MarkiRAT is a Windows remote access trojan associated with TAG-182 and assessed as part of Iran-linked surveillance activity targeting Farsi-speaking users inside and outside Iran. It has been distributed through lure software themed as VPN, media-player, and utility applications and has used masquerading to resemble legitimate executables and application components, including software associated with Telegram and Chrome.
The malware supports host profiling and surveillance functions including retrieving the victim username, enumerating running processes, checking for security products such as Kaspersky and Bitdefender, capturing clipboard contents, and taking screenshots. It also performs targeting checks by using keyboard layout information to determine whether a compromised host is configured for Persian, indicating selective victim filtering.
MarkiRAT includes persistence mechanisms on Windows. Observed methods include dropping its payload into the Startup folder and modifying a Telegram shortcut so that the malicious payload is launched alongside the legitimate application. It also uses masquerading to reduce suspicion by adopting names similar to legitimate system or application files.
For collection and theft, MarkiRAT stores gathered data locally before transmitting it and can upload victim data to command-and-control infrastructure. Reported behavior includes local staging of collected information in an .nfo file and exfiltration over its C2 channel. The malware has also been associated with use of Windows command-shell execution and native APIs for operational tasks.
Overall, MarkiRAT is best characterized as an espionage-oriented RAT used in targeted surveillance operations, with capabilities centered on victim profiling, collection, persistence, defense evasion, and exfiltration on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Over multiple years, the group developed and deployed a custom implant known as MarkiRAT that provides broad collection capabilities, keystroke and clipboard logging, screenshots, filesystem searches for targeted file types and credential stores, remote command execution, and staged exfiltration over HTTP(S).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
recent TAG-182 activity used exactly such lures to distribute MarkiRAT to Farsi-speaking users inside and outside Iran.
Over multiple years, the group developed and deployed a custom implant known as MarkiRAT that provides broad collection capabilities, keystroke and clipboard logging, screenshots, filesystem searches for targeted file types and credential stores, remote command execution, and staged exfiltration over HTTP(S).
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Cobalt Strike's Beacon payload is capable of running shell commands without cmd.exe and PowerShell commands without powershell.exe.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
title: MarkiRAT Malware Bitsadmin File Download ... description: Detects the use of bitsadmin to download a file from a remote URL by MarkiRAT malware used by Iran-Nexus TAG-182. ... tags: - attack.t1197 # BITS Jobs
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities... Bazar can perform a check to ensure that the operating system's keyboard and language settings are not set to Russian... Clop has checked the keyboard language using the GetKeyboardLayout() function... Ryuk has been observed to query the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Language and the value InstallLanguage.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
56 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
41 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan distributed via lure files targeting Farsi-speaking users inside and outside Iran, in the context of surveillance and targeting activity.
MarkiRAT is described as the main backdoor used by TAG-182. It uses BITSAdmin to download payloads from remote URLs, communicates with C2 endpoints via /i.php and /uploadx.php, uploads data, and includes screenshot-capture functionality for surveillance.
Custom espionage implant/RAT used by Ferocious Kitten for surveillance and data theft: keylogging and clipboard capture, screenshots, file and directory discovery, targeted collection of sensitive file types (including credential/key store formats like KeePass .kdbx), remote command execution, and HTTP(S)-based C2 with staged exfiltration. Also uses persistence via startup folder and execution-flow hijacking by planting alongside legitimate apps (e.g., Telegram/Chrome) and modifying shortcuts.
Remote access trojan that can retrieve the victim username.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.