Threat research firm Recorded Future's Insikt Group says an Iran linked cluster it tracks as TAG 182 is spreading MarkiRAT — a remote access trojan — through a fake VPN called Pis2ray and a fake media player, YESHICA.
A free VPN that promises privacy can take screenshots of your phone in the background and ship them to attacker-run servers. Recorded Future's Insikt Group attributes the campaign to TAG-182, an Iran-nexus threat cluster distributing MarkiRAT through two off-store lures: a fake VPN called Pis2ray and a fake media player, YESHICA.
Neither app has ever appeared in Google Play or the App Store. Distribution runs through social-media posts, including Instagram pushes following Iran's late-2025 street protests. YESHICA was renamed YESHICA YEPlayer in March 2026 after researchers publicly exposed the original; the renamed variant is still circulating off-store.
MarkiRAT exfiltrates screenshots and spoofs its own process names to look ordinary. Cleanup rarely catches it: the malware abuses Windows BITS, the background service that handles update and download jobs, to pull additional files after the initial install.
Insikt Group assesses the cluster is "highly likely" targeting Iranian users inside and outside the country, and stops short of naming a specific Iranian agency. Related coverage places the activity inside a broader ecosystem of state-aligned surveillance groups that have used the same MarkiRAT lineage before.
A privacy or media app that is not on the official store, with no reputable publisher, distributed through a social post, is the threat itself.