Also known as: Charming Kitten, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, tracked as, ESET said, MuddyWater, indicating shared resources, Olalampo, Tech Sectors, hyp3rlinx, ApparitionSec, Mustang Panda, APT35, Israel in late 2020, France, the Middle Eas, Parastoo, iKittens, NEWSCASTER, NewsBeef, Phosphorus, Group 83, APT34, Agrius, Gamaredon APT
TAG‑182 is an advanced threat cluster believed to be affiliated with Iranian state‑oriented actors. Recent activity in 2026 demonstrates an escalation of surveillance operations, with the deployment of MarkiRAT as a Remote Access Trojan that harvests system and credential data from both Windows and Android platforms. The organization distributes counterfeit VPN and media applications through Instagram and other social‑media channels to entice users into downloading malicious code. Operationally, TAG‑182 leverages multiple tradecraft layers: spearphishing, smishing/vishing social engineering, exploitation of known CVEs (notably CVE‑2025‑0282 in Ivanti Connect Secure and the Adobe Commerce CVE‑2024‑34102), and persistent use of compromised accounts to move laterally via Windows Management Instrumentation (WMI) and Remote Services. The group also injects Rust‑based RAT code, embeds legitimate vendor names into process metadata, and utilizes PowerShell scripts for remote management and data exfiltration, often encapsulated within obfuscated files. The threat actor’s infrastructure spans numerous autonomous systems and employs domain generation algorithm (DGA) techniques that mimic legitimate services such as Microsoft, Google, and Facebook. A pattern of file upload activity further indicates the use of C2 channels to receive additional payloads and potentially execute client‑side exploits. All these behaviors align with other Iran‑aligned families such as MuddyWater/Boggy Serpens, suggesting shared tactics or possibly a broader network of collaborators. Given the sophisticated mix of social media delivery, exploitation, and persistence mechanisms, TAG‑182 represents a significant risk to both governmental and commercial entities dealing with sensitive information. Continuous monitoring for MarkiRAT indicators and rigorous patch management remain critical defense measures.
Fake Social Media Account
Targeted Sectors
Targeted Countries / Regions
Executive Summary
TAG‑182, an Iran‑nexus espionage cluster, increasingly leverages MarkiRAT and fake VPN/media applications to surreptitiously surveil Iranian citizens domestically and abroad. The group combines social‑engineering tactics with the exploitation of unpatched public‑facing vulnerabilities such as CVE‑2025‑0282 in Ivanti Connect Secure to expand lateral reach within targeted networks. Their operations focus on critical sectors—government, financial services, defense, telecoms, energy, maritime, and education—in a pattern that suggests a long‑term intelligence agenda.
Goals & Targeting
TAG‑182 is driven primarily by clandestine intelligence gathering with a secondary profit motive. Their targeting spans government ministries, financial institutions, defense contractors, telecom operators, energy suppliers, maritime firms, and educational establishments across Iran’s allied network as well as other regions in the Middle East, Europe, and North America. By exploiting publicly accessible services and leveraging sophisticated social‑engineering, the actor seeks to infiltrate systems to siphon data while maintaining a low profile. The eventual deployment of ransomware or encrypted impact techniques suggests an appetite for financial extortion once infiltration is secured. The strategic objectives therefore appear twofold: (1) sustained surveillance against perceived dissidents and opposition figures among Iranian nationals both inside and outside the country, and (2) opportunistic exploitation of high‑value target assets for monetary gains via ransom or espionage trade. The actor’s focus on critical infrastructure sectors also indicates a potential future escalation towards sabotage or strategic disruption if politically warranted. By combining domain impersonation, mobile app delivery, and exploitation of vulnerable enterprise software, TAG‑182 is building a diversified attack surface that enhances their ability to remain hidden while continuously expanding reach within targeted communities. key_capabilities':['Acquire infrastructure (domains)','Spearfishing/Smishing-vishing social engineering','Exploit unpatched CVEs for remote code execution (e.g., CVE-2025-0282 Ivanti Connect Secure)','Deploy backdoors and RATs (MarkiRAT, LampoRAT)','Persistence via compromised accounts and credential reuse','Lateral movement over Remote Services (WMI, SMB, RDP)','Data exfiltration and encrypted impact through ransomware or data encryption','Rust-based RAT development','File upload capability for payload delivery','PowerShell scripting for remote monitoring and data theft','Use of AI‑assisted workflows for code generation and obfuscation'],'mitre_techniques':['T1583.001','T1586','T1190','T1203','T1068','T1078','T1005','T1486','T1021','T1059.001','T1105','T1047','T1033','T1082','T1016'],'mitre_tactics':['Resource Development','Initial Access','Execution','Persistence','Privilege Escalation','Discovery','Lateral Movement','Impact','Defense Evasion','Exfiltration'],'associated_tools':['MarkiRAT','LampoRAT','Android.Spy.1292.origin','PowerShell Toolkit'],'campaign_insights':'TAG‑182 has shown a steady increase in campaign activity from 2023 to 2026, with primary focus on Iranian citizens and allied entities. The actor exploits social‑media outlets (particularly Instagram) for delivery of malicious Android apps while concurrently delivering desktop payloads via phishing emails and exploitable CVEs. Victims include government agencies, financial institutions, telecom operators, critical infrastructure providers, and educational organizations across Iran, the broader Middle East, Europe, North America, and parts of Asia. The operational tempo is medium‑slow, with repeated reconnaissance before each wave of delivery. Notably, TAG‑182 has shared tactics and tools (e.g., Rust‑based RATs, PowerShell backdoors) with other Iranian‑aligned families such as Boggy Serpens/MuddyWater, indicating potential collaboration or resource sharing. ioc_patterns':['file exe','domain','ip-v4','hash-sha256','exploiting CVE-2025-0282 Ivanti Connect Secure','spearphishing attachments/links','smishing/vishing targeting mobile devices','fake VPN/media app delivery','credential theft from compromised accounts','masquerading as legitimate antivirus executable (avp.exe)','embedding vendor keyword in file metadata','public‑facing vulnerability exploitation CVE-2024-34102','PowerShell scripts for remote management','file upload activity'], recommended_actions':['Patch known vulnerabilities immediately, notably CVE-2025-0282 Ivanti Connect Secure and CVE-2024-34102 Adobe Commerce','Block suspicious VPN appliance access and monitor for unauthorized remote code execution attempts','Implement robust email filtering and anti‑phishing controls across corporate mail','Enforce least privilege and multi‑factor authentication to mitigate compromised account risk','Deploy Endpoint Detection & Response solutions that detect MarkiRAT activity, fileless PowerShell usage, and remote management commands','Validate authenticity of system processes to flag masqueraded antivirus binaries','Segment networks and employ intrusion detection for unauthorized file upload traffic'], suggested_tags':['TAG-182','Charming Kitten','APT39','Chafer','Cadelspy','Remexi','ITG07','MuddyWater','Olalampo','Tech Sectors','hyp3rlinx','ApparitionSec','Mustang Panda','APT35','Parastoo','NEWSCASTER','Phosphorus','Group 83','APT34','Agrius','Gamaredon','Boggy Serpens'], confidence_assessment':'The overall confidence in the threat profile is moderate to high. Multiple public advisory sources converge on the same set of capabilities, indicators, and operational patterns for TAG‑182, lending credibility to attribution within an Iran‑aligned actor network. However, definitive linkages between all alias groups remain partially speculative due to overlapping tradecraft and shared tooling across families such as MuddyWater and Boggy Serpens. Key gaps include a comprehensive timeline of activity prior to 2023, precise attribution evidence for each delivery vector, and the full extent of influence on downstream actors (e.g., whether the Rust‑based RATs are independently developed or shared). Continuous monitoring of new indicators is recommended to refine confidence levels and operational understanding. sources':['https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/']}
Enhanced Description
No campaigns linked yet.
No observed data linked yet.
19
Techniques
43
Tools
0
Campaigns
99
IOCs
0
Observed Data
11
Tactics