Recorded Future's Insikt Group details TAG-182, an Iran-nexus threat cluster distributing MarkiRAT — a surveillance backdoor disguised as fake VPN and media apps. The group targets Iranian dissidents and anti-government networks inside Iran and abroad. Infrastructure analysis reveals domains hosted on AS47447 and AS199959, using Let's Encrypt certificates and typosquatted names mimicking Google, Microsoft, and Facebook. TAG-182 is assessed as likely related to Ferocious Kitten and part of a broader pro-Iranian cyber-surveillance ecosystem supporting the IRGC, Basij, and FATA. The report includes full indicators of compromise (domains, IPs, SHA256 hashes), MITRE ATT&CK technique mappings, a YARA detection rule for MarkiRAT, and a Sigma rule for detecting bitsadmin-based file downloads used by the malware.

5m read timeFrom recordedfuture.com
Post cover image
Table of contents
Executive SummaryKey FindingsThreat Analysis
121 Impressions