A report from Recorded Future’s Insikt Group details a campaign linked to an Iran-nexus threat cluster known as TAG-182, which is disseminating spyware through fake VPN and media player applications. This malware, identified as MarkiRAT, is designed to spy on users who install these applications, primarily targeting Iranian individuals both within and outside the country.
Researchers noted that the infrastructure for this campaign involves domains controlled by attackers, hosting applications that do not appear on established platforms like Google Play or Apple’s App Store. Two specific applications mentioned are Pis2ray VPN and a media player initially branded as YESHICA, which was renamed to YESHICA YEPlayer in March 2026 after scrutiny from researchers.
If users download and execute these files, they inadvertently install MarkiRAT, which acts as a remote access Trojan, giving control of the device to external parties. Analysts have reported that this malware can capture screenshots and upload them to servers operated by attackers, utilizing legitimate process names to avoid detection.
MarkiRAT exploits the BITS service in Windows, which is used for fetching updates, allowing it to download additional malicious files while masquerading as routine system maintenance. This stealthy behavior helps the malware evade standard security measures.
While Recorded Future has not specifically attributed TAG-182 to any particular Iranian agency, they place it within a wider array of state-aligned surveillance groups. MarkiRAT has been previously linked to Ferocious Kitten, a group noted by Kaspersky for conducting covert surveillance against activists in Iran.
The distribution of these fake apps primarily occurs via social media. Insikt Group observed promotions for Pis2ray VPN on Instagram in the aftermath of street protests in late 2025, and again during Iran’s internet shutdown, which partially ended on May 26, 2026. Users seeking virtual private networks during these critical times may be particularly vulnerable to downloading these malicious applications.




