InterSecLab’s nine-week assessment of VK’s state-mandated Max Android messenger, version 26.12.0 build 6664, alleges that messages are not protected by end-to-end encryption and can be accessed by VK servers. The researchers said the app’s advertised “secret chats” implement message-deletion timers rather than encrypted conversations.
The report further alleges that VK can enable account-specific functions remotely—including VPN detection, enhanced logging, voice transcription, and network probing—without an app update or user notification. It also identified collection of contact and network data, including unhashed address-book uploads, public-IP and VPN checks, and a concealed reporting channel to trace-flow.ru; an installed-applications component was present but not initialized. The findings have not been independently validated, and the assessment did not document surveillance against any identified individual.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
InterSecLab published its analysis alleging that Max lacks end-to-end encryption, permits VK servers to access message content, and supports server-controlled, account-specific activation of functions including VPN detection, logging, transcription, and network probing. The report also identified the VK-associated domain trace-flow.ru as a secondary reporting channel, while stating it had not documented use of the capabilities against a specific person.
InterSecLab conducted a nine-week technical assessment of Max Android version 26.12.0 build 6664 from March through May 2026, combining pre-encryption traffic capture with static code analysis.
VK's Max messaging application was described as becoming mandatory in Russia beginning in September 2025.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourceinterseclab.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.