Summary
Recorded Future's Insikt Group has uncovered an Iran-linked group, TAG-182, distributing spyware through fake VPN and media player apps like Pis2ray VPN and YESHICA. The malware, MarkiRAT, is primarily targeting Iranian users and dissidents, allowing attackers remote control of their devices and data exfiltration.