Iran-linked group caught hiding surveillance tools in fake apps
Recorded Future found an Iran-linked group spreading spyware The malware is delivered through fake VPN and media player apps Researchers assess that most targets are Iranian users A new report from Recorded Future's Insikt Group describes a campaign that inverts the whole point of a privacy tool: fa
<![CDATA[ <article> <ul><li><strong>Recorded Future found an Iran-linked group spreading spyware</strong></li><li><strong>The malware is delivered through fake VPN and media player apps</strong></li><li><strong>Researchers assess that most targets are Iranian users</strong></li></ul><p>A new report from <a href="https://www.recordedfuture.com/research/nexus-tag182-disseminates-markirat" target="_blank" rel="nofollow">Recorded Future's Insikt Group</a> describes a campaign that inverts the whole point of a privacy tool: fake VPN apps built specifically to spy on the people who install them.</p><p>Researchers have linked fresh infrastructure to an Iran-nexus threat cluster they track as TAG-182, which is using fake VPN and media player downloads to allegedly deliver a surveillance tool called MarkiRAT. The group is "highly likely" to be targeting Iranians living inside and outside the country, <a href="https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-ir-2026-0701.pdf" target="_blank" rel="nofollow">the report says</a>.</p><p>It's a blunt reminder that choosing one of the <a href="https://www.techradar.com/vpn/best-vpn" target="_blank" rel="nofollow">best VPN</a> services is a lot more secure than downloading free, unvetted tools.</p><h2 id="fake-apps-real-surveillance">Fake apps, real surveillance</h2><p>Insikt Group identified a cluster of attacker-controlled domains allegedly used to stage downloads of applications that appear nowhere on Google Play or Apple's App Store. </p><p>Two names stand out: Pis2ray VPN and a media player branded YESHICA, which was quietly renamed YESHICA YEPlayer in March 2026 after researchers publicly exposed the original.</p><p>According to researchers, if you download and run one of these files, you get MarkiRAT, a remote access Trojan. In plain terms, that is software that hands control of your device to somebody else. </p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">A fake VPN app. A fake media player. Both delivering Iranian government surveillance #malware to targeted dissidents. Insikt Group has new research on TAG-182 and MarkiRAT:https://t.co/G7p9JO6peT#ThreatIntelligence #Cybersecurity pic.twitter.com/GwDyvGC99r<a href="https://twitter.com/cantworkitout/status/2072720755884695924">July 2, 2026</a></p></blockquote><div class="see-more__filter"></div></div><p>Analysts have documented it capturing screenshots and uploading them to attacker-run servers, while disguising itself under believable process names.</p><p>It also abuses BITS, the background service Windows uses to fetch updates, to pull down further files. Because that activity looks like ordinary system housekeeping rather than an attack, it tends to slip past routine cleanup.</p><p>MarkiRAT is not new. It has previously been used by Ferocious Kitten, a group <a href="https://securelist.com/ferocious-kitten-6-years-of-covert-surveillance-in-iran/102806/" target="_blank" rel="nofollow">Kaspersky</a> documented conducting years of covert surveillance against activists inside Iran. </p><p>Recorded Future stops short of attributing TAG-182 to any specific Iranian agency, but places it within a broader ecosystem of state-aligned surveillance groups.</p><h2 id="why-a-fake-vpn-makes-such-an-effective-lure">Why a fake VPN makes such an effective lure</h2><p>Distribution runs largely through social media. Insikt Group found Instagram posts promoting Pis2ray VPN in the weeks following street protests in Iran in late 2025, and again around the <a href="https://www.techradar.com/vpn/vpn-privacy-security/the-internet-is-not-connected-irans-88-day-blackout-begins-to-lift-but-traffic-remains-under-50-percent">country's prolonged internet shutdown</a>, which ended with partial restoration of access on 26 May 2026.</p><p>The people most desperate for a <a href="https://www.techradar.com/vpn/virtual-private-networks">virtual private network (VPN)</a> in a censored country are exactly the people most likely to install one from a social media link, because the official stores are often the very thing they cannot reach. </p><p>Recorded Future considers it almost certain that most targets are located in Iran or tied to anti-government movements in Europe and North America. TechRadar has covered <a href="https://www.techradar.com/vpn/vpn-privacy-security/beware-iran-linked-fake-vpn-apps-found-to-spy-on-android-users" target="_blank" rel="nofollow">previous Iran-linked fake VPN campaigns</a>, and this one seems to follow the same pattern with better infrastructure.</p><h2 id="how-to-stay-safe">How to stay safe</h2><p>Most readers will never be targeted by a state actor, but the underlying lesson travels. </p><p>Install VPN apps only from official stores, and check that the provider has a real, verifiable presence outside the app listing. </p><p>Treat any VPN promoted through an Instagram post, a Telegram channel, or a direct message as suspect, however polished it looks. </p><p>Star ratings are a weak signal, since fake reviews are cheap.</p> </article> ]]>
Read the full article on TechRadar
Read Full Article →