Security Affairs
U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog|eSIM Plus and Nicegram Share Belarus-Linked Codebase, Analysis Finds|Claude Mythos Shows AI Can Outpace Human Cryptography Research|Hackers Strike Minnesota Water Utilities, One Plant Briefly Offline|ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Data|Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code Execution|OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach|OpenAI’s Rogue AI Agent Breached Second Company, Report Says|VPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” Claims|Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure|JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover|New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide|U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog|eSIM Plus and Nicegram Share Belarus-Linked Codebase, Analysis Finds|Claude Mythos Shows AI Can Outpace Human Cryptography Research|Hackers Strike Minnesota Water Utilities, One Plant Briefly Offline|ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Data|Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code Execution|OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach|OpenAI’s Rogue AI Agent Breached Second Company, Report Says|VPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” Claims|Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure|JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover|New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide|
Advertisement

Ad Placeholder

Full Width × 90

Cyber Crime

eSIM Plus and Nicegram Share Belarus-Linked Codebase, Analysis Finds

Analysis found eSIM Plus and Nicegram share a Belarus-linked codebase, while eSIM Plus routes data and calls through Russian services. Two popular apps available in EU app stores, Nicegram, with over 50 million downloads, and eSIM Plus, with over 1 million, are presented to users as Lithuanian products. The Mysterium VPN Research Team pulled apart […]

eSIM Plus

Analysis found eSIM Plus and Nicegram share a Belarus-linked codebase, while eSIM Plus routes data and calls through Russian services.

Two popular apps available in EU app stores, Nicegram, with over 50 million downloads, and eSIM Plus, with over 1 million, are presented to users as Lithuanian products. The Mysterium VPN Research Team pulled apart both Android packages to see what the binaries themselves reveal, following OCCRP reporting that both apps are allegedly developed and controlled from Belarus. What they found in the code substantially corroborates that reporting.

“Most decisively, the eSIM Plus package is cryptographically signed by “Mobyrix, Minsk” (a Belarusian signature on an app marketed under the Lithuanian “Appvillis” brand), and it ships live integrations with two Russian services, Yandex AppMetrica (analytics) and Voximplant (call routing, via a .ru endpoint).” reads the report published by Mysterium VPN Research Team. “Nicegram shares the same “Appvillis” codebase and backend, though the specific Russian SDKs aren’t present in the Nicegram build we examined.”

eSIM Plus 4.4.26Nicegram 1.55.0
Signing certificateMobyrix, Minsk, Belarus (original key)Google Play re-sign (developer identity hidden)
Yandex AppMetricaYes — full SDK (yandex.net, appmetrica.io)No SDK present
VoximplantYes — full SDK (.ru balancer)No
LocationFine + coarse, tracking wiredFine + coarse + background
Other telephonyTwilioN/A
Analytics/CDPAppMetrica, Mixpanel, Segment, Customer.io, AppsFlyer, Facebook, Firebase, QonversionFirebase, Adjust, Qonversion, AdMob, AppsFlyer
Notable extrasPayment SDKsCrypto wallet (seed phrases), “God’s Eye” profiling

The signing certificate is the most decisive piece of evidence. It carries the Minsk postal code 220020. An app publicly presented under a Lithuanian-facing brand is cryptographically signed by a company in Belarus, not by inference, but directly from the certificate.

The Russian integrations in eSIM Plus are both confirmed and live. Yandex AppMetrica is fully wired in with around 2,900 code references, communicating with Yandex infrastructure at startup and reporting events to appmetrica.io. AppMetrica derives client IP server-side by design, and location tracking is enabled.

“eSIM Plus integrates the Voximplant calling SDK across a full call stack (VoximplantCallManager, VoximplantIncomingCallService, and related classes, ~1,700 references). It routes through balancer.root.voximplant.ru — a Russian (.ru) endpoint — under the account appvillis.n8.voximplant.com. (Confirmed.)” continues the report. “These are the two specific “leads to Russia” technical indicators named in the reporting, and both are genuinely present and wired to live production hosts.”

In other words, a user making a call through eSIM Plus is routing that call through Russian infrastructure, with no indication of this in the store listing.

The data collection surface on eSIM Plus is unusually wide even by the standards of free apps. It requests 35 permissions including fine and coarse location, contacts, camera, microphone, and telephony. On top of AppMetrica it carries Mixpanel, Segment, Customer.io, AppsFlyer, Facebook SDK, Firebase, and Qonversion, plus payment SDKs and a second telephony vendor. Nicegram’s data collection footprint is similarly broad — 73 declared permissions including background location, camera, and phone identity — and it additionally bundles a non-custodial crypto wallet with seed-phrase handling and a module the researchers call “God’s Eye” that profiles Telegram users’ activity patterns by sending channel and session data to Nicegram’s servers.

“the Nicegram 1.55.0 package we examined does not contain the Yandex AppMetrica SDK, does not contain Voximplant, and contains no .by endpoints or Mobyrix strings.”continues the report. “The only Russian-hosted domains reachable from Nicegram are static-maps.yandex.ru (an optional map-tile provider inherited from upstream Telegram) and coub.com (a media-embed service) — both benign, user-action-gated, and not telemetry channels. “

The Russian-SDK evidence is in eSIM Plus, not in this specific Nicegram build. The two apps corroborate the shared-developer claim; eSIM Plus is where the Belarusian signature and Russian data flows are direct and technical.

The structural problem this research exposes is straightforward. A user in the EU installs an app that presents as Lithuanian and unknowingly routes their identifiers, location, and voice calls through analytics and telephony services in Russia, built and signed by a company in Minsk. Nothing in the store listing told them this. The trust was assumed; the reality was only recoverable by pulling the binary apart. That gap — between what an app’s label says and what the package itself contains — is invisible at install time and only legible to someone willing to do a static teardown. Most users aren’t, and shouldn’t have to be.

“For users, the practical takeaway is that an app’s store-listed “publisher” and country can differ materially from who actually builds, signs, and receives data from the software — a gap that’s invisible in the store listing but legible in the package itself.” concludes the report.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, eSIM Plus)