HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

eSIM Plus and Nicegram Use Belarus‑Linked Codebase and Route Data Through Russian Services

Security researchers found that eSIM Plus and Nicegram, marketed as Lithuanian apps, are signed by a Belarusian entity and that eSIM Plus embeds Russian analytics and call‑routing SDKs, raising supply‑chain and data‑jurisdiction concerns for SOC 2‑ready organizations.

LiveThreat™ Intelligence · 📅 July 30, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

eSIM Plus and Nicegram Use Belarus‑Linked Codebase and Route Data Through Russian Services

What Happened — Security researchers dissected the Android packages of eSIM Plus (≈ 1 M downloads) and Nicegram (≈ 50 M downloads). Both apps are marketed as Lithuanian products but are cryptographically signed by a Belarus‑based entity (“Mobyrix, Minsk”). eSIM Plus also embeds live integrations with Russian services Yandex AppMetrica (analytics) and Voximplant (call routing).

Why It Matters for Compliance & Audit Readiness

  • The shared, foreign‑origin codebase is a classic third‑party supply‑chain risk that SOC 2 vendor‑management controls are designed to identify, assess, and continuously monitor.
  • Routing user data and call traffic through Russian endpoints may violate data‑locality, privacy, and export‑control requirements, demanding documented due‑diligence and evidence of control effectiveness.
  • Continuous monitoring of code‑signing certificates and SDK usage provides audit‑ready proof that your organization is exercising reasonable oversight of mobile‑app vendors.

Who Is Affected – Consumer‑facing mobile‑messaging and eSIM management apps; broadly, any organization that integrates or recommends these apps for employee or customer communications.

Recommended Actions

  • Add eSIM Plus and Nicegram to your vendor inventory and trigger a SOC 2‑aligned third‑party risk assessment.
  • Verify code‑signing certificates, SDK provenance, and data‑flow diagrams; collect evidence of any foreign‑jurisdiction data routing.
  • Implement continuous monitoring of app updates and third‑party SDK changes to maintain an auditable trail. Source: SecurityAffairs

Technical Notes – The eSIM Plus package (v4.4.26) includes Yandex AppMetrica SDK (≈ 2,900 references) and Voximplant call‑routing SDK (≈ 1,700 references) communicating with .ru endpoints. Nicegram (v1.55.0) shares the same “Appvillis” codebase but lacks the Russian SDKs in the examined build. Both apps request fine‑grained location permissions and embed multiple analytics/marketing SDKs. Source: same as above

📰 Original Source
https://securityaffairs.com/196280/security/esim-plus-and-nicegram-share-belarus-linked-codebase-analysis-finds.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →