logo

TAG-182 Threat Cluster Spreads MarkiRAT Malware

ID: 0de92bed-ff79-591f-baf0-97c75d3f5378

STIX ID: report--0de92bed-ff79-591f-baf0-97c75d3f5378

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-07-06

Date Updated: 2026-08-06

Author: Do Son

...
...

Insikt Group researchers attribute a targeted cyber-surveillance campaign to TAG-182 (suspected Iran-aligned) that lures Farsi-speaking users with fake VPNs and media players to distribute the MarkiRAT remote-access/spyware; the report details the infection chain, stealth/persistence techniques (BITS job manipulation, dropping svehost.exe), attacker infrastructure (malicious domains, Let’s Encrypt certs, shared hosting), and active promotion on social media aimed at dissidents during regional internet outages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.