- What: Belarusian code found in EU apps Nicegram and eSIM Plus
- Impact: Apps may route data through Russian infrastructure
Application security Belarusian code found in popular EU app store apps Nicegram and eSIM Plus July 30, 2026 Share By SC Staff (Adobe Stock) According to Security Affairs, research has uncovered a shared codebase between two popular apps, Nicegram and eSIM Plus, available in EU app stores, with evidence suggesting a Belarusian origin and routing of data through Russian services. Mysterium VPN's research team analyzed the Android packages of Nicegram, with over 50 million downloads, and eSIM Plus, with over 1 million. Both apps are marketed as Lithuanian products. The analysis revealed that eSIM Plus is cryptographically signed by "Mobyrix, Minsk," a Belarusian entity, despite being branded as Lithuanian. Furthermore, eSIM Plus integrates with Russian services Yandex AppMetrica for analytics and Voximplant for call routing, with calls being directed through Russian infrastructure. Nicegram shares the same codebase but, in the examined version, did not contain the specific Russian SDKs found in eSIM Plus. Both applications exhibit broad data collection practices, requesting numerous permissions including location, contacts, and microphone access. eSIM Plus also includes payment SDKs, while Nicegram features a crypto wallet and a profiling module. The findings corroborate previous reports suggesting Belarusian development and control, highlighting a significant gap between app store branding and the actual origin and data handling practices of the software. Source: Security Affairs SC Staff Related AI/ML The best defense against an AI attacker might be its own safety training Harshad Sadashiv Kadam July 30, 2026 Decoys may be the best defense against fast-moving autonomous AI attacks. AI/ML OpenAI agent exploited JFrog Artifactory flaw, abused Modal customer sandbox Laura French July 30, 2026 Hugging Face and OpenAI revealed further details on the agent’s 4.5-day attack campaign. Application security DEF CON bans Meta smart glasses due to privacy concerns SC Staff July 29, 2026 Following insights from The Register, DEF CON, a prominent cybersecurity conference, has announced a ban on Meta-style glasses equipped with recording capabilities ahead of its upcoming event in Las Vegas. Related Events Cybercast Bridging the Gap from CISO-Developed Tools to Black Hat Hype: What AI Security Leaders Should Watch Next On-Demand Event Cybercast Protecting Application User Data for Better Privacy, Governance, and Compliance On-Demand Event Cybercast The Next Evolution of Application Security: AI- Accelerated DevSecOps On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Banner Browser Cache Cramming Common Gateway Interface (CGI) Client Cookie DLL Injection Dynamic Link Library You can skip this ad in 5 seconds