- Recorded Future found an Iran-linked group spreading spyware
- The malware is delivered through fake VPN and media player apps
- Researchers estimate that most targets are Iranian users
A new report from Recorded Futures Insikt Group describes a campaign that turns the whole point of a privacy tool on its head: fake VPN apps built specifically to spy on the people who install them.
Researchers have linked new infrastructure to an Iran-nexus threat cluster they track as TAG-182, which uses fake VPN and media player downloads to allegedly deliver a surveillance tool called MarkiRAT. The group is “highly likely” to target Iranians living inside and outside the country, the report said.
It is a sharp reminder that you choose one of them best VPN services are much safer than downloading free, uncontrolled tools.
Fake apps, real surveillance
Insikt Group identified a cluster of hacker-controlled domains allegedly used to stage downloads of applications that do not appear anywhere on Google Play or Apple’s App Store.
Two names stand out: Pis2ray VPN and a media player branded YESHICA, which was quietly renamed YESHICA YEPlayer in March 2026 after researchers publicly revealed the original.
According to researchers, if you download and run one of these files, you get MarkiRAT, a remote access Trojan. In short, it is software that gives control of your device to someone else.
A fake VPN app. A fake media player. Both deliver Iranian government surveillance #malware to targeted dissidents. Insikt Group has new research on TAG-182 and MarkiRAT: #Cybersecurity pic.twitter.com/GwDyvGC99r2 July 2026
Analysts have documented that it takes screenshots and uploads them to attacker-run servers while hiding under credible process names.
It also abuses BITS, the background service Windows uses to download updates, to download additional files. Because that activity looks like general system housekeeping rather than an attack, it tends to slip past routine cleanup.
MarkiRAT is not new. It has previously been used by Ferocious Kitten, a group Kaspersky documented as conducting years of covert surveillance against activists in Iran.
Recorded Future stops short of attributing TAG-182 to a specific Iranian agency, but places it within a broader ecosystem of government surveillance groups.
Why a fake VPN is such an effective decoy
Distribution takes place to a large extent via social media. Insikt Group found Instagram posts promoting Pis2ray VPN in the weeks following street protests in Iran in late 2025, and again around the country’s prolonged internet shutdown, which ended with partial restoration of access on May 26, 2026.
The people most desperate for a virtual private network (VPN) in a censored country are exactly the people most likely to install one from a social media link, because the official stores are often just what they can’t reach.
Recorded Future considers it almost certain that most targets are located in Iran or tied to anti-government movements in Europe and North America. TechRadar has covered previous Iran-linked fake VPN campaigns, and this one seems to follow the same pattern with better infrastructure.
How to stay safe
Most readers will never be hit by a state actor, but the underlying lesson travels.
Only install VPN apps from official stores and verify that the provider has a real, verifiable presence outside of the app list.
Treat any VPN promoted through an Instagram post, Telegram channel, or direct message as suspicious, no matter how polished it looks.
Star ratings are a weak signal as fake reviews are cheap.



