Application security

Belarusian code found in popular EU app store apps Nicegram and eSIM Plus

Bloggers touch screen smartphone light night city, girls using in hands mobile phone closeup, online wi-fi internet, woman texting text message

According to Security Affairs, research has uncovered a shared codebase between two popular apps, Nicegram and eSIM Plus, available in EU app stores, with evidence suggesting a Belarusian origin and routing of data through Russian services.

Mysterium VPN's research team analyzed the Android packages of Nicegram, with over 50 million downloads, and eSIM Plus, with over 1 million. Both apps are marketed as Lithuanian products. The analysis revealed that eSIM Plus is cryptographically signed by "Mobyrix, Minsk," a Belarusian entity, despite being branded as Lithuanian. Furthermore, eSIM Plus integrates with Russian services Yandex AppMetrica for analytics and Voximplant for call routing, with calls being directed through Russian infrastructure.

Nicegram shares the same codebase but, in the examined version, did not contain the specific Russian SDKs found in eSIM Plus. Both applications exhibit broad data collection practices, requesting numerous permissions including location, contacts, and microphone access. eSIM Plus also includes payment SDKs, while Nicegram features a crypto wallet and a profiling module. The findings corroborate previous reports suggesting Belarusian development and control, highlighting a significant gap between app store branding and the actual origin and data handling practices of the software.

Source: Security Affairs

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds