A cyber-espionage group identified as TAG-182, believed to be operating on behalf of the Iranian government, is actively distributing a surveillance tool known as MarkiRAT. This malware is being disseminated through fake applications designed to mimic legitimate services like VPNs and media players, with the apparent aim of collecting intelligence on Iranian targets both within and outside the country.
Researchers have observed TAG-182 utilizing social media platforms, particularly Instagram, to promote these deceptive applications. The group's activities are thought to have intensified following a period of reduced kinetic conflict involving Iran, the United States, and Israel. This shift in focus is seen as a redirection of Iranian security efforts towards enhanced cyber surveillance and digital enforcement against perceived dissidents and alleged foreign collaborators. The restoration of partial internet access in Iran on May 26, 2026, is also believed to be a factor in the increased activity.
The MarkiRAT malware itself has a history of being employed by a group previously tracked as Ferocious Kitten for surveillance operations targeting anti-government networks, activists, and human rights advocates within Iran. Analysis of new MarkiRAT samples associated with TAG-182 reveals significant overlaps in tradecraft with earlier variants. One notable similarity is the use of the Background Intelligent Transfer Service (BITS) for malicious purposes, a technique also observed in previous Ferocious Kitten campaigns.
TAG-182 has been observed creating dedicated websites to host and distribute these fake applications. One such application is named "YESHICA," with related samples found under the name "YEPlayer." Another lure identified is "Pis2ray VPN," which is not available on official app stores. In March 2026, researchers noted a new sample associated with TAG-182's infrastructure using the name "YESHICA YEPlayer," indicating a continued use of similar naming conventions despite previous exposure of their methods.
The infrastructure supporting TAG-182's operations includes a cluster of domains hosted on a server managed by 23M GmbH. Additional attacker-controlled assets are also hosted on servers provided by CrownCloud. The group predominantly uses Let's Encrypt certificates for its domains and employs a variety of naming conventions, often incorporating terms like "microsoft," "download," "vpn," "google," and names of social media entities to lend an air of legitimacy to their fake applications.
Initial access to a victim's system typically begins with a request to a compromised or attacker-controlled domain, such as vip.yeplayer.store, to download a malicious archive. Even if the website displays an error, the payload continues to be delivered, suggesting deliberate staging. Upon execution of the malware, such as YEPlayer.exe, it initiates communication with a command-and-control server, for example, microsotf.comi-site.website, using a POST request to upload data.
Further analysis of the malware reveals it attempts to disguise itself by creating a file named "svehost.exe," which mimics the legitimate Windows process "svchost.exe." This malicious file is often placed in the AppData\Windows directory, and the malware then removes the hidden file attribute to make it visible.
The researchers emphasize that TAG-182 is likely an integral part of Iran's broader surveillance apparatus. The group's focus on targeting Farsi-speaking communities, combined with the technical overlaps in malware and infrastructure, strongly suggests a direct connection to Iranian state-sponsored cyber operations. The ongoing nature of these operations is expected, particularly as Iranian authorities continue to prioritize digital surveillance for domestic security objectives.






