Iran Linked Spyware Campaign Uses Fake VPN Apps to Target Privacy Seeking Users

Share

- Advertisement -
  • Researchers uncovered an Iran linked campaign distributing MarkiRAT spyware through fake VPN and media player applications.
  • The malicious apps are hosted outside official app stores and provide attackers with persistent access to infected devices.
  • Social media promotions reportedly targeted users seeking VPNs during internet restrictions and political unrest in Iran.
  • Experts recommend downloading VPN software only from trusted sources and avoiding unofficial links shared through social platforms.

People often turn to VPNs to protect their privacy, especially during periods of internet censorship or political unrest. That trust is exactly what a newly uncovered cyber campaign appears to exploit. Security researchers have identified a fresh operation that disguises surveillance malware inside fake VPN and media player applications, turning privacy tools into powerful spying platforms.

According to researchers at Recorded Future’s Insikt Group, the campaign is linked to a threat cluster known as TAG 182. The operation allegedly targets Iranian users both inside the country and abroad by distributing malicious software through unofficial downloads rather than trusted app stores.

The findings once again highlight a simple but important cybersecurity lesson. Downloading software from unofficial sources, particularly security related tools such as VPNs, can expose users to far greater risks than the problems they are trying to avoid.

Fake VPN apps become powerful surveillance tools

The researchers discovered several attacker controlled websites hosting applications that imitate legitimate software. Among the identified programs were a fake VPN application called Pis2ray VPN and a media player branded YESHICA, which was later renamed YESHICA YEPlayer after earlier versions attracted public attention.

Unlike legitimate applications available through Google Play or Apple’s App Store, these downloads were hosted on external websites. Anyone installing them unknowingly deployed a remote access Trojan known as MarkiRAT.

Once active, MarkiRAT reportedly gives attackers extensive control over an infected device. Researchers observed the malware taking screenshots, collecting system information, and secretly sending captured data to attacker controlled servers. To reduce suspicion, it disguises its activity by using process names that resemble legitimate Windows services.

- Advertisement -

The malware also makes use of the Windows Background Intelligent Transfer Service, commonly known as BITS. Since Windows relies on this service for downloading updates and transferring files in the background, malicious activity can blend into normal system operations, making detection significantly more difficult.

Although MarkiRAT has been documented before, researchers say the latest campaign demonstrates that the malware remains an active surveillance tool with improved delivery methods and supporting infrastructure.

Social media plays a key role in spreading malware

One of the most notable aspects of this campaign is how victims are lured into downloading the fake software. Instead of relying on traditional phishing emails, the attackers reportedly promoted the applications through social media platforms.

Researchers found Instagram posts advertising the fake VPN around periods of heightened political tension in Iran, including demonstrations during late 2025 and extended internet disruptions that continued into 2026.

This timing appears carefully chosen. During internet restrictions, many people urgently search for VPN services to regain access to blocked websites and communication platforms. Official app stores may also become difficult to access, making users more willing to trust download links shared through social media or messaging platforms.

Cybersecurity experts believe this creates an ideal opportunity for threat actors. Individuals looking for secure communication tools are often forced into downloading software from unfamiliar sources, unknowingly installing surveillance malware instead.

- Advertisement -

Recorded Future believes the campaign primarily targets users inside Iran, although members of Iranian communities living in Europe and North America may also be at risk, particularly those associated with opposition movements or activist groups.

The campaign reflects a broader pattern of cyber surveillance

While researchers stopped short of directly attributing the operation to a specific Iranian government agency, they believe TAG 182 operates within a wider ecosystem of Iran aligned surveillance groups.

MarkiRAT itself has previously been associated with the threat actor commonly referred to as Ferocious Kitten, a group that cybersecurity researchers have linked to years of digital surveillance targeting activists, journalists, and politically sensitive individuals.

The latest findings suggest that surveillance operations continue to evolve by combining familiar malware with improved infrastructure and more convincing social engineering techniques. Instead of relying solely on technical exploits, attackers increasingly exploit human behavior and moments of heightened urgency.

This approach makes campaigns harder to stop because victims often install the malicious software voluntarily, believing they are protecting themselves.

How users can reduce their risk

Although campaigns like this tend to focus on specific regions and communities, the underlying tactics can affect anyone. Fake applications remain one of the most common methods for distributing malware worldwide.

- Advertisement -

Users should install VPN software only from official app stores or directly from well established providers with a verified reputation. Any VPN promoted through unsolicited social media posts, direct messages, or unofficial websites should be treated with caution.

Checking whether an application has a legitimate developer, consistent update history, independent security reviews, and a transparent company presence can also help separate trustworthy software from malicious imitations.

Finally, users should remember that high ratings and positive reviews alone are not proof of legitimacy. Fake reviews remain inexpensive and easy for attackers to generate, making independent verification far more valuable than popularity scores.

Follow TechBSB For More Updates

- Advertisement -
Emily Parker
Emily Parker
Emily Parker is a seasoned tech consultant with a proven track record of delivering innovative solutions to clients across various industries. With a deep understanding of emerging technologies and their practical applications, Emily excels in guiding businesses through digital transformation initiatives. Her expertise lies in leveraging data analytics, cloud computing, and cybersecurity to optimize processes, drive efficiency, and enhance overall business performance. Known for her strategic vision and collaborative approach, Emily works closely with stakeholders to identify opportunities and implement tailored solutions that meet the unique needs of each organization. As a trusted advisor, she is committed to staying ahead of industry trends and empowering clients to embrace technological advancements for sustainable growth.

Read More

Trending Now