Ethical Hacking News
A recent investigation by the Mysterium VPN Research Team has revealed a startling connection between two popular mobile apps – eSIM Plus and Nicegram – and their shared Belarus-led codebase. Contrary to their marketed Lithuanian origins, both applications contain significant integrations with Russian services, highlighting a critical gap within the app ecosystem that threatens user trust and security.
The investigation found that eSIM Plus and Nicegram, two popular mobile apps, share a common codebase linked to Belarus.The shared developer identity was cryptographically signed by Mobyrix, Minsk, a Belarusian company.eSIM Plus integrates with Russian services Yandex AppMetrica and Voximplant for analytics purposes.Nicegram does not contain any evidence of Yandex AppMetrica or Voximplant integrations.The investigation highlights a critical structural problem within the app ecosystem, exposing a gap between an app's publisher and developer country.The lack of transparency and oversight in the app store ecosystem underscores a need for enhanced regulation and consumer education.
In a recent investigation conducted by the Mysterium VPN Research Team, two popular mobile apps – eSIM Plus and Nicegram – have been found to share a common codebase linked to Belarus. The analysis revealed that both applications are marketed as Lithuanian products but contain significant evidence pointing towards their actual development and control being led by Belarus.
The investigation began with an examination of the Android packages for both eSIM Plus and Nicegram, which ultimately led to the discovery of a shared developer identity – Appvillis – claiming responsibility for these apps. However, upon closer inspection, the team found that this shared developer was cryptographically signed by Mobyrix, Minsk, a Belarusian company. This signing certificate serves as a decisive piece of evidence in establishing the connection between eSIM Plus and Nicegram.
The analysis revealed that eSIM Plus contains full integrations with two Russian services: Yandex AppMetrica and Voximplant. The integration with Yandex AppMetrica is particularly noteworthy, as it communicates with Yandex infrastructure at startup and reports events to appmetrica.io. Moreover, the application utilizes Mixpanel, Segment, Customer.io, AppsFlyer, Facebook SDK, Firebase, and Qonversion for analytics purposes, including tracking user location, contacts, camera access, microphone usage, and telephony. Notably, eSIM Plus also includes a module that facilitates "God's Eye" profiling of Telegram users by sending channel and session data to its servers.
In stark contrast, the Nicegram 1.55.0 package examined did not contain any evidence of Yandex AppMetrica or Voximplant integrations. While it does include static maps from yandex.ru and coub.com, these domains are benign and user-gated, unlike those in eSIM Plus.
The implications of this investigation are significant, as they highlight a critical structural problem within the app ecosystem. Specifically, it exposes a gap between an app's store-listed "publisher" and country and who actually builds, signs, and receives data from the software – a gap that remains invisible to most users at install time but becomes legible only through static package analysis.
The research emphasizes that this issue has far-reaching consequences, as users unwittingly entrust their personal and sensitive information to apps claiming to be of Lithuanian origin but in reality being developed by Belarus-based companies. The lack of transparency and oversight within the app store ecosystem underscores a pressing need for enhanced regulation and consumer education.
Ultimately, the discovery of this codebase highlights the importance of scrutinizing the intricacies of mobile app development and the critical role that static package analysis plays in uncovering hidden patterns and anomalies.
Related Information:
https://www.ethicalhackingnews.com/articles/eSIM-Plus-and-Nicegram-Unveiling-the-Belarus-Led-Codebase-Behind-a-Lithuanian-Facade-ehn.shtml
https://securityaffairs.com/196280/security/esim-plus-and-nicegram-share-belarus-linked-codebase-analysis-finds.html
Published: Thu Jul 30 04:06:41 2026 by llama3.2 3B Q4_K_M