• Recorded Future found an Iran-linked group spreading spyware
  • The malware is delivered through fake VPN and media player apps
  • Researchers assess that most targets are Iranian users

A new report from Recorded Future's Insikt Group describes a campaign that inverts the whole point of a privacy tool: fake VPN apps built specifically to spy on the people who install them.

Researchers have linked fresh infrastructure to an Iran-nexus threat cluster they track as TAG-182, which is using fake VPN and media player downloads to allegedly deliver a surveillance tool called MarkiRAT. The group is "highly likely" to be targeting Iranians living inside and outside the country, the report says.

It's a blunt reminder that choosing one of the best VPN services is a lot more secure than downloading free, unvetted tools.

Fake apps, real surveillance

Insikt Group identified a cluster of attacker-controlled domains allegedly used to stage downloads of applications that appear nowhere on Google Play or Apple's App Store.

Two names stand out: Pis2ray VPN and a media player branded YESHICA, which was quietly renamed YESHICA YEPlayer in March 2026 after researchers publicly exposed the original.

According to researchers, if you download and run one of these files, you get MarkiRAT, a remote access Trojan. In plain terms, that is software that hands control of your device to somebody else.

Analysts have documented it capturing screenshots and uploading them to attacker-run servers, while disguising itself under believable process names.

It also abuses BITS, the background service Windows uses to fetch updates, to pull down further files. Because that activity looks like ordinary system housekeeping rather than an attack, it tends to slip past routine cleanup.

MarkiRAT is not new. It has previously been used by Ferocious Kitten, a group Kaspersky documented conducting years of covert surveillance against activists inside Iran.

Recorded Future stops short of attributing TAG-182 to any specific Iranian agency, but places it within a broader ecosystem of state-aligned surveillance groups.

Why a fake VPN makes such an effective lure

Distribution runs largely through social media. Insikt Group found Instagram posts promoting Pis2ray VPN in the weeks following street protests in Iran in late 2025, and again around the country's prolonged internet shutdown, which ended with partial restoration of access on 26 May 2026.

The people most desperate for a virtual private network (VPN) in a censored country are exactly the people most likely to install one from a social media link, because the official stores are often the very thing they cannot reach.

Recorded Future considers it almost certain that most targets are located in Iran or tied to anti-government movements in Europe and North America. TechRadar has covered previous Iran-linked fake VPN campaigns, and this one seems to follow the same pattern with better infrastructure.

How to stay safe

Most readers will never be targeted by a state actor, but the underlying lesson travels.

Install VPN apps only from official stores, and check that the provider has a real, verifiable presence outside the app listing.

Treat any VPN promoted through an Instagram post, a Telegram channel, or a direct message as suspect, however polished it looks.

Star ratings are a weak signal, since fake reviews are cheap.

Monica is a tech journalist with over a decade of experience. She writes about the latest developments in computing, which means anything from computer chips made out of paper to cutting-edge desktop processors.

GPUs are her main area of interest, and nothing thrills her quite like that time every couple of years when new graphics cards hit the market.

She built her first PC nearly 20 years ago, and dozens of builds later, she’s always planning out her next build (or helping her friends with theirs). During her career, Monica has written for many tech-centric outlets, including Digital Trends, SlashGear, WePC, and Tom’s Hardware.