exe, a proxy tool dropper • 7zFM.exe drops three files, including Uphero.exe , and then executes Uphero.exe via Windows service • Uphero.exe updates via C2 communication, configures firewall settings, and generates a victim -specific mask (MD5 -based system identifier) • It then executes hero.exe via a Windows service with the mask as an argument ( -m option) 7zInstaller.exe Fake 7 -zip Installer 7zFM.exe Proxy tools dropper and kick Uphero.exe via Service Uphero.exe Change Firewall settings, send heartbeat request, load configs from C2 and k ick hero.exe via Service hero.exe Connect proxy tunnel $ C:\Windows\SysWOW64\hero¥hero.exe –s hero –m [md5hash calculated by env.] $ C:\WINDOWS\system32\cmd.exe /c netsh advfirewall firewall add rule name="hero" dir=out action=allow program="C:\Windows\SysWOW64\hero\hero.exe"
  14. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 13 TLP:

    CLEAR Deeper Analysis - Dropper (7zFM.exe) - BSides Tokyo 2026 A simple dropper that stores all PE files in its resources without encryption or obfuscation
  15. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 14 TLP:

    CLEAR POST /client_v2/report/report-log Deeper Analysis - Updater ( Uphero.exe ) - BSides Tokyo 2026 {version=514E504E…} HTTP/1/1 200 OK {"code":200,"msg":"SUCCESS","data":null} POST /client_v2/report/win-log {version=514E504E…} POST /client_v1/config POST /client_v2/version/server {version=514E504E…} {"code":200,"msg":"SUCCESS","data":null} {mask=1234567890abcd…} {"code":200,"msg":"SUCCESS","data":……} {"code":200,"msg":"SUCCESS","data":……} Phase1: Send system information and heartbeat • All data is transmitted XOR - encoded with the single -byte key 0x60 • The server does not return any meaningful responses. HTTP/1/1 200 OK HTTP/1/1 200 OK HTTP/1/1 200 OK Phase2: Fetch configuration required for proxy communication • For some reason, only this API uses a different version, and the data is transmitted in plaintext Phase3: Retrieves campaign update information from the C2 server • The latest proxy tool deployed
  16. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 15 TLP:

    CLEAR POST /client_v2/report/report-log Deeper Analysis - Updater ( Uphero.exe ) Phase 1 - BSides Tokyo 2026 {version=514E504E…} HTTP/1/1 200 OK {"code":200,"msg":"SUCCESS","data":null} POST /client_v2/report/win-log {version=514E504E…} POST /client_v1/config POST /client_v2/version/server {version=514E504E…} {"code":200,"msg":"SUCCESS","data":null} {mask=1234567890abcd…} {"code":200,"msg":"SUCCESS","data":……} {"code":200,"msg":"SUCCESS","data":……} HTTP/1/1 200 OK HTTP/1/1 200 OK HTTP/1/1 200 OK {. "code": 200, "msg": "SUCCESS", "data": null } version=514E504E504E52&platform=54&type=5154& app=0805120F&mask=0351590205590651530450030 206035105505651585056550354015555025957&uui d=3535292451245126225022224D525122594D54262 3504D225051574D215424212421525351255157&dis k_id=33051209010C2E150D020512&baseboard_id=& cpu_id=30120F030513130F122904505758222622262 65050585050265152&guid=56255822592624225452 2658542553542123552656592653252655535558235 5&net_mac=2D21232104041205131352585A51225A 52505A55525A54515A5553&imei=2D0F04050C24252 C2C1C2D010E150601031415120512210D0512090301 0E2D0507011412050E0413290E034E&data=0805011 21402050114 app=0805120F XOR by 0x60 app=6865726F ASCII app=hero #heartbeat ※ mask : A victim -specific identifier generated from system information.
  17. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 16 TLP:

    CLEAR POST /client_v2/report/report-log Deeper Analysis - Updater ( Uphero.exe ) Phase 2 - BSides Tokyo 2026 {version=514E504E…} HTTP/1/1 200 OK {"code":200,"msg":"SUCCESS","data":null} POST /client_v2/report/win-log {version=514E504E…} POST /client_v1/config POST /client_v2/version/server {version=514E504E…} {"code":200,"msg":"SUCCESS","data":null} {mask=1234567890abcd…} {"code":200,"msg":"SUCCESS","data":……} {"code":200,"msg":"SUCCESS","data":……} HTTP/1/1 200 OK HTTP/1/1 200 OK HTTP/1/1 200 OK { "code": 200, "msg": "SUCCESS", "data": { "china_ip_list": { "md5":(snip.)", ”url”(snip.)}, "china_domain_list": { "md5”(snip.) , "url”: (snip.)}, (snip.) }, (snip.) "http": { "server_addr": "89.187.169.66:1000", "limit": 0, "user_id": 19661396, (snip.) "sleep_time": 10, "key": 112, "keep_time": 25 }, (snip.) } mask=c19be9f13d0cbfc1e0618065c4a55b97&platfor m=4&version=1.2.1.0_8_hero • Fetch configuration required for the proxy tool ( hero.exe ) • The server response includes the proxy server IP address and port, as well as a single-byte XOR key used for communication encryption. • All data is transmitted in plaintext • possibly because the implementation was incomplete
  18. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 17 TLP:

    CLEAR POST /client_v2/report/report-log Deeper Analysis - Updater ( Uphero.exe ) Phase 3 - BSides Tokyo 2026 {version=514E504E…} HTTP/1/1 200 OK {"code":200,"msg":"SUCCESS","data":null} POST /client_v2/report/win-log {version=514E504E…} POST /client_v1/config POST /client_v2/version/server {version=514E504E…} {"code":200,"msg":"SUCCESS","data":null} {mask=1234567890abcd…} {"code":200,"msg":"SUCCESS","data":……} {"code":200,"msg":"SUCCESS","data":……} HTTP/1/1 200 OK HTTP/1/1 200 OK HTTP/1/1 200 OK { "code": 200, "msg": "SUCCESS", "data": { "id": 26, "version": "1.0.0.2", "update_msg": "up to 1.0.0.2", "platform": 4, "app": "hero", "update_type": 0, "download_url":"https:\/\/ update.7zip.com\/version\/ win-service\/1.0.0.2\/ autoupdate.xml", "created_at": "2026-01-04 18:06:58", "updated_at": "2026-01-04 18:07:08", ”app_package_name": "” } } version=514E504E504E52&platform=54&type=5154& app=0805120F&mask=0351590205590651530450030 206035105505651585056550354015555025957&uui d=3535292451245126225022224D525122594D54262 3504D225051574D215424212421525351255157&dis k_id=33051209010C2E150D020512&baseboard_id=& cpu_id=30120F030513130F122904505758222622262 65050585050265152&guid=56255822592624225452 2658542553542123552656592653252655535558235 5&net_mac=2D21232104041205131352585A51225A 52505A55525A54515A5553&imei=2D0F04050C24252 C2C1C2D010E150601031415120512210D0512090301 0E2D0507011412050E0413290E034E Updates the latest proxy tool and its service configuration.
  19. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 18 TLP:

    CLEAR Deeper Analysis - Proxy tool ( hero.exe ) - BSides Tokyo 2026 Ref. Beware of Fake 7zip Installer: upStage Proxy , https://blog.lukeacha.com/2026/01/beware-of-fake-7zip-installer-upstage.html Establishes a TCP connection to the target using configuration provided by the C2 server. Communication is XOR -encoded with a single byte key, and the tool relays traffic as a proxy.
  20. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 19 TLP:

    CLEAR Deeper Analysis - Proxy tunnel endpoint - BSides Tokyo 2026 https://platform.censys.io/search?q=host.autonomous_system.asn+%3D+%2260068%22+and+host.services.por t%3A+%7B999%2C+1300%2C+1301%7D&org=4dee09ba -f67f -460f -b1c9 -3a34a9b69c2b The proxy endpoints distributed by the C2 change frequently. Around 60 endpoints were identified through Censys .
  21. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 20 ©

    NTT DOCOMO BUSINESS, Inc. All Rights Reserved. Pivoting Across Similar Campaigns BSides Tokyo 2026 3
  22. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 21 TLP:

    CLEAR Similar Campaigns BSides Tokyo 2026 Highly similar endpoint structure Fake RocketApp Campaign (Inference) Binary similarities iShark VPN Campaign (Ongoing ) Wire VPN Campaign (Ongoing ) Identical PDB path Snaptik Campaign
  23. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 22 TLP:

    CLEAR Similar Campaign - Wire VPN - BSides Tokyo 2026 Highly similar endpoint structure Fake RocketApp Campaign (Inference) Binary similarities iShark VPN Campaign (Ongoing) Wire VPN Campaign (Ongoing ) Identical PDB path Snaptik Campaign
  24. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 23 TLP:

    CLEAR C2 server response (from uclscan.io ) BSides Tokyo 2026 Accessing the default page displays a message advertising the technical support service. Ref. URLScan , https://urlscan.io/result/019bc548-7f63-70e5-8a71-35a7ec7b14e4/
  25. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 24 TLP:

    CLEAR Search for servers returning the same response BSides Tokyo 2026
  26. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 25 TLP:

    CLEAR Search for servers returning the same response BSides Tokyo 2026 Potential API endpoint for VPN?
  27. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 26 TLP:

    CLEAR What is Wire VPN?? BSides Tokyo 2026 https://wirevpn.app Advertised as free VPN to use. VPN applications are available not only for Windows, but also on Google Play and the App Store.
  28. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 27 TLP:

    CLEAR Who operates this service? BSides Tokyo 2026 Appears to be sponsored by well -known companies
  29. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 28 TLP:

    CLEAR Who operates this service? BSides Tokyo 2026 Appears to be sponsored by well -known companies The operator and background are unclear!!
  30. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 29 TLP:

    CLEAR Wire VPN Campaign Infection Chain BSides Tokyo 2026 update.wirevpn.app wirevpn.app apiv3. wirevpn.app DnsPoliSvc.exe NetRpcSvc.exe NetRpcSvc.dll Wirevpn.exe %LOCALAPPDATA% \policysrv 1. Access landing website 2. Download 6. Update request WireVPN _ v1.0.X.Y.exe a 4. Drop VPN app. 5. Deploy proxy tools 7. Kich proxy tool 5. Fetch configuration and registration as node Load 8. Proxy operation Proxy endpoints (Port 1000 or 1002) Ref. Fake 7 -zip Operation( REPOST)
  31. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 30 TLP:

    CLEAR Wire VPN Campaign Infection Chain BSides Tokyo 2026 update.wirevpn.app wirevpn.app apiv3. wirevpn.app DnsPoliSvc.exe NetRpcSvc.exe NetRpcSvc.dll Wirevpn.exe %LOCALAPPDATA% \policysrv 1. Access landing website 2. Download 6. Update request WireVPN _ v1.0.X.Y.exe a 4. Drop VPN app. 5. Deploy proxy tools 7. Kich proxy tool 5. Fetch configuration and registration as node Load 8. Proxy operation Proxy endpoints (Port 1000 or 1002) Ref. Fake 7 -zip Operation( REPOST) TTPs are almost completely consistent
  32. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 31 TLP:

    CLEAR Code Similarities in DLL BSides Tokyo 2026 Over 90% similarity to the proxy module used in the Fake 7 -Zip campaign
  33. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 32 TLP:

    CLEAR Similar Campaign - iShark VPN - BSides Tokyo 2026 Highly similar endpoint structure Fake RocketApp Campaign (Inference) Binary similarities iShark VPN Campaign (Ongoing ) Wire VPN Campaign (Ongoing) Identical PDB path Snaptik Campaign
  34. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 33 TLP:

    CLEAR Patchwork implementation BSides Tokyo 2026 When starting a new campaign, they add new functionality on top of existing code using conditional branching . As a result, traces and hints from past operations remain in the codebase. Uphero.exe
  35. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 34 TLP:

    CLEAR What is “ iShark VPN” BSides Tokyo 2026 A free VPN available on multiple platforms, similar to Wire VPN, with an unknown operator. https://www.ishark.com
  36. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 35 TLP:

    CLEAR iShark VPN Campaign Infection Chain BSides Tokyo 2026 update.isharkvpn [.]com ishark [.]com api .isharkvpn [.]com HealthService.exe HealthSvc.exe HealthSvc.dll isharkVPN Lancher.exe C:\Windows \SysWOW64 \health 1. Access landing website 2. Download 6. Update request isharkVPN _ v1.0.0.X.exe a 4. Drop VPN app. 5. Deploy proxy tools 7. Kich proxy tool 5. Fetch configuration and registration as node Load 8. Proxy operation Proxy endpoints (Port 1000 or 1002) Ref. Wire VPN Operation( REPOST)
  37. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 36 TLP:

    CLEAR Similar Campaign – Snaptik - BSides Tokyo 2026 Highly similar endpoint structure Fake RocketApp Campaign (Inference) Binary similarities iShark VPN Campaign (Ongoing) Wire VPN Campaign (Ongoing) Identical PDB path Snaptik Campaign
  38. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 37 TLP:

    CLEAR Investigation of PDB path BSides Tokyo 2026 7zipInstall.exe upTiktok.exe This actor operates from the path ”D:\youqu_job ”. I also identified a “Snaptik” (related upTiktok.exe ) application using a nearly identical PDB path.”
  39. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 38 TLP:

    CLEAR Snaptik Campaign Infection Chain BSides Tokyo 2026 update.snaptik [.]io snaptik [.]io api.snaptik [.]io upTiktok.exe tiktok.exe tik.dll Snaptik.exe C:\Windows \SysWOW64 \tiktok 1. Access landing website 2. Download 6. Update request Snaptik_ v1.0.0.X.exe a 4. Drop snaptik app. 5. Deploy proxy tools 7. Kich proxy tool 5. Fetch configuration and registration as node Load 8. Proxy operation Proxy endpoints (Port 1000 or 1002)
  40. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 39 TLP:

    CLEAR [REPOST ] Similar Campaigns BSides Tokyo 2026 Highly similar endpoint structure Fake RocketApp Campaign (Inference) Binary similarities iShark VPN Campaign (Ongoing ) Wire VPN Campaign (Ongoing ) Identical PDB path Snaptik Campaign
  41. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 40 TLP:

    CLEAR [REPOST ] Similar Campaigns BSides Tokyo 2026 Highly similar endpoint structure Fake RocketApp Campaign (Inference) Binary similarities iShark VPN Campaign (Ongoing ) Wire VPN Campaign (Ongoing ) Identical PDB path Snaptik Campaign What is the background behind these campaigns?
  42. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 41 TLP:

    CLEAR Investigation of PE Signatures BSides Tokyo 2026 upTiktok.exe
  43. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 42 TLP:

    CLEAR Investigation of PE Signatures BSides Tokyo 2026 upTiktok.exe 911proxy.exe The code -signing certificate embedded in the PE file is reused by a proxy tool, 911proxy.exe
  44. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 43 TLP:

    CLEAR What is 911Proxy? BSides Tokyo 2026 https://www.911proxy.com Based on the website, 911Proxy service seems to mainly offer residential proxy
  45. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 44 TLP:

    CLEAR What is 911Proxy? BSides Tokyo 2026 https://www.911proxy.com Based on the website, 911Proxy service seems to mainly offer residential proxy The company name matches the PE signing certificate.
  46. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 45 TLP:

    CLEAR Residential Proxy Location BSides Tokyo 2026 The compromised hosts may be monetized as commercial residential proxy infrastructures.
  47. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 46 TLP:

    CLEAR BSides Tokyo 2026 The Residential Proxy Ecosystem Overview api.wirevpn.com api.isharkvpn.com api.7zip.cloud api.snaptik.io api…. Monetization Used for credit card abuse and cyber attacks Leverage proxy services operate L2 C2 server L1 C2 servers Residential proxy nodes
  48. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 47 ©

    NTT DOCOMO BUSINESS, Inc. All Rights Reserved. Wrap -up BSides Tokyo 2026 4
  49. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 48 TLP:

    CLEAR Limitation BSides Tokyo 2026 • As an ISP operator, we would like to take action against infected users, but currently have limited options • Unlike IoT botnets, compromised endpoints are not exposed at the Internet boundary . • One possible option is to use this service to identify compromised devices, however… • Giving attackers financial incentives is not a desirable approach • Generalizing countermeasures is difficult • In this case, avoiding suspicious applications is the main mitigation • However, residential proxies could also be deployed through today’s supply chain attacks
  50. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 49 TLP:

    CLEAR Summary BSides Tokyo 2026 • Deep dive into the Fake 7 -Zip campaign observed in Japan • This is only the tip of the iceberg of a much larger residential proxy • The VPN services introduced today are still available on app stores and remain part of an ongoing campaigns . • There is no silver bullet for mitigation • As practical measures, frequently used applications should be deployed by IT departments rather than individual users, and development environments should be isolated when possible I am looking for collaborators with new ideas for combating residential proxy incidents!!
  51. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. © NTT

    DOCOMO BUSINESS, Inc. All Rights Reserved. Thank you for listening! Your feedbacks are welcome!! ※ strinsert1Na BSides Tokyo 2026
  52. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 51 TLP:

    CLEAR Reference - 1 - BSides Tokyo 2026 [1]: Beware of Fake 7zip Installer: upStage Proxy, Security Magic https://blog.lukeacha.com/2026/01/beware -of-fake -7zip -installer -upstage.html [2]: Fake 7 -Zip downloads are turning home PCs into proxy nodes, Malwarebytes Labs https://www.malwarebytes.com/blog/threat -intel/2026/02/fake -7-zip -downloads -are - turning -home -pcs -into -proxy -nodes [3]:非公式7-Zip Web サイトにて公開されているインストーラによる不審なファイルの展開, wizSafe Security Siganal by IIJ https://wizsafe.iij.ad.jp/2026/01/2075/ [4]: When Open Source Is Weaponized: Analysis of a Trojanized 7 Zip Installer, DARKTRACE https://www.darktrace.com/blog/when -open -source -is-weaponized -analysis -of-a- trojanized -7-zip -installer
  53. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 52 TLP:

    CLEAR Reference - 2 - BSides Tokyo 2026 [5]: Wayback Machine, Internet Archive https://web.archive.org/web/20260123064211/https://www.7zip.com/api_v1 [6]: C2 (API) Server fingerprint, URLScan https://urlscan.io/result/019bc548 -7f63 -70e5 -8a71 -35a7ec7b14e4/ [7]: 911Proxy official website, https://www.911proxy.com
  54. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 53 TLP:

    CLEAR Appendix: YARA BSides Tokyo 2026 rule MAL_Residential_Proxy_Toolset_1 { meta: author = "Migawari" description = "Generic rule to detect the proxy tool associated with the Fake 7-Zip Installer campaign" strings: $str_service_wire = "hola" ascii wide nocase $str_service_ishark = "ishark" ascii wide nocase $str_api_path1 = /\/client_v[12]\/config/ ascii $str_api_path2 = /\/client_v[12]\/report/ ascii $str_api_path3 = /\/client_v[12]\/version\/server/ ascii $pdb1 = "D:\\youqu_job\\SuperBrowser" ascii wide nocase $pdb2 = "D:\\job\\jumpserver" ascii wide nocase condition: uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550 and (2 of ($str*) or any of ($pdb*)) }
  55. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 54 TLP:

    CLEAR Appendix: IoC (file hash -1-) BSides Tokyo 2026 Filename SHA -256 Details 7zipInstall.exe 408a89bc9966e76f3a192ecbf47b36fdc8ddaa4067aaee753c0bd6ae502f5cea Fake 7 -Zip installer 7zFM.exe fc10ff87b6fe2dcbeffe636c7a3ca85ce3da944c38c7ea08cd7e784c11fa0302 Proxy tool dropper Uphero.exe e7291095de78484039fdc82106d191bf41b7469811c4e31b4228227911d25027 Proxy tool updater hero.exe b7a7013b951c3cea178ece3363e3dd06626b9b98ee27ebfd7c161d0bbcfbd894 Main executable of the proxy tool hero.dll 3544ffefb2a38bf4faf6181aa4374f4c186d3c2a7b9b059244b65dce8d5688d9 Proxy tool module WireVpn_v1.0.1.5.exe 6d96a1b6db9ebff6370bbd97b369df10813028c5a7e04ed8d246d143d5beb1ae Wire VPN installer (Malicious) DnsPoliSvc.exe 69fb32f175dd127ea1c13ce40e21abc9508b919234c60f73a9c25ffa3919d92e Proxy tool updater NetRpcSvc.exe 5aee27902872be8b44ab80d2a31d6c11c44e25029b30a22fa7282b6a1597de6e Main executable of the proxy tool NetRpcSvc.dll b5ab9195b368f712a5571b3cce73f2c53802527c0087f63444959ae73a75c9ac Proxy tool module
  56. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 55 TLP:

    CLEAR Appendix: IoC (file hash -2-) BSides Tokyo 2026 Filename SHA -256 Details isharkVPN_v1.0.0.7.exe 2610f786fdc8239e752f49dd71c7c2587edb970c79de4a778577555f15213b7c ishark VPN installer (Malicious) HealthService.exe 90ac4b522bce556890668c6501662c4a3620693400beccf9fbce3098855750c6 Proxy tool updater HealthSvc.exe b081b90488e58af72e5defb13522d1ec08c150ddacb3cbdb2ffe94b3887be5ca Main executable of the proxy tool HealthSvc.dll 0407c290495c71899bac9e7f349e0025755f67268d18196d2d1f2ee9342f5b03 Proxy tool module Snaptik_v1.0.0.2.exe bd159754247191bda16d4972a4059ae70a94b23e84561dabe305205aaeeaa769 Snaptik installer (Malicious) upTiktok.exe 01d9c5bc992538e21ef2ad5f113e30e887f437c0eb16b1af0e426ecf3428ab7e Proxy tool updater tiktok.exe 0376d0e1f1d6614e6d9c03524d3e7a439e32d0ba2cc73ab2d35a1831ea293f71 Main executable of the proxy tool tik.dll 88a6751752b86e4dce3f506ec09b3575500437329ac40d388e5a271ac0011ea4 Proxy tool module
  57. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 56 TLP:

    CLEAR Appendix: IoC (C2 Servers) BSides Tokyo 2026 Domain Details api.7zip[.]cloud C2 domain of the Fake 7 -Zip campaign update.7zip[.]cloud Fake 7 -Zip installer distribution domain spark.herosms [.]io C2 domain of the Fake 7 -Zip campaign soc.hero -sms [.]co C2 domain of the Fake 7 -Zip campaign neo.herosms [.]co C2 domain of the Fake 7 -Zip campaign flux.smshero [.]co C2 domain of the Fake 7 -Zip campaign nova.smshero [.]ai C2 domain of the Fake 7 -Zip campaign zest.hero -sms [.]ai C2 domain of the Fake 7 -Zip campaign apex.herosms [.]ai C2 domain of the Fake 7 -Zip campaign mint.smshero [.]com C2 domain of the Fake 7 -Zip campaign vivid.smshero [.]vip C2 domain of the Fake 7 -Zip campaign Domain Details prime.herosms [.]vip C2 domain of the Fake 7 -Zip campaign glide.smshero [.]cc C2 domain of the Fake 7 -Zip campaign pulse.herosms [.]cc C2 domain of the Fake 7 -Zip campaign api.wirevpn [.]app C2 domain of the Wire VPN campaign apiv3.wirevpn[.]app C2 domain of the Wire VPN campaign update.wirevpn [.]app C2 domain of the Wire VPN campaign api.isharkvpn [.]com C2 domain of the ishark VPN campaign update.isharkvpn [.]com C2 domain of the ishark VPN campaign api.snaptik [.]io C2 domain of the Snaptik campaign update.snaptik [.]io C2 domain of the Snaptik campaign run.rocketapp [.]cc C2 domain of the related RocetApp campaign
  58. © NTT DOCOMO BUSINESS, Inc. All Rights Reserved. 57 TLP:

    CLEAR Appendix: IoC (Proxy endpoints) BSides Tokyo 2026 Endpoints for proxy tunnels (using ports 1000 or 1002) 79.127.221[.]41 84.17.37[.]1 84.17.41[.]55 84.17.56[.]87 212.102.42[.]15 156.146.44[.]218 79.127.221[.]47 84.17.37[.]3 84.17.41[.]56 84.17.56[.]88 212.102.42[.]16 156.146.44[.]223 79.127.221[.]56 84.17.37[.]4 84.17.41[.]57 84.17.56[.]89 212.102.42[.]17 156.146.44[.]224 79.127.221[.]57 84.17.37[.]5 84.17.41[.]58 84.17.56[.]90 212.102.42[.]21 156.146.44[.]226 79.127.221[.]58 84.17.37[.]8 84.17.41[.]59 84.17.56[.]91 212.102.42[.]22 156.146.44[.]229 79.127.221[.]59 84.17.37[.]49 84.17.41[.]64 84.17.56[.]95 212.102.42[.]23 156.146.44[.]230 79.127.241[.]51 84.17.37[.]50 84.17.41[.]72 84.17.56[.]236 212.102.42[.]36 156.146.44[.]239 169.150.255[.]33 84.17.37[.]51 89.187.169[.]66 156.146.44[.]213 212.102.42[.]41 156.146.44[.]240 169.150.255[.]38 84.17.37[.]52 89.187.169[.]78 156.146.44[.]215 212.102.42[.]43 156.146.44[.]244 169.150.255[.]50 84.17.37[.]53 89.187.169[.]90 156.146.44[.]216 212.102.42[.]228 138.199.12[.]70 169.150.255[.]51 195.181.170[.]79 95.173.197[.]212 156.146.44[.]217 212.102.42[.]232 ※ As of May 2026 Censys search query: host.autonomous_system.asn = "60068" and host.services.port: {999, 1300, 1301}