- Recorded Future Found Iran-Linked Group Spreading Spyware
- Malware is distributed via fake media player and VPN apps
- Researchers assess that most of the targets are Iranian users
A new report from Recorded Future’s Insikt Group describes a campaign that turns the entire point of a privacy tool on its head: fake VPN apps created specifically to spy on the people who install them.
Researchers have linked new infrastructure to an Iran nexus threat group they track as TAG-182, which uses fake downloads from VPNs and media players to supposedly deliver a surveillance tool called MarkiRAT. The group is “very likely” to target Iranians living inside and outside the country, the report says.
It is a clear reminder that choosing one of the The best VPN services are much safer than downloading free and unauthorized tools.
Fake apps, real surveillance
Insikt Group identified a group of attacker-controlled domains allegedly used to perform app downloads that do not appear anywhere on Google Play or Apple’s App Store.
Two names stand out: Pis2ray VPN and a YESHICA-branded media player, which was quietly renamed YESHICA YEPlayer in March 2026 after researchers publicly exposed the original.
According to researchers, if you download and run one of these files, you get MarkiRAT, a remote access Trojan. In simple terms, this is software that hands control of your device to someone else.
A fake VPN app. A fake media player. Both deliver Iranian government surveillance #malware to targeted dissidents. Insikt Group has new research on TAG-182 and MarkiRAT: #Cybersecurity pic.twitter.com/GwDyvGC99rJuly 2, 2026
Analysts have documented this by capturing screenshots and uploading them to attacker-managed servers, while disguising itself under credible process names.
It also abuses BITS, the background service that Windows uses to check for updates and extract more files. Because that activity looks like ordinary system cleanup rather than an attack, it tends to miss routine cleanup.
MarkiRAT is not new. It has previously been used by Ferocious Kitten, a group that Kaspersky documented conducting years of covert surveillance against activists inside Iran.
Recorded Future stops short of attributing TAG-182 to any specific Iranian agency, but places it within a broader ecosystem of state-aligned surveillance groups.
Why a fake VPN is such an effective decoy
Distribution is largely done through social media. Insikt Group found posts on Instagram promoting Pis2ray VPN in the weeks following street protests in Iran at the end of 2025, and again around the world. the prolonged Internet shutdown in the country, which ended with the partial restoration of access on May 26, 2026.
The people most desperate for a virtual private network (VPN) in a censored country are exactly the people most likely to install one from a social network link, because official stores are often the place they can’t access it.
Recorded Future considers it almost certain that most of the targets are located in Iran or linked to anti-government movements in Europe and North America. TechRadar has covered previous fake VPN campaigns linked to Iran, and this one appears to follow the same pattern with better infrastructure.
How to stay safe
Most readers will never be the target of a state actor, but the underlying lesson travels.
Install VPN apps only from official stores and verify that the provider has a real, verifiable presence outside of the app list.
Treat any VPN promoted through an Instagram post, Telegram channel, or direct message as suspicious, no matter how polished it may seem.
Star ratings are a weak signal as fake reviews are cheap.




