Lithuanian authorities have opened a national security review after reporting and technical analysis linked the Android apps Nicegram and eSIM Plus to Belarus rather than the Lithuanian branding used in app stores. Investigators said the apps were presented as products of Lithuanian company Appvillis, but code and signing artifacts tied them to Belarusian company Mobyrix and businessman Andrei Shimanovich. In the strongest finding, researchers said eSIM Plus was signed by "Mobyrix, Minsk" and included active integrations with Russian services including Yandex AppMetrica and Voximplant, with call routing through a .ru endpoint.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
Andrei Shimanovich obtained a Lithuanian temporary residence permit as a startup founder. OCCRP reports he has held this legal status since 2023.
Lithuanian authorities said they are reassessing the national security implications of Andrei Shimanovich after the reporting on the apps. The Migration Department said it will ask the State Security Department to reevaluate his risk and will involve the National Cyber Security Center and Criminal Police Bureau to examine the linked applications for vulnerabilities and possible malicious behavior.
A Buro and OCCRP investigation reported that apps presented as Lithuanian products, including Nicegram and eSIM Plus, were actually developed and maintained in Belarus and were linked technically to Shimanovich’s Belarusian company Mobyrix. The reporting also said some of the apps transmitted user data to services in Belarus and Russia, raising privacy and security concerns.
An analysis of the Android apps eSIM Plus and Nicegram found they appear to share an Appvillis-linked codebase, supporting prior reporting that the apps were allegedly developed and controlled from Belarus. The strongest technical evidence cited was in eSIM Plus, including a package signed by "Mobyrix, Minsk" and integrations with Russian services such as Yandex AppMetrica and Voximplant.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.