- Recorded Future uncovered Iran-linked group spreading spyware
- Malware is distributed via fake VPN apps and media players
- Researchers believe most targets are Iranian users
A new report from Recorded Future’s Insikt Group describes a campaign that reverses the entire point of a privacy tool: fake VPN apps designed specifically to spy on the people who install them.
Researchers have linked new infrastructure to an Iran-linked threat group they track as TAG-182, which uses fake VPN and media player downloads to allegedly deliver a surveillance tool called MarkiRAT. It is “highly likely” that the group targets Iranians living inside and outside the country, the report said.
It’s a stark reminder that choosing one of The best VPN services are much more secure than downloading free, unapproved tools.
Fake apps, real surveillance
Insikt Group has identified a group of domains controlled by attackers that are allegedly used to organize the download of apps that do not appear anywhere on Google Play or the Apple App Store.
Two names stand out: Pis2ray VPN and a YESHICA-branded media player, which was quietly renamed YESHICA YEPlayer in March 2026 after researchers publicly exposed the original.
According to researchers, if you download and run one of these files, you get MarkiRAT, a remote access Trojan. Simply put, it is software that hands over control of your device to someone else.
A fake VPN app. A fake media player. Both provide Iranian government surveillance #malware to targeted dissidents. Insikt Group has new research on TAG-182 and MarkiRAT: #Cybersecurity pic.twitter.com/GwDyvGC99rJuly 2, 2026
Analysts documented this by capturing screenshots and uploading them to servers run by attackers, while disguising themselves under credible process names.
It also abuses BITS, the background service that Windows uses to fetch updates, to extract other files. Because this activity looks like ordinary system maintenance rather than an attack, it tends to escape routine cleanup.
MarkiRAT is not new. It has already been used by Ferocious Kitten, a group that Kaspersky has documented conducting years of covert surveillance against activists in Iran.
Recorded Future does not go so far as to attribute TAG-182 to any specific Iranian agency, but places it within a broader ecosystem of state-aligned surveillance groups.
Why a fake VPN is such an effective lure
Distribution is largely carried out via social networks. Insikt Group discovered posts on Instagram promoting Pis2ray VPN in the weeks following street protests in Iran in late 2025, and again around 2025. the country’s prolonged internet shutdown, which ended with partial restoration of access on May 26, 2026.
The people who most desperately need a virtual private network (VPN) in a censored country are exactly the ones who are most likely to install one from a social network link, because the official stores are often the ones they can’t reach.
Recorded Future considers it almost certain that most of the targets are located in Iran or linked to anti-government movements in Europe and North America. TechRadar has covered previous fake VPN campaigns linked to Iran, and this one appears to follow the same pattern with better infrastructure.
How to stay safe
Most readers will never be targeted by a state actor, but the underlying lesson gets through.
Install VPN apps only from official stores and verify that the provider has a real, verifiable presence outside the apps list.
Treat any VPN promoted via an Instagram post, Telegram channel, or direct message as suspicious, no matter how sophisticated it may be.
Star ratings are a weak signal because fake reviews are cheap.




