A new report from Recorded Future’s Insikt Group has uncovered a campaign involving an Iran-linked threat cluster that is distributing surveillance software through fake VPN and media player applications. The group, tracked as TAG-182, is using downloads of fake privacy tools to deliver a remote access Trojan called MarkiRAT, which effectively hands control of an infected device to the attackers. The report assesses that the group is “highly likely” targeting Iranian citizens living both inside and outside the country, exploiting the urgent need for online privacy and circumvention tools in a heavily censored environment.
The malicious applications identified in the campaign include a fake VPN called Pis2ray VPN and a media player branded as YESHICA, which was quietly renamed to YESHICA YEPlayer in March 2026 after researchers publicly exposed the original version. These apps do not appear on the Google Play Store or Apple’s App Store, and are instead distributed through attacker-controlled domains. Users who download and install these files receive the MarkiRAT Trojan, which is capable of capturing screenshots and uploading them to attacker-run servers, while disguising its activity under believable process names to avoid detection.
The malware also abuses BITS, the Background Intelligent Transfer Service that Windows uses to fetch updates, to pull down additional malicious files. Because this activity mimics ordinary system housekeeping rather than an overt attack, it tends to slip past routine security scans and cleanup efforts. MarkiRAT is not a new tool; it has previously been used by Ferocious Kitten, a group documented by Kaspersky as having conducted years of covert surveillance against activists inside Iran. While Recorded Future stops short of attributing TAG-182 to any specific Iranian agency, it places the group within a broader ecosystem of state-aligned surveillance operations.
The distribution of these fake apps runs largely through social media platforms. Insikt Group found Instagram posts promoting Pis2ray VPN in the weeks following street protests in Iran in late 2025, and again around the country’s prolonged internet shutdown, which ended with partial restoration of access on 26 May 2026. The researchers consider it almost certain that most targets are located in Iran or are tied to anti-government movements in Europe and North America. The people most desperate for a VPN in a censored country are exactly the people most likely to install one from a social media link, as official app stores are often inaccessible.
This campaign follows a pattern seen in previous Iran-linked fake VPN operations, but with improved infrastructure, according to TechRadar’s coverage. The report serves as a blunt reminder that choosing a reputable, verified VPN service is significantly more secure than downloading free, unvetted tools from unverified sources. Security experts advise that users should only install VPN apps from official stores and verify that the provider has a real, verifiable presence outside the app listing. Any VPN promoted through an Instagram post, Telegram channel, or direct message should be treated as suspect, regardless of how polished it appears, as star ratings and reviews can be easily faked.