TAG-182 Deploys MarkiRAT in Escalating Iranian Surveillance Campaigns
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Downloader,Dropper,Malware,RAT,Spyware,Baiting,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/High Probability
Threat Overview
The Iran-nexus threat cluster TAG-182 is actively disseminating MarkiRAT malware to conduct digital surveillance against Iranian citizens, dissidents, and anti-government networks located in Iran, Europe, and North America. Capitalizing on Iran's recent internet restoration, the group distributes the malware by disguising it as legitimate applications, such as fake VPNs and media players, promoted through Farsi-language social media lures. TAG-182 utilizes infrastructure masking as well-known tech services to facilitate command and control. These operations are highly likely part of a broader Iranian state-sponsored initiative involving multiple security organizations aimed at suppressing domestic unrest and monitoring civil society sectors through intensified cyber espionage.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Dissident | Verified |
| Region | Iran | Verified |
Extracted IOCs
- com-accounts[.]website
- come-signin[.]quest
- comesignt[.]website
- comestore[.]site
- comisignin[.]online
- comx-view[.]store
- migavpn[.]store
- orbitx[.]site
- pis2ray[.]online
- sahar2ray[.]online
- yemplayer[.]site
- yeplayer[.]store
- accountes.google.comesignt[.]website
- accounts.google.comisignin[.]online
- admin.google.com-accounts[.]website
- admin.instagram.com-accounts[.]website
- c.pis2ray[.]online
- download.yeplayer[.]store
- google.com-accounts[.]website
- google.comisignin[.]online
- google.com-signin[.]site
- host.comview[.]website
- microsoft.come-site[.]website
- microsoft.comesite[.]website
- microsoft.comi-site[.]website
- microsoft.comview[.]website
- microsoft.pis2ray[.]online
- microsotf.comi-site[.]website
- miga.comesignt[.]website
- min.come-site[.]website
- min.comi-site[.]website
- min.comview[.]website
- min.pis2ray[.]online
- ns1.com-signin[.]site
- ns2.com-signin[.]site
- prx.pis2ray[.]online
- starvpn.pis2ray[.]online
- svpn.pis2ray[.]online
- tools.sahar2ray[.]online
- vip.yeplayer[.]store
- vpn.pis2ray[.]online
- webmail.com-accounts[.]website
- webmail.facebook.com-accounts[.]website
- webmail.google.com-accounts[.]website
- webmail.instagram.com-accounts[.]website
- www.facebook.com-accounts[.]website
- www.google.com-accounts[.]website
- www.instagram.com-accounts[.]website
- www.pis2ray[.]online
- www.yemplayer[.]site
- www.yeplayer[.]store
- 13440348516ccee839675f6ac908dd1724ce1d28f92af92fdc7938740d2b7ec5
- 400eb6a94810323a1fc5f8ab31c682fe765aaec2cc61b37c31d719c7e45c9a6c
- 51a6686b8c5ec7c610637398f3de43589f4e9fcbe8bcc0245343c5454d3b91de
- 66dcd98c6b310f4429890821e609d48cc6395a6be15ffe5a121ec68b7a8f7402
- 6c74d29903bc2cc17ec4afdb1a120d2060209b22830cee2b7005f5436e86f90e
- 8a7f5c8533df9e51b2da7cc2aeb52d8787418e4915577cc9288be1e46d1945c6
- a4f1b79e96a7d016de1991a64506792018de99eac5df00f7cabe26ef41b2bd81
- bb0c7ae4f12e5141480ee26f473636b07e836bb994ff3b2cfec93d4480da171b
- cc59bf019af195dcec4394ffd7a8e23c080f4e02b12dcb7c04fb1da6671922a1
- ea755862ee81dd0d991b4afca42d8b82bb22a8f1d370bf3d28dbf2e44ab241dd
- fa246327bed8fc5864827a8147b8b7aedb6246068259b8c97e82adb957315347
- 212[.]83.61.198
- 45[.]86.162.197
- 46[.]30.191.105
- 46[.]30.191.123
- 89[.]144.145.237
- 89[.]144.145.239
Tip: 68 related IOCs (6 IP, 51 domain, 0 URL, 0 email, 11 file hash) to this threat have been found.
FAQs
TAG-182 MarkiRAT Surveillance Campaign
Security researchers identified a new cyber surveillance campaign distributing a piece of malware known as MarkiRAT. The attackers used fake Android applications, specifically disguising them as VPNs and media players, to trick users into downloading the malicious software.
The campaign is attributed to a threat cluster tracked as TAG-182, which is highly likely part of the Iranian government's broader cyber-surveillance network. While their exact organizational affiliation is unconfirmed, their tactics closely mirror those of "Ferocious Kitten," a group notorious for targeting anti-government networks.
The primary goal of this campaign is intelligence collection and domestic surveillance. By infecting devices with the MarkiRAT software, the attackers aim to secretly monitor the digital activities and communications of their targets to support government security objectives.
The campaign is highly targeted rather than broad or indiscriminate. It focuses specifically on identifying and monitoring individuals perceived as dissidents or threats to the state, heavily utilizing social media platforms like Instagram to find targets.
The attackers specifically targeted Farsi-speaking users, including Iranian civilians, perceived dissidents, activists, and anti-government movements located both inside and outside of Iran. They aimed to compromise personal devices to monitor digital activities and collect sensitive intelligence.
Attackers promoted fake applications—like "Pis2ray VPN" or "YESHICA YEPlayer"—through social media posts, taking advantage of users looking for ways to bypass internet restrictions. When targets downloaded and installed these seemingly helpful tools, the hidden MarkiRAT malware was secretly installed on their devices, giving the attackers remote surveillance capabilities.
Following recent street protests and a massive 88-day internet shutdown in Iran, the government is intensifying its internal security measures. Dissidents and activists are highly attractive targets because monitoring them allows authorities to detect opposition, track anti-government sentiment, and enforce strict digital and physical control.
Individuals should strictly avoid downloading applications from unverified sources or links shared on social media, sticking only to official app stores like Google Play or the Apple App Store. Organizations should update their network defenses using the identified technical indicators and monitor for unauthorized background system activities.
This is a highly targeted issue aimed specifically at individuals connected to Iranian opposition, activism, or those seeking to bypass domestic internet controls. It is not a widespread threat to the general public outside of this specific demographic.