LIVE · cybersecurity feed
Live wire
iranhigh

Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool

A threat group linked to Iran, known as TAG-182, is actively distributing a surveillance tool called MarkiRAT. This malware is being spread through fake applications disguised as VPNs and download tools, primarily targeting Iranian citizens both within and outside the country. The operations appear to be conducted via social media platforms and are likely part of Iran's intensified cyber surveillance efforts.

zeroday.news · 31d ago

A cyber-espionage group identified as TAG-182, believed to be operating on behalf of the Iranian government, is actively distributing a surveillance tool known as MarkiRAT. This malware is being disseminated through fake applications designed to mimic legitimate services like VPNs and media players, with the apparent aim of collecting intelligence on Iranian targets both within and outside the country.

Researchers have observed TAG-182 utilizing social media platforms, particularly Instagram, to promote these deceptive applications. The group's activities are thought to have intensified following a period of reduced kinetic conflict involving Iran, the United States, and Israel. This shift in focus is seen as a redirection of Iranian security efforts towards enhanced cyber surveillance and digital enforcement against perceived dissidents and alleged foreign collaborators. The restoration of partial internet access in Iran on May 26, 2026, is also believed to be a factor in the increased activity.

The MarkiRAT malware itself has a history of being employed by a group previously tracked as Ferocious Kitten for surveillance operations targeting anti-government networks, activists, and human rights advocates within Iran. Analysis of new MarkiRAT samples associated with TAG-182 reveals significant overlaps in tradecraft with earlier variants. One notable similarity is the use of the Background Intelligent Transfer Service (BITS) for malicious purposes, a technique also observed in previous Ferocious Kitten campaigns.

TAG-182 has been observed creating dedicated websites to host and distribute these fake applications. One such application is named "YESHICA," with related samples found under the name "YEPlayer." Another lure identified is "Pis2ray VPN," which is not available on official app stores. In March 2026, researchers noted a new sample associated with TAG-182's infrastructure using the name "YESHICA YEPlayer," indicating a continued use of similar naming conventions despite previous exposure of their methods.

The infrastructure supporting TAG-182's operations includes a cluster of domains hosted on a server managed by 23M GmbH. Additional attacker-controlled assets are also hosted on servers provided by CrownCloud. The group predominantly uses Let's Encrypt certificates for its domains and employs a variety of naming conventions, often incorporating terms like "microsoft," "download," "vpn," "google," and names of social media entities to lend an air of legitimacy to their fake applications.

Initial access to a victim's system typically begins with a request to a compromised or attacker-controlled domain, such as vip.yeplayer.store, to download a malicious archive. Even if the website displays an error, the payload continues to be delivered, suggesting deliberate staging. Upon execution of the malware, such as YEPlayer.exe, it initiates communication with a command-and-control server, for example, microsotf.comi-site.website, using a POST request to upload data.

Further analysis of the malware reveals it attempts to disguise itself by creating a file named "svehost.exe," which mimics the legitimate Windows process "svchost.exe." This malicious file is often placed in the AppData\Windows directory, and the malware then removes the hidden file attribute to make it visible.

The researchers emphasize that TAG-182 is likely an integral part of Iran's broader surveillance apparatus. The group's focus on targeting Farsi-speaking communities, combined with the technical overlaps in malware and infrastructure, strongly suggests a direct connection to Iranian state-sponsored cyber operations. The ongoing nature of these operations is expected, particularly as Iranian authorities continue to prioritize digital surveillance for domestic security objectives.

iranespionagemalwaresurveillanceandroid
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.