Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors tag-182

Also known as: Charming Kitten, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, tracked as, ESET said, MuddyWater, indicating shared resources, Olalampo, Tech Sectors, hyp3rlinx, ApparitionSec, Mustang Panda, APT35, Israel in late 2020, France, the Middle Eas, Parastoo, iKittens, NEWSCASTER, NewsBeef, Phosphorus, Group 83, APT34, Agrius, Gamaredon APT

Description

TAG‑182 is an advanced threat cluster believed to be affiliated with Iranian state‑oriented actors. Recent activity in 2026 demonstrates an escalation of surveillance operations, with the deployment of MarkiRAT as a Remote Access Trojan that harvests system and credential data from both Windows and Android platforms. The organization distributes counterfeit VPN and media applications through Instagram and other social‑media channels to entice users into downloading malicious code. Operationally, TAG‑182 leverages multiple tradecraft layers: spearphishing, smishing/vishing social engineering, exploitation of known CVEs (notably CVE‑2025‑0282 in Ivanti Connect Secure and the Adobe Commerce CVE‑2024‑34102), and persistent use of compromised accounts to move laterally via Windows Management Instrumentation (WMI) and Remote Services. The group also injects Rust‑based RAT code, embeds legitimate vendor names into process metadata, and utilizes PowerShell scripts for remote management and data exfiltration, often encapsulated within obfuscated files. The threat actor’s infrastructure spans numerous autonomous systems and employs domain generation algorithm (DGA) techniques that mimic legitimate services such as Microsoft, Google, and Facebook. A pattern of file upload activity further indicates the use of C2 channels to receive additional payloads and potentially execute client‑side exploits. All these behaviors align with other Iran‑aligned families such as MuddyWater/Boggy Serpens, suggesting shared tactics or possibly a broader network of collaborators. Given the sophisticated mix of social media delivery, exploitation, and persistence mechanisms, TAG‑182 represents a significant risk to both governmental and commercial entities dealing with sensitive information. Continuous monitoring for MarkiRAT indicators and rigorous patch management remain critical defense measures.

TTP Summary

Fake Social Media Account

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Energy
Non profit
Critical infrastructure
Maritime
Retail
Education
Healthcare
Aerospace
Aviation
Transportation
Media
Think tank
Information technology
Hospitality
Utilities
Gaming
Mining
Manufacturing

Targeted Countries / Regions

Iran, Islamic Republic of
CN
RU
IR
UA
US
IL
AE
IN
KP
TW
AZ
JP
BY
SA
MX
PL
KR
PK
KZ
IT
BR
GB
TR
EG
ES
VN
LB
AU
FR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

TAG‑182, an Iran‑nexus espionage cluster, increasingly leverages MarkiRAT and fake VPN/media applications to surreptitiously surveil Iranian citizens domestically and abroad. The group combines social‑engineering tactics with the exploitation of unpatched public‑facing vulnerabilities such as CVE‑2025‑0282 in Ivanti Connect Secure to expand lateral reach within targeted networks. Their operations focus on critical sectors—government, financial services, defense, telecoms, energy, maritime, and education—in a pattern that suggests a long‑term intelligence agenda.

Goals & Targeting

TAG‑182 is driven primarily by clandestine intelligence gathering with a secondary profit motive. Their targeting spans government ministries, financial institutions, defense contractors, telecom operators, energy suppliers, maritime firms, and educational establishments across Iran’s allied network as well as other regions in the Middle East, Europe, and North America. By exploiting publicly accessible services and leveraging sophisticated social‑engineering, the actor seeks to infiltrate systems to siphon data while maintaining a low profile. The eventual deployment of ransomware or encrypted impact techniques suggests an appetite for financial extortion once infiltration is secured. The strategic objectives therefore appear twofold: (1) sustained surveillance against perceived dissidents and opposition figures among Iranian nationals both inside and outside the country, and (2) opportunistic exploitation of high‑value target assets for monetary gains via ransom or espionage trade. The actor’s focus on critical infrastructure sectors also indicates a potential future escalation towards sabotage or strategic disruption if politically warranted. By combining domain impersonation, mobile app delivery, and exploitation of vulnerable enterprise software, TAG‑182 is building a diversified attack surface that enhances their ability to remain hidden while continuously expanding reach within targeted communities. key_capabilities':['Acquire infrastructure (domains)','Spearfishing/Smishing-vishing social engineering','Exploit unpatched CVEs for remote code execution (e.g., CVE-2025-0282 Ivanti Connect Secure)','Deploy backdoors and RATs (MarkiRAT, LampoRAT)','Persistence via compromised accounts and credential reuse','Lateral movement over Remote Services (WMI, SMB, RDP)','Data exfiltration and encrypted impact through ransomware or data encryption','Rust-based RAT development','File upload capability for payload delivery','PowerShell scripting for remote monitoring and data theft','Use of AI‑assisted workflows for code generation and obfuscation'],'mitre_techniques':['T1583.001','T1586','T1190','T1203','T1068','T1078','T1005','T1486','T1021','T1059.001','T1105','T1047','T1033','T1082','T1016'],'mitre_tactics':['Resource Development','Initial Access','Execution','Persistence','Privilege Escalation','Discovery','Lateral Movement','Impact','Defense Evasion','Exfiltration'],'associated_tools':['MarkiRAT','LampoRAT','Android.Spy.1292.origin','PowerShell Toolkit'],'campaign_insights':'TAG‑182 has shown a steady increase in campaign activity from 2023 to 2026, with primary focus on Iranian citizens and allied entities. The actor exploits social‑media outlets (particularly Instagram) for delivery of malicious Android apps while concurrently delivering desktop payloads via phishing emails and exploitable CVEs. Victims include government agencies, financial institutions, telecom operators, critical infrastructure providers, and educational organizations across Iran, the broader Middle East, Europe, North America, and parts of Asia. The operational tempo is medium‑slow, with repeated reconnaissance before each wave of delivery. Notably, TAG‑182 has shared tactics and tools (e.g., Rust‑based RATs, PowerShell backdoors) with other Iranian‑aligned families such as Boggy Serpens/MuddyWater, indicating potential collaboration or resource sharing. ioc_patterns':['file exe','domain','ip-v4','hash-sha256','exploiting CVE-2025-0282 Ivanti Connect Secure','spearphishing attachments/links','smishing/vishing targeting mobile devices','fake VPN/media app delivery','credential theft from compromised accounts','masquerading as legitimate antivirus executable (avp.exe)','embedding vendor keyword in file metadata','public‑facing vulnerability exploitation CVE-2024-34102','PowerShell scripts for remote management','file upload activity'], recommended_actions':['Patch known vulnerabilities immediately, notably CVE-2025-0282 Ivanti Connect Secure and CVE-2024-34102 Adobe Commerce','Block suspicious VPN appliance access and monitor for unauthorized remote code execution attempts','Implement robust email filtering and anti‑phishing controls across corporate mail','Enforce least privilege and multi‑factor authentication to mitigate compromised account risk','Deploy Endpoint Detection & Response solutions that detect MarkiRAT activity, fileless PowerShell usage, and remote management commands','Validate authenticity of system processes to flag masqueraded antivirus binaries','Segment networks and employ intrusion detection for unauthorized file upload traffic'], suggested_tags':['TAG-182','Charming Kitten','APT39','Chafer','Cadelspy','Remexi','ITG07','MuddyWater','Olalampo','Tech Sectors','hyp3rlinx','ApparitionSec','Mustang Panda','APT35','Parastoo','NEWSCASTER','Phosphorus','Group 83','APT34','Agrius','Gamaredon','Boggy Serpens'], confidence_assessment':'The overall confidence in the threat profile is moderate to high. Multiple public advisory sources converge on the same set of capabilities, indicators, and operational patterns for TAG‑182, lending credibility to attribution within an Iran‑aligned actor network. However, definitive linkages between all alias groups remain partially speculative due to overlapping tradecraft and shared tooling across families such as MuddyWater and Boggy Serpens. Key gaps include a comprehensive timeline of activity prior to 2023, precise attribution evidence for each delivery vector, and the full extent of influence on downstream actors (e.g., whether the Rust‑based RATs are independently developed or shared). Continuous monitoring of new indicators is recommended to refine confidence levels and operational understanding. sources':['https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/']}

Enhanced Description

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 1 Domain 7 Filename 9 IPv4 Address 3

References

  1. attack.mitre.org — Cited by web research for: Advanced Persistent Threat 39
  2. unit42.paloaltonetworks.com — Cited by web research for: MuddyWater
  3. attack.mitre.org — Cited by web research for: hyp3rlinx
  4. www.cybereason.com — Cited by web research for: APT35
  5. www.recordedfuture.com — Cited by web research for: T1486
  6. www.recordedfuture.com — Cited by web research for: T1078

Intel Summary

19

Techniques

43

Tools

0

Campaigns

99

IOCs

0

Observed Data

11

Tactics

Tags

Backdoor / C2
Government Targeting
APT
surveillance
espionage
Iran/Iranian-nexus
network monitoring

Details

MITRE ID
APT35
Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
Iran (IR)
Confidence
55%
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.