MarkiRAT is a Windows backdoor associated with the Iran-nexus TAG-182 activity cluster. It has been distributed to Farsi-speaking users inside and outside Iran through trojanized VPN, media-player, and utility software that masquerades as legitimate applications. The malware supports surveillance and host profiling by capturing screenshots and clipboard contents; collecting the current username; enumerating running processes; checking for selected antivirus products; and identifying Persian keyboard layouts. It can collect and locally stage victim data before uploading it to command-and-control infrastructure. MarkiRAT establishes persistence through the Windows Startup folder and can modify a Telegram shortcut so that its malicious payload launches alongside the legitimate application. It also uses deceptive naming intended to resemble legitimate Windows, browser, messaging, and update-related software.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Over multiple years, the group developed and deployed a custom implant known as MarkiRAT that provides broad collection capabilities, keystroke and clipboard logging, screenshots, filesystem searches for targeted file types and credential stores, remote command execution, and staged exfiltration over HTTP(S).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The TAG-182 campaign documented by Recorded Future shares none of our technical indicators; its lure is a VPN application marketed to anti-government audiences that deploys MarkiRAT.
Over multiple years, the group developed and deployed a custom implant known as MarkiRAT that provides broad collection capabilities, keystroke and clipboard logging, screenshots, filesystem searches for targeted file types and credential stores, remote command execution, and staged exfiltration over HTTP(S).
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Cobalt Strike's Beacon payload is capable of running shell commands without cmd.exe and PowerShell commands without powershell.exe.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
title: MarkiRAT Malware Bitsadmin File Download ... description: Detects the use of bitsadmin to download a file from a remote URL by MarkiRAT malware used by Iran-Nexus TAG-182. ... tags: - attack.t1197 # BITS Jobs
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities... Bazar can perform a check to ensure that the operating system's keyboard and language settings are not set to Russian... Clop has checked the keyboard language using the GetKeyboardLayout() function... Ryuk has been observed to query the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Language and the value InstallLanguage.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
56 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-access trojan mentioned only as part of an unrelated TAG-182 campaign used for comparison; the article identifies no technical or operational overlap with Iranopasmigirim.
Remote access trojan delivered via fake VPN and media player lures.
A remote access trojan distributed via lure files targeting Farsi-speaking users inside and outside Iran, in the context of surveillance and targeting activity.
MarkiRAT is described as the main backdoor used by TAG-182. It uses BITSAdmin to download payloads from remote URLs, communicates with C2 endpoints via /i.php and /uploadx.php, uploads data, and includes screenshot-capture functionality for surveillance.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.