• Iran-linked group caught hiding surveillance tools in fake apps

    From TechnologyDaily@1337:1/100 to All on Saturday, July 25, 2026 07:15:24
    Iran-linked group caught hiding surveillance tools in fake apps

    Date:
    Sat, 25 Jul 2026 06:00:00 +0000

    Description:
    Researchers at Recorded Future found evidence that an Iran-linked group is spreading MarkiRAT spyware through fake VPN and media player apps promoted on social media, targeting Farsi speakers worldwide.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Recorded Future found an Iran-linked group spreading spyware The malware is delivered through fake VPN and media player apps Researchers assess that most targets are Iranian users
    A new report from Recorded Future's Insikt Group describes a campaign that inverts the whole point of a privacy tool: fake VPN apps built specifically
    to spy on the people who install them.

    Researchers have linked fresh infrastructure to an Iran-nexus threat cluster they track as TAG-182, which is using fake VPN and media player downloads to allegedly deliver a surveillance tool called MarkiRAT. The group is "highly likely" to be targeting Iranians living inside and outside the country, the report says . It's a blunt reminder that choosing one of the best VPN
    services is a lot more secure than downloading free, unvetted tools. Fake apps, real surveillance Insikt Group identified a cluster of attacker-controlled domains allegedly used to stage downloads of applications that appear nowhere on Google Play or Apple's App Store.

    Two names stand out: Pis2ray VPN and a media player branded YESHICA, which
    was quietly renamed YESHICA YEPlayer in March 2026 after researchers publicly exposed the original. You may like Fake X-VPN installers found to spread credential-stealing malware here's how to stay safe Russian researcher
    claims state-backed MAX app secretly records users and monitors VPNs This dangerous 'CallPhantom' scam spread across 28 Google Play apps downloaded
    over 7 million times - here's what we know

    According to researchers, if you download and run one of these files, you get MarkiRAT, a remote access Trojan. In plain terms, that is software that hands control of your device to somebody else. A fake VPN app. A fake media player. Both delivering Iranian government surveillance #malware to targeted dissidents. Insikt Group has new research on TAG-182 and MarkiRAT:https://t.co/G7p9JO6peT#ThreatIntelligence #Cybersecurity pic.twitter.com/GwDyvGC99r July 2, 2026 Analysts have documented it capturing screenshots and uploading them to attacker-run servers, while disguising itself under believable process names.

    It also abuses BITS, the background service Windows uses to fetch updates, to pull down further files. Because that activity looks like ordinary system housekeeping rather than an attack, it tends to slip past routine cleanup.

    MarkiRAT is not new. It has previously been used by Ferocious Kitten, a group Kaspersky documented conducting years of covert surveillance against
    activists inside Iran.

    Recorded Future stops short of attributing TAG-182 to any specific Iranian agency, but places it within a broader ecosystem of state-aligned
    surveillance groups. What to read next Iranian hackers launch ransomware campaign looking to steal details via Microsoft Teams Iran-linked hackers claim massive FBI drone breach, threaten FPV attacks Huge hacking campaign uses spoofed Ghidra, dnSpy, and SpiderFoot security tools to harvest ad revenue and serve malware Today's best VPN deals NordVPN 2 Year 2.59 /mth
    View +3 months free Surfshark 24 Months 1.79 /mth View Proton VPN 24 Month 2.39 /mth View We check over 250 million products every day for the best prices Why a fake VPN makes such an effective lure Distribution runs largely through social media. Insikt Group found Instagram posts promoting Pis2ray
    VPN in the weeks following street protests in Iran in late 2025, and again around the country's prolonged internet shutdown , which ended with partial restoration of access on 26 May 2026.

    The people most desperate for a virtual private network (VPN) in a censored country are exactly the people most likely to install one from a social media link, because the official stores are often the very thing they cannot reach.

    Recorded Future considers it almost certain that most targets are located in Iran or tied to anti-government movements in Europe and North America. TechRadar has covered previous Iran-linked fake VPN campaigns , and this one seems to follow the same pattern with better infrastructure. How to stay safe Most readers will never be targeted by a state actor, but the underlying lesson travels.

    Install VPN apps only from official stores, and check that the provider has a real, verifiable presence outside the app listing.

    Treat any VPN promoted through an Instagram post, a Telegram channel, or a direct message as suspect, however polished it looks.

    Star ratings are a weak signal, since fake reviews are cheap. Follow
    TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!



    ======================================================================
    Link to news story: https://www.techradar.com/vpn/vpn-privacy-security/iran-linked-group-caught-hi ding-surveillance-tools-in-fake-apps


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)