State-Sponsored Spyware Discovered in Malicious VPN Applications Targeting Global User Authentication and Privacy

state-sponsored spyware malicious VPN apps Bahamut APT group MarkiRAT data exfiltration
V
Viktor Sokolov

Network Infrastructure & Protocol Security Researcher

 
July 26, 2026
5 min read
State-Sponsored Spyware Discovered in Malicious VPN Applications Targeting Global User Authentication and Privacy

TL;DR

• State-sponsored actors are using trojanized VPNs to monitor private user data. • Bahamut group exploits Android devices using fake 'SecureVPN' applications. • TAG-182 utilizes the 'MarkiRAT' trojan to target journalists and dissidents. • Malware scrapes messages from WhatsApp, Signal, Telegram, and other platforms. • These apps use sleeper-cell tactics to evade automated security sandboxes.

State-Sponsored Spyware: The VPN Trap Targeting Your Privacy

It’s the ultimate irony: you download a VPN to lock down your digital life, only to hand the keys to a state-sponsored intelligence agency.

Recent investigations have blown the lid off a series of coordinated, state-backed espionage campaigns. These actors aren't just hacking servers; they’re playing a long game, using trojanized VPN apps to burrow into your phone and desktop. Once they’re in, they don’t just grab a password and leave—they set up camp, exfiltrating your private messages and keeping a permanent eye on your network.

Research from ESET and Recorded Future paints a grim picture. By masquerading as legitimate privacy tools, these malicious apps bypass the healthy skepticism most users apply to unknown software. They’re not just stealing data; they’re subverting the very tools we use to protect ourselves.

The Bahamut Playbook: Android Under Siege

The Bahamut APT group has been busy. They’ve been caught running a surgical strike on Android users, distributing a fake "SecureVPN" app through a standalone website that has absolutely nothing to do with legitimate VPN providers.

According to ESET research, the spyware is essentially a "franken-app"—a trojanized version of open-source tools like OpenVPN or SoftVPN. What makes this particularly nasty is its patience. The malicious code stays dormant, a digital sleeper cell, until the victim enters a specific activation key. It’s a clever trick designed to slip past automated security sandboxes that might otherwise flag the app as suspicious.

Once that key is punched in, the gloves come off. The spyware gains access to:

  • Your Private Conversations: It scrapes chat logs from WhatsApp, Facebook Messenger, Signal, Viber, and Telegram.
  • Your Digital Life: It pulls contact lists, SMS history, and even records your calls.
  • Persistence: ESET has already tracked at least eight different versions of this malware. They’re iterating, and they aren't stopping.

TAG-182 and the MarkiRAT Threat

While Bahamut targets a broad range of users, the Iranian-linked group known as TAG-182 is much more focused. They’ve been using a remote access trojan called "MarkiRAT" to hunt down Persian-speaking journalists and dissidents.

As Recorded Future’s analysis details, the delivery method is surprisingly low-tech: social media. They push apps like "Pis2ray VPN" and "YESHICA YEPlayer" directly through Instagram.

MarkiRAT is a sophisticated piece of work. It’s programmed to scan for devices using Persian-language keyboard layouts, ensuring they only hit their intended targets. To stay hidden, it adopts the name "svehost.exe"—a classic "living off the land" technique meant to mimic the legitimate Windows "svchost.exe" process. Even worse, it exploits the Windows Background Intelligent Transfer Service (BITS) to sneak data out of your machine, a move that often flies under the radar of traditional antivirus software.

Threat Actor Malicious App Name Primary Target Key Capability
Bahamut SecureVPN (Fake) Android Users Messaging/Chat Interception
TAG-182 Pis2ray / YEPlayer Persian Speakers MarkiRAT / BITS Abuse

Beyond the App: The Infrastructure War

While mobile users are being targeted by apps, there’s a much larger, more dangerous game being played at the backbone of the internet. A global coalition of cybersecurity agencies has issued warnings about state-sponsored campaigns—largely originating from China—that are targeting the very hardware that makes the internet work.

Since 2021, these actors have been systematically compromising backbone, provider edge (PE), and customer edge (CE) routers. By seizing control of these devices, they aren't just watching one person; they’re gaining a vantage point into entire government, military, and telecommunications networks. This isn't just "hacking"—it's strategic positioning. Several entities, including Sichuan Juxinhe Network Technology and Beijing Huanyu Tianqiong Information Technology, have been linked to these efforts.

The industry has identified several clusters of activity, including Salt Typhoon, OPERATOR PANDA, RedMike, UNC5807, and GhostEmperor. These aren't hobbyists; these are state-level operations with the resources to compromise the physical infrastructure of the web.

How to Fight Back

The rise of these "legitimate-looking" threats changes the security landscape. When attackers use the tools that are supposed to keep us safe, the old rules of thumb don't always apply.

The abuse of Windows BITS is a perfect example of why simple signature-based detection is failing. If a system process is doing the heavy lifting, your antivirus might just shrug and let it happen. Defenders need to look for anomalous behavior, not just known malicious files.

If you’re worried about these threats, here’s how to tighten your defenses:

  1. Stick to the Source: If it’s not on the official App Store or Google Play, don't touch it. If you find a "VPN" through a random link on Instagram or a shady website, treat it like a live grenade.
  2. Audit Your Hardware: If you’re managing an enterprise network, keep a close eye on your router configurations. Look for unauthorized changes or strange traffic patterns at the provider edge.
  3. Upgrade Your Monitoring: Move toward EDR (Endpoint Detection and Response) solutions that can spot the misuse of system services like BITS. You need to know when a system process starts acting out of character.
  4. Lock Down Access: Stop relying on single-factor passwords for network hardware. Use multi-factor authentication everywhere, and restrict administrative access to the bare minimum.

These campaigns are not a passing phase. They are a permanent feature of modern statecraft. Whether they’re going after your personal messages via a fake VPN or compromising the routers that route global traffic, the goal is the same: persistent, long-term surveillance. Whether you're in the US, Australia, the UK, or anywhere else, the threat is real—and it’s designed to be invisible. Stay vigilant.

V
Viktor Sokolov

Network Infrastructure & Protocol Security Researcher

 

Viktor Sokolov is a network engineer and protocol security researcher with deep expertise in how data travels across the internet and where it becomes vulnerable. He spent eight years working for a major internet service provider, gaining firsthand knowledge of traffic analysis, deep packet inspection, and ISP-level surveillance capabilities. Viktor holds multiple Cisco certifications (CCNP, CCIE) and a Master's degree in Telecommunications Engineering. His insider knowledge of ISP practices informs his passionate advocacy for VPN use and encrypted communications.

Related News

Qilin Ransomware Group Targets Enterprise VPN Infrastructure in Coordinated Attacks Against Major Network Vendors
Qilin ransomware

Qilin Ransomware Group Targets Enterprise VPN Infrastructure in Coordinated Attacks Against Major Network Vendors

Qilin ransomware is exploiting critical vulnerabilities in major VPN vendors. Learn how this RaaS group breaches networks and how to protect your infrastructure.

By Elena Voss July 28, 2026 4 min read
common.read_full_article
State-Sponsored Spyware Discovered in Malicious VPN Applications Targeting Global User Authentication and Privacy
MarkiRAT malware

State-Sponsored Spyware Discovered in Malicious VPN Applications Targeting Global User Authentication and Privacy

State-sponsored hackers are using fake VPN apps to deploy the MarkiRAT malware, targeting Persian speakers globally to steal sensitive data and monitor devices.

By James Okoro July 27, 2026 4 min read
common.read_full_article
Active Exploitation of SonicWall SMA1000 Zero-Day Vulnerabilities Triggers Deployment of Custom Malware Campaigns
SonicWall SMA1000

Active Exploitation of SonicWall SMA1000 Zero-Day Vulnerabilities Triggers Deployment of Custom Malware Campaigns

SonicWall SMA1000 appliances are under attack by UTA0533 using zero-day exploits. Patch immediately to prevent root-level access and data theft.

By Elena Voss July 25, 2026 4 min read
common.read_full_article
Volexity Identifies Active Zero-Day Exploitation Campaign Targeting SonicWall VPN Appliances
SonicWall SMA 1000 exploit

Volexity Identifies Active Zero-Day Exploitation Campaign Targeting SonicWall VPN Appliances

Volexity warns of a critical zero-day campaign targeting SonicWall SMA 1000 VPNs. Patch CVE-2026-15409 and CVE-2026-15410 immediately to prevent root access.

By James Okoro July 24, 2026 3 min read
common.read_full_article