Index  ›  world  ›  TechRadar
world · TechRadar ↗

Iran-linked group caught hiding surveillance tools in fake apps

TechRadar Published Jul 25, 2026 Reviewed Jul 25, 2026 ✓ Reviewed by citations.press editors
Iran-linked group caught hiding surveillance tools in fake apps
Insikt Group documented Instagram posts promoting Pis2ray VPN in the weeks following street protests in Iran in late 2025 and again around Iran’s prolonged internet shutdown, which ended with partial restoration of access on 26 May 2026.
Recorded Future’s Insikt Group linked fresh infrastructure to an Iran-nexus threat cluster they track as TAG-182, which is using fake VPN and media player downloads to allegedly deliver MarkiRAT surveillance malware.
MarkiRAT, a remote access Trojan previously used by Ferocious Kitten, captures screenshots and uploads them to attacker-run servers while disguising itself under believable process names and abuses Windows BITS to download additional payloads.
Insikt Group identified fake VPN app Pis2ray VPN and media player YESHICA (renamed YESHICA YEPlayer in March 2026) as delivery mechanisms for the MarkiRAT surveillance tool, which is designed to grant remote access to attackers.

A new report from Recorded Future's Insikt Group describes a campaign that inverts the whole point of a privacy tool: fake VPN apps built specifically to spy on the people who install them.

Researchers have linked fresh infrastructure to an Iran-nexus threat cluster they track as TAG-182, which is using fake VPN and media player downloads to allegedly deliver a surveillance tool called MarkiRAT. The group is "highly likely" to be targeting Iranians living inside and outside the country, the report says.

It's a blunt reminder that choosing one of the best VPN services is a lot more secure than downloading free, unvetted tools.

Insikt Group identified a cluster of attacker-controlled domains allegedly used to stage downloads of applications that appear nowhere on Google Play or Apple's App Store.

Two names stand out: Pis2ray VPN and a media player branded YESHICA, which was quietly renamed YESHICA YEPlayer in March 2026 after researchers publicly exposed the original.

According to researchers, if you download and run one of these files, you get MarkiRAT, a remote access Trojan. In plain terms, that is software that hands control of your device to somebody else.

A fake VPN app. A fake media player. Both delivering Iranian government surveillance #malware to targeted dissidents. Insikt Group has new research on TAG-182 and MarkiRAT:https://t.co/G7p9JO6peT#ThreatIntelligence #Cybersecurity pic.twitter.com/GwDyvGC99rJuly 2, 2026

Analysts have documented it capturing screenshots and uploading them to attacker-run servers, while disguising itself under believable process names.

It also abuses BITS, the background service Windows uses to fetch updates, to pull down further files. Because that activity looks like ordinary system housekeeping rather than an attack, it tends to slip past routine cleanup.

MarkiRAT is not new. It has previously been used by Ferocious Kitten, a group Kaspersky documented conducting years of covert surveillance against activists inside Iran.

Recorded Future stops short of attributing TAG-182 to any specific Iranian agency, but places it within a broader ecosystem of state-aligned surveillance groups.

Distribution runs largely through social media. Insikt Group found Instagram posts promoting Pis2ray VPN in the weeks following street protests in Iran in late 2025, and again around the country's prolonged internet shutdown, which ended with partial restoration of access on 26 May 2026.

The people most desperate for a virtual private network (VPN) in a censored country are exactly the people most likely to install one from a social media link, because the official stores are often the very thing they cannot reach.

Recorded Future considers it almost certain that most targets are located in Iran or tied to anti-government movements in Europe and North America. TechRadar has covered previous Iran-linked fake VPN campaigns, and this one seems to follow the same pattern with better infrastructure.

Most readers will never be targeted by a state actor, but the underlying lesson travels.

Install VPN apps only from official stores, and check that the provider has a real, verifiable presence outside the app listing.

Treat any VPN promoted through an Instagram post, a Telegram channel, or a direct message as suspect, however polished it looks.

Star ratings are a weak signal, since fake reviews are cheap.

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

Monica is a tech journalist with over a decade of experience. She writes about the latest developments in computing, which means anything from computer chips made out of paper to cutting-edge desktop processors.

GPUs are her main area of interest, and nothing thrills her quite like that time every couple of years when new graphics cards hit the market.

She built her first PC nearly 20 years ago, and dozens of builds later, she’s always planning out her next build (or helping her friends with theirs). During her career, Monica has written for many tech-centric outlets, including Digital Trends, SlashGear, WePC, and Tom’s Hardware.

Please logout and then login again, you will then be prompted to enter your display name.

This article was originally published by TechRadar ↗. citations.press indexes the source-backed facts above and links to the original. Something wrong? Corrections policy · Report an error