State-Sponsored Spyware Discovered in Malicious VPN Applications Targeting Global User Authentication and Privacy

state-sponsored spyware malicious VPN apps Bahamut APT group MarkiRAT data exfiltration
V
Viktor Sokolov

Network Infrastructure & Protocol Security Researcher

 
July 26, 2026
5 min read
State-Sponsored Spyware Discovered in Malicious VPN Applications Targeting Global User Authentication and Privacy

TL;DR

• State-sponsored actors are using trojanized VPNs to monitor private user data. • Bahamut group exploits Android devices using fake 'SecureVPN' applications. • TAG-182 utilizes the 'MarkiRAT' trojan to target journalists and dissidents. • Malware scrapes messages from WhatsApp, Signal, Telegram, and other platforms. • These apps use sleeper-cell tactics to evade automated security sandboxes.

State-Sponsored Spyware: The VPN Trap Targeting Your Privacy

It’s the ultimate irony: you download a VPN to lock down your digital life, only to hand the keys to a state-sponsored intelligence agency.

Recent investigations have blown the lid off a series of coordinated, state-backed espionage campaigns. These actors aren't just hacking servers; they’re playing a long game, using trojanized VPN apps to burrow into your phone and desktop. Once they’re in, they don’t just grab a password and leave—they set up camp, exfiltrating your private messages and keeping a permanent eye on your network.

Research from ESET and Recorded Future paints a grim picture. By masquerading as legitimate privacy tools, these malicious apps bypass the healthy skepticism most users apply to unknown software. They’re not just stealing data; they’re subverting the very tools we use to protect ourselves.

The Bahamut Playbook: Android Under Siege

The Bahamut APT group has been busy. They’ve been caught running a surgical strike on Android users, distributing a fake "SecureVPN" app through a standalone website that has absolutely nothing to do with legitimate VPN providers.

According to ESET research, the spyware is essentially a "franken-app"—a trojanized version of open-source tools like OpenVPN or SoftVPN. What makes this particularly nasty is its patience. The malicious code stays dormant, a digital sleeper cell, until the victim enters a specific activation key. It’s a clever trick designed to slip past automated security sandboxes that might otherwise flag the app as suspicious.

Once that key is punched in, the gloves come off. The spyware gains access to:

  • Your Private Conversations: It scrapes chat logs from WhatsApp, Facebook Messenger, Signal, Viber, and Telegram.
  • Your Digital Life: It pulls contact lists, SMS history, and even records your calls.
  • Persistence: ESET has already tracked at least eight different versions of this malware. They’re iterating, and they aren't stopping.

TAG-182 and the MarkiRAT Threat

While Bahamut targets a broad range of users, the Iranian-linked group known as TAG-182 is much more focused. They’ve been using a remote access trojan called "MarkiRAT" to hunt down Persian-speaking journalists and dissidents.

As Recorded Future’s analysis details, the delivery method is surprisingly low-tech: social media. They push apps like "Pis2ray VPN" and "YESHICA YEPlayer" directly through Instagram.

MarkiRAT is a sophisticated piece of work. It’s programmed to scan for devices using Persian-language keyboard layouts, ensuring they only hit their intended targets. To stay hidden, it adopts the name "svehost.exe"—a classic "living off the land" technique meant to mimic the legitimate Windows "svchost.exe" process. Even worse, it exploits the Windows Background Intelligent Transfer Service (BITS) to sneak data out of your machine, a move that often flies under the radar of traditional antivirus software.

Threat Actor Malicious App Name Primary Target Key Capability
Bahamut SecureVPN (Fake) Android Users Messaging/Chat Interception
TAG-182 Pis2ray / YEPlayer Persian Speakers MarkiRAT / BITS Abuse

Beyond the App: The Infrastructure War

While mobile users are being targeted by apps, there’s a much larger, more dangerous game being played at the backbone of the internet. A global coalition of cybersecurity agencies has issued warnings about state-sponsored campaigns—largely originating from China—that are targeting the very hardware that makes the internet work.

Since 2021, these actors have been systematically compromising backbone, provider edge (PE), and customer edge (CE) routers. By seizing control of these devices, they aren't just watching one person; they’re gaining a vantage point into entire government, military, and telecommunications networks. This isn't just "hacking"—it's strategic positioning. Several entities, including Sichuan Juxinhe Network Technology and Beijing Huanyu Tianqiong Information Technology, have been linked to these efforts.

The industry has identified several clusters of activity, including Salt Typhoon, OPERATOR PANDA, RedMike, UNC5807, and GhostEmperor. These aren't hobbyists; these are state-level operations with the resources to compromise the physical infrastructure of the web.

How to Fight Back

The rise of these "legitimate-looking" threats changes the security landscape. When attackers use the tools that are supposed to keep us safe, the old rules of thumb don't always apply.

The abuse of Windows BITS is a perfect example of why simple signature-based detection is failing. If a system process is doing the heavy lifting, your antivirus might just shrug and let it happen. Defenders need to look for anomalous behavior, not just known malicious files.

If you’re worried about these threats, here’s how to tighten your defenses:

  1. Stick to the Source: If it’s not on the official App Store or Google Play, don't touch it. If you find a "VPN" through a random link on Instagram or a shady website, treat it like a live grenade.
  2. Audit Your Hardware: If you’re managing an enterprise network, keep a close eye on your router configurations. Look for unauthorized changes or strange traffic patterns at the provider edge.
  3. Upgrade Your Monitoring: Move toward EDR (Endpoint Detection and Response) solutions that can spot the misuse of system services like BITS. You need to know when a system process starts acting out of character.
  4. Lock Down Access: Stop relying on single-factor passwords for network hardware. Use multi-factor authentication everywhere, and restrict administrative access to the bare minimum.

These campaigns are not a passing phase. They are a permanent feature of modern statecraft. Whether they’re going after your personal messages via a fake VPN or compromising the routers that route global traffic, the goal is the same: persistent, long-term surveillance. Whether you're in the US, Australia, the UK, or anywhere else, the threat is real—and it’s designed to be invisible. Stay vigilant.

V
Viktor Sokolov

Network Infrastructure & Protocol Security Researcher

 

Viktor Sokolov is a network engineer and protocol security researcher with deep expertise in how data travels across the internet and where it becomes vulnerable. He spent eight years working for a major internet service provider, gaining firsthand knowledge of traffic analysis, deep packet inspection, and ISP-level surveillance capabilities. Viktor holds multiple Cisco certifications (CCNP, CCIE) and a Master's degree in Telecommunications Engineering. His insider knowledge of ISP practices informs his passionate advocacy for VPN use and encrypted communications.

Related News

Outdated OpenVPN Implementations Expose Commercial VPN Clients to Critical Vulnerabilities and Security Risks
OpenVPN vulnerabilities

Outdated OpenVPN Implementations Expose Commercial VPN Clients to Critical Vulnerabilities and Security Risks

A 2026 security audit reveals many commercial VPNs use outdated, vulnerable OpenVPN versions. See which providers are leaving your data exposed to RCE attacks.

By James Okoro August 5, 2026 4 min read
common.read_full_article
SonicWall VPN Vulnerabilities and AI-Powered Hacking Campaigns Pose New Risks to Enterprise Infrastructure
SonicWall VPN vulnerabilities

SonicWall VPN Vulnerabilities and AI-Powered Hacking Campaigns Pose New Risks to Enterprise Infrastructure

Hackers are exploiting SonicWall VPNs via CVE-2024-40766 and credential stuffing. Learn how to secure your enterprise infrastructure against these attacks.

By Viktor Sokolov August 4, 2026 4 min read
common.read_full_article
Amazon Threat Intelligence Links North Korean Hackers to Malicious npm Supply Chain Attack
npm supply chain attack

Amazon Threat Intelligence Links North Korean Hackers to Malicious npm Supply Chain Attack

Amazon threat intelligence links North Korean hackers to malicious npm supply chain attacks. Discover how popular libraries like axios were weaponized.

By Elena Voss August 3, 2026 4 min read
common.read_full_article
AWS Threat Intelligence Report Links North Korean Hackers to Open-Source Supply Chain Attacks
AWS threat intelligence

AWS Threat Intelligence Report Links North Korean Hackers to Open-Source Supply Chain Attacks

AWS threat report reveals North Korean hackers are poisoning open-source repositories to infiltrate cloud environments and harvest developer credentials.

By James Okoro August 2, 2026 5 min read
common.read_full_article