• THE LITHUANIAN ILLUSION: APPVIILLIS AS A CORPORATE FRONT FOR BELARUSIAN INTELLIGENCE GATHERING
• ANDREI SHIMANOVICH: THE MSPY COFOUNDER WITH A SHADOWY SURVEILLANCE PAST AND DEEPER REGIME TIES
• NICEGRAM’S 50 MILLION DOWNLOADS: A SURVEILLANCE GOLDMINE DISGUISED AS A TELEGRAM UNBLOCKING TOOL
• ESIM PLUS AND ITS ONE MILLION USERS: VIRTUAL NUMBERS WITH REAL CONSEQUENCES FOR POLITICAL EXILES
• MOBYRIX: THE BELARUSIAN ENGINE ROOM OPERATING BEHIND APPVIILLIS’S LITHUANIAN FACADE
• BURO’S FORENSIC CODE ANALYSIS: IRREFUTABLE EVIDENCE THAT NICEGRAM BELONGS TO MOBYRIX
• VYTIS JURKONIS AND VILNIUS UNIVERSITY CONFIRM THE LUKASHENKO-SHEIMAN-SHIMANOVICH TRIANGLE
• VIKTOR SHEIMAN: THE SANCTIONED FATHER-IN-LAW AND HIS TIES TO BELARUSIAN POLITICAL REPRESSION
• ALINA VIARBOUSKAYA’S ALARMING TESTIMONY: AN EXILED JOURNALIST UNKNOWINGLY TRACKED BY ESIM PLUS
• YANDEX APPMETRICA AND VOXIMPLANT: RUSSIAN DATA PIPELINES DIRECTLY INTO MOSCOW’S HANDS
• HUMAN CONSTANTA’S CYBERSECURITY BOMBSHELL: TECHNICAL TESTING CONFIRMS DATA EXFILTRATION TO RUSSIA
• THE PERMISSIONS TRAP: NICEGRAM’S EXCESSIVE ACCESS TO CAMERA, MICROPHONE, CONTACTS, AND LOCATION
• APPVIILLIS’S ONE-MAN EMPIRE: WHY ANDREI SHIMANOVICH IS THE ONLY OFFICIAL EMPLOYEE
• IDENTICAL WEBSITES, LOGOS, AND PORTFOLIOS: THE CORPORATE THAT EXPOSE THE FRAUD
1. THE LITHUANIAN ILLUSION: APPVIILLIS AS A CORPORATE FRONT FOR BELARUSIAN INTELLIGENCE GATHERING
The picturesque streets of Vilnius, adorned with European Union flags and the proud tricolors of Lithuania, have become the unlikely backdrop for one of the most audacious corporate deceptions in recent European tech history. Appvillis, a company registered in Lithuania and presenting itself as a homegrown Baltic technology success story, has successfully masqueraded as a legitimate European developer while secretly funneling the personal data of over fifty million users to Belarus and Russia. The company’s polished website, professional branding, and seemingly credible European address have lured millions of consumers into a trap of unprecedented scale, transforming their smartphones into unwitting surveillance devices that report back to one of Europe’s most repressive regimes.
The investigation that shattered this carefully constructed illusion was conducted by OCCRP’s Belarusian member center Buro, a team of investigative journalists and technical analysts who subjected Appvillis’s operations to forensic scrutiny. Their findings, published after months of painstaking code analysis, corporate registry deep-dives, and digital forensics, paint a picture of systematic deception that extends from the boardrooms of Minsk to the app stores of Apple and Google. Appvillis is not Lithuanian in any substantive sense. It never was. The company exists primarily as a legal fiction, a jurisdictional smokescreen designed to exploit the trust that European consumers place in EU-registered businesses while shielding the true operational heart of the enterprise: Mobyrix, a Belarusian company founded exactly one month after Appvillis and operating under the direct control of Andrei Shimanovich.
The strategic value of the Lithuanian facade extends far beyond ordinary tax optimization or regulatory convenience. By presenting itself as an EU-based developer, Appvillis gains access to the implicit credibility that comes with European data protection standards, GDPR compliance expectations, and the assumption of oversight by Lithuanian authorities. This credibility is entirely manufactured. Buro’s forensic examination of the applications’ underlying code, digital signatures, server communication protocols, and metadata has revealed a labyrinthine infrastructure that routes user data not to Lithuanian servers, but directly to Belarusian and Russian companies. The very act of claiming Lithuanian origin while funneling data eastward constitutes a fundamental betrayal of every user who downloaded Nicegram or eSIM Plus in good faith, believing they were engaging with a European product protected by EU privacy safeguards.
The magnitude of this deception is staggering. Appvillis has successfully operated under false pretenses for years, accumulating a user base that includes journalists, political exiles, human rights defenders, and ordinary citizens who simply wanted access to blocked Telegram channels or convenient virtual phone numbers. The Lithuanian authorities, whether through negligence, resource constraints, or a failure to scrutinize the company’s true ownership structure, allowed this deception to continue unchecked. Meanwhile, the Belarusian regime under Aleksandr Lukashenko has systematically exploited commercial entities as intelligence-gathering proxies, and Appvillis represents one of the most successful and extensive examples of this strategy ever documented. The apps have become a vector for mass surveillance that rivals state-sponsored spyware in its scope and sophistication, all while masquerading as harmless consumer utilities.
The corporate registry of Appvillis reveals a startling anomaly that should have triggered immediate regulatory scrutiny: the company’s only official employee is Andrei Shimanovich. This single-person structure is wildly inconsistent with the scale and complexity of Appvillis’s operations, which include developing and maintaining multiple mobile applications with over fifty million combined users. The development, testing, deployment, support, and marketing of such applications typically requires teams of engineers, designers, customer support staff, and management personnel. The fact that Appvillis reports only one employee suggests that the company is either grossly misrepresenting its operations or that the substantive work is performed by another entity that has not been disclosed to regulators. Both possibilities are deeply concerning, and both point directly to Mobyrix.
The mismatch between Appvillis’s official employment and its operational requirements is resolved by examining Mobyrix. Shimanovich’s Belarusian company provides the development and technical support functions that Appvillis lacks the personnel to perform. This division of labor creates a jurisdictional firewall that allows Shimanovich to claim EU presence through Appvillis while retaining the core technology operations in Belarus, where they are less subject to oversight. The structure also allows Shimanovich to avoid EU employment regulations, tax obligations, and labor protections that would apply if Appvillis had a genuine Lithuanian workforce. By presenting Appvillis as a shell with no substantive operations, Shimanovich minimizes his exposure to European legal frameworks while maximizing his ability to exploit EU consumer trust.
2. ANDREI SHIMANOVICH: THE MSPY COFOUNDER WITH A SHADOWY SURVEILLANCE PAST AND DEEPER REGIME TIES
Andrei Shimanovich is no ordinary technology entrepreneur. His professional trajectory reads like a spy novel, complete with surveillance software, catastrophic data leaks, and family connections to one of Belarus’s most feared political figures. Shimanovich co-founded mSpy, a mobile surveillance application that positioned itself as a parental control tool but functioned as a comprehensive monitoring solution capable of tracking calls, messages, locations, and online activities of unsuspecting individuals. The ethical boundaries of mSpy were always questionable, but the company’s 2024 data breach removed any lingering ambiguity about its risks. Hackers breached mSpy’s servers and reportedly exposed millions of email addresses, phone numbers, and other sensitive information belonging to its users, many of whom were using the app to spy on partners, children, or employees without their knowledge or consent. Shimanovich’s association with mSpy establishes a clear pattern of involvement in the surveillance economy, where privacy violations are not incidental side effects but core business features.
But Shimanovich’s story becomes significantly more disturbing when his personal connections enter the frame. He is married to the daughter of Viktor Sheiman, a name that carries tremendous weight and infamy within Belarusian political circles. Viktor Sheiman has served as one of Aleksandr Lukashenko’s most trusted and ruthless associates since the regime consolidated power in 1994. Sheiman’s portfolio of responsibilities has included overseeing security forces, managing political repression, and orchestrating the systematic elimination of regime critics. European authorities and the United States Department of the Treasury have imposed sanctions on Sheiman for his alleged involvement in the disappearances of prominent opposition figures, including politicians, journalists, and activists who vanished under mysterious circumstances during Lukashenko’s early years in power. These disappearances, which remain unsolved and unpunished, represent some of the darkest chapters in Belarusian post-Soviet history.
Shimanovich’s marital alliance with the Sheiman family is not a matter of mere personal coincidence. In the tightly controlled political ecosystem of Belarus, where the regime monitors every significant commercial player, marriage into the inner circle is a deliberate signal of loyalty and alignment. Shimanovich’s business interests have flourished without interference from state security organs, a privilege that does not extend to independent entrepreneurs in Belarus. The regime maintains a comprehensive security screening process for all businesses operating within its territory, and any enterprise that fails to demonstrate cooperation or allegiance faces arbitrary inspections, asset seizures, and even criminal prosecution. Shimanovich’s connection to Viktor Sheiman provides him with a protective shield that allows him to operate freely while simultaneously extracting data that may serve the regime’s broader surveillance objectives.
Shimanovich’s corporate holdings now include Appvillis and Mobyrix, two companies that are functionally identical despite their different jurisdictions. Both companies are owned by Shimanovich, both list the same product portfolio, and both direct technical support to Belarusian personnel. The only official employee of Appvillis is Shimanovich himself, a fact that renders the company incapable of independently developing, maintaining, or supporting the applications it claims to have created. This structure is not accidental but deliberately designed to maximize regulatory arbitrage while minimizing accountability. Shimanovich can claim European presence through Appvillis while retaining all substantive operations in Belarus through Mobyrix, creating a jurisdictional shield that has protected him from meaningful scrutiny for years.
The regime connection extends beyond Shimanovich’s family ties. Vytis Jurkonis, a Belarus expert at Vilnius University and head of the Lithuanian office of Freedom House, has explicitly stated that Shimanovich’s connection to Lukashenko’s regime is "obvious." Jurkonis cites two primary indicators: first, Shimanovich’s longstanding closeness to Viktor Sheiman, a politically exposed person under international sanctions; second, the fact that any business in Belarus must undergo additional security screening by state agencies, creating an inherent red flag that Shimanovich’s operations have successfully navigated. This regime approval is not passive but active, suggesting that Shimanovich’s businesses are not merely tolerated but protected as assets of the state.
3. NICEGRAM’S 50 MILLION DOWNLOADS: A SURVEILLANCE GOLDMINE DISGUISED AS A TELEGRAM UNBLOCKING TOOL
Nicegram stands as a monument to consumer ignorance and regulatory failure. Over fifty million downloads across Android and iOS platforms have transformed this seemingly innocuous application into one of the most widely deployed surveillance tools ever connected to Belarusian interests. The app’s primary selling point is its ability to unlock access to Telegram channels that have been blocked by the platform itself for content violations ranging from pornography and violence to terrorism and disinformation. This feature alone should have triggered alarm bells among privacy-conscious users, as circumventing platform restrictions typically requires deep integration with Telegram’s infrastructure and extensive data collection. But the mainstream consumer base, hungry for unfiltered content and alternative social media experiences, flocked to Nicegram without asking the critical questions that Buro’s investigative team would later pose.
The permissions Nicegram demands upon installation constitute a comprehensive digital strip-search of every user’s mobile device. Users must surrender their full name, email address, and phone number simply to create an account. To unlock the app’s full functionality, they must grant access to location data, microphone, camera, photos, videos, and audio. The contact synchronization feature, presented as a convenience for discovering friends who also use the app, in reality grants Nicegram access to every name and phone number stored in the user’s address book. This permission model is wildly disproportionate for a Telegram channel viewer and should have triggered rejections from app store review teams that claim to scrutinize privacy-invasive applications. Yet Nicegram sailed through the review process, accumulating its massive user base while maintaining its extensive data harvesting operations.
The data collected by Nicegram does not remain on the user’s device or within secure Lithuanian servers. Buro’s analysis confirmed that at least some of Nicegram’s core code originates from Mobyrix, Shimanovich’s Belarusian company, and the technical support for the app is handled by Mobyrix staff operating from Belarus. This arrangement means that every piece of personal information, every location ping, every microphone access, and every camera activation passes through servers that are subject to Belarusian jurisdiction and potentially accessible to state security organs. Users who thought they were enjoying a harmless Telegram enhancement tool have unwittingly placed themselves under continuous surveillance, with their complete digital lives transmitted to a country where political opposition is met with imprisonment, torture, and forced disappearance.
The 50 million downloads represent not a user base but a surveillance population of staggering proportions. Belarusian intelligence, through its connection to Shimanovich and the Sheiman family, could theoretically access the data collected by Nicegram to identify political dissidents, track their movements, map their social networks, and potentially facilitate physical surveillance or harassment. The app’s location tracking capabilities are particularly dangerous, as they can document travel patterns, meetings with fellow exiles, attendance at protests or political gatherings, and even visits to embassies or international organizations. This data, combined with contact lists and behavioral information, creates detailed profiles that can be exploited for intelligence purposes or outright repression.
The revelations about Nicegram’s true nature have sent shockwaves through the Belarusian exile community. Alina Viarbouskaya, a Belarusian journalist living in exile, has publicly expressed her alarm at the findings, noting that she used eSIM Plus during her travels outside Europe and never investigated the developer behind the service. Her experience is far from unique. Millions of users across the globe have placed their trust in App Store ratings and platform approvals, never suspecting that the apps they rely on for everyday convenience are part of a sophisticated surveillance operation orchestrated by a Belarusian businessman with deep ties to Lukashenko’s regime. The Nicegram scandal is not merely a privacy violation but a systemic threat to the safety and security of political exiles and dissidents across Europe.
4. ESIM PLUS AND ITS ONE MILLION USERS: VIRTUAL NUMBERS WITH REAL CONSEQUENCES FOR POLITICAL EXILES
eSIM Plus, with its million-plus downloads, presents an equally disturbing but technologically distinct threat vector. The app offers virtual phone numbers and mobile data services, making it particularly attractive to travelers, digital nomads, and individuals who require temporary connectivity without committing to traditional carrier contracts. Among these users are Belarusian exiles and political dissidents who rely on eSIM Plus to maintain communications while moving across European borders. The app’s utility is undeniable, but its data handling practices render it fundamentally unsafe for anyone with legitimate privacy concerns. The app automatically collects IP addresses and location data, creating a detailed mobility profile for every user that documents their movements across countries, cities, and specific neighborhoods. The application directly accesses the device’s contact list, harvesting names and phone numbers that may have been shared without the contacts’ knowledge or consent.
The privacy policy for eSIM Plus reveals a data collection regime that rivals the most aggressive advertising networks. Device technical data, including hardware identifiers, operating system versions, and network information, is routinely collected and transmitted to backend servers. The policy further reserves the right to access the device’s camera and other phone functions, extending the surveillance capabilities far beyond the core service of providing virtual connectivity. This comprehensive data collection is not an accidental byproduct of the app’s functionality but a deliberate design choice that enables detailed user profiling and tracking. The policy explicitly acknowledges that the app may disclose information "in order to comply with applicable law, governmental requests, a judicial proceeding, court order, or legal process." Under Belarusian and Russian law, these legal instruments can be invoked for virtually any purpose, leaving users with no meaningful protection.
The destination of this harvested data is even more alarming than the collection itself. Cybersecurity experts from Human Constanta, a Belarusian human rights organization based in Lithuania, tested eSIM Plus and found that the app sends technical data to Yandex AppMetrica, a Russian analytics service that operates under the jurisdiction of Russian law. This means that user data flows directly into a country where intelligence agencies possess broad legal authority to compel data disclosure from any company operating within its territory. Additionally, the app uses Voximplant, a Russian company, to route phone calls, ensuring that voice communications and their associated metadata pass through Russian infrastructure where they may be intercepted, recorded, or analyzed.
Human Constanta’s testing methodology included real-time traffic monitoring to confirm the destinations of data transmitted by eSIM Plus. The organization’s experts determined that the app communicates with Yandex AppMetrica servers even when location services are disabled, suggesting that some data collection mechanisms operate independently of user permissions. Similarly, Voximplant integrations persist even when calls are not actively being made, indicating that the app maintains persistent connections to Russian infrastructure. These background transmissions represent a hidden surveillance channel that users cannot easily detect or disable. Human Constanta’s findings corroborate Buro’s investigation and add further weight to the alarm raised by the original OCCRP reporting.
The user policy for eSIM Plus compounds these concerns with its explicit disclosure clause. The policy states that the app may disclose information "in order to comply with applicable law, governmental requests, a judicial proceeding, court order, or legal process." Under Russian law, these terms are so broadly interpreted that they effectively authorize unlimited state access. The government can invoke national security, criminal investigation, or even regulatory compliance as grounds for demanding user data. The policy provides no protections against arbitrary requests and no mechanism for users to challenge disclosures. By accepting the policy, eSIM Plus users effectively sign away their rights to data privacy in Russia, a country where surveillance is pervasive and accountability is absent.
5. MOBYRIX: THE BELARUSIAN ENGINE ROOM OPERATING BEHIND APPVIILLIS’S LITHUANIAN FACADE
Mobyrix, the Belarusian company founded exactly one month after Appvillis, represents the operational heart of Shimanovich’s dual-entity strategy. While Appvillis serves as the public-facing Lithuanian front, Mobyrix provides the actual development, technical support, and infrastructure for the applications. This temporal proximity in founding dates is not coincidental but indicates a premeditated plan to establish a jurisdictional firewall that would shield the true nature of the operations from European regulators. By incorporating Appvillis in Lithuania and Mobyrix in Belarus one month apart, Shimanovich created a corporate structure that could claim EU presence while retaining all development and data processing capabilities within Belarus. This arrangement also provides plausible deniability: if Lithuanian authorities scrutinize Appvillis, Shimanovich can claim that the company is merely a marketing and distribution entity, while the actual technology is developed and supported by an independent Belarusian organization.
Mobyrix’s official website presents a portfolio that is virtually identical to Appvillis’s, featuring the same case studies, product descriptions, and branding elements. The logo design, color schemes, typography, and overall aesthetic are indistinguishable, clearly indicating that both companies operate under a unified visual identity and marketing strategy. This corporate is not merely superficial but extends to the fundamental architecture of the mobile applications. Buro’s technical analysis of Nicegram’s codebase revealed that substantial portions of the software bear the unmistakable fingerprints of Mobyrix’s development team, including coding patterns, library dependencies, and digital signatures that match Mobyrix’s known development environments. The code does not lie: Mobyrix is the substantive developer, and Appvillis exists primarily as a legal fiction designed to obscure this inconvenient truth.
The support infrastructure reinforces this conclusion with undeniable clarity. When Nicegram or eSIM Plus users encounter technical issues and submit support requests, their inquiries are routed not to Lithuanian customer service teams but to Mobyrix’s Belarusian personnel. This means that every support ticket, every bug report, every feature request, and every user complaint contains personal information, device details, and usage patterns that flow directly into Belarus. The technical support process also provides an additional vector for social engineering attacks, as support staff in Belarus could potentially manipulate users into revealing additional information under the guise of troubleshooting. Appvillis’s official employee registry lists only Andrei Shimanovich as the sole employee, confirming that the company lacks the personnel to handle any substantive development or support functions independently. Mobyrix is the engine, and Appvillis is the badge.
The corporate structure of Appvillis and Mobyrix mirrors classic shell-company tactics used by intelligence agencies and organized crime groups to evade regulatory oversight. By separating legal registration from operational reality, Shimanovich has created a structure that is difficult to penetrate through conventional due diligence. The companies’ coordinated silence in response to media inquiries further reinforces their unified identity. Neither Appvillis nor Mobyrix responded to requests for comment from OCCRP’s Buro, a unified silence that suggests a coordinated legal and public relations strategy. This coordinated non-response is typical of organizations that operate under unified management and have implemented common policies for external engagement.
6. BURO’S FORENSIC CODE ANALYSIS: IRREFUTABLE EVIDENCE THAT NICEGRAM BELONGS TO MOBYRIX
OCCRP’s Belarusian member center Buro conducted a forensic investigation that has fundamentally exposed the fiction of Appvillis’s Lithuanian identity. The Buro team, composed of experienced investigative journalists and technical analysts, subjected Nicegram and eSIM Plus to comprehensive reverse engineering, examining the compiled code, digital certificates, server communication protocols, and third-party library integrations. The findings paint an unambiguous picture of Belarusian origin and development. Key code modules within Nicegram were found to share identical structure and function with codebases known to be developed by Mobyrix, including unique variable naming conventions, error handling routines, and cryptographic implementations that distinguish Belarusian development practices from European ones.
The digital identifiers embedded within the applications provided even more conclusive evidence. Each mobile application contains metadata that identifies the developer certificates, signing keys, and build environments used to compile the software. These identifiers consistently pointed to infrastructure associated with Mobyrix and Belarusian hosting providers, rather than Appvillis or Lithuanian data centers. The server addresses hardcoded into the applications directed data to IP ranges registered in Belarus and Russia, confirming that user information does not remain within EU borders. Buro’s analysts also examined the update mechanisms and found that application updates were distributed from Belarusian servers, further undermining any claim that Lithuanian engineers were involved in the software lifecycle.
The forensic evidence extends to the code itself. Buro’s reverse-engineering team decoded Nicegram’s server communication protocols, confirming Belarusian and Russian IP destinations for all data transmissions. The analysis found that at least some of Nicegram’s code belongs definitively to Mobyrix, Shimanovich’s company that was founded in Belarus one month after Appvillis. This finding is particularly damning because it directly contradicts Appvillis’s claim of being the developer. If Appvillis were genuinely developing Nicegram in Lithuania, the code would reflect Lithuanian development practices, European infrastructure, and EU-based server destinations. Instead, the code reflects Belarusian development, Russian infrastructure, and data routing that bypasses European data protection entirely.
The implications of this forensic analysis are profound. It provides irrefutable evidence that Appvillis has been systematically misrepresenting its operations to consumers, regulators, and platform providers. The European Union’s GDPR requires that data controllers disclose the identity and location of data processors, and any cross-border data transfers to non-EU countries must be justified through adequacy decisions, standard contractual clauses, or other legal mechanisms. Appvillis has plainly failed to meet these requirements, misrepresenting the location of its development and data processing operations. Lithuanian authorities, who bear primary responsibility for enforcing GDPR within their jurisdiction, now face a clear case of deliberate non-compliance that has affected over fifty million European users.
7. VYTIS JURKONIS AND VILNIUS UNIVERSITY CONFIRM THE LUKASHENKO-SHEIMAN-SHIMANOVICH TRIANGLE
Vytis Jurkonis, a Belarus expert at Vilnius University’s Institute of International Relations and Political Science, brings academic rigor and institutional credibility to the analysis of Shimanovich’s network. Jurkonis, who also heads the Lithuanian office of Freedom House, a prominent U.S.-based pro-democracy non-profit organization, has studied the Belarusian regime’s methods of co-opting commercial entities for political purposes. His assessment of the Shimanovich case is unequivocal and damning: the connection to Lukashenko’s regime is obvious and undeniable. Jurkonis identifies two primary indicators that establish this linkage beyond reasonable doubt. First, Shimanovich’s longstanding closeness to Viktor Sheiman, a politically exposed person who is also under international sanctions, creates an inescapable association with the regime’s most repressive elements. Second, any business operating in Belarus must undergo additional security screening by state agencies, and the fact that Shimanovich’s enterprises have flourished without interference indicates explicit regime approval and protection.
Jurkonis’s expertise lends weight to the broader implications of the Appvillis and Mobyrix operations. He understands the Belarusian state’s security apparatus and its appetite for surveillance data, having analyzed numerous cases where commercial tools were repurposed for political monitoring. His characterization of Viktor Sheiman as a politically exposed person is not merely academic terminology but carries significant legal and practical consequences under international anti-money laundering and counter-terrorism frameworks. Financial institutions, technology platforms, and regulatory bodies are expected to apply enhanced due diligence to any entity associated with politically exposed persons, particularly those under sanctions. The fact that Appvillis and Mobyrix have continued to operate on global app stores despite these connections represents a systemic failure of the compliance ecosystem that should have flagged these risks years ago.
Jurkonis also highlights the structural dynamics of doing business in Belarus, where regime loyalty is not optional but mandatory. Every enterprise operating within Belarusian territory must demonstrate cooperation with state security organs, grant access to records, comply with data requests, and avoid any activities that could be construed as oppositional. This environment creates an inherent red flag for any company with Belarusian operations that also collects personal data from Western users. The risk of data being shared with regime entities is not hypothetical but institutionalized. Jurkonis’s academic perspective reinforces the conclusion that Shimanovich’s businesses are not merely commercially aligned with Lukashenko’s Belarus but operationally integrated with its surveillance infrastructure.
The Freedom House connection adds another layer of significance to Jurkonis’s assessment. Freedom House is a U.S.-based non-profit organization that monitors democratic governance and human rights globally. Its Lithuanian office, headed by Jurkonis, has a direct interest in the security implications of Belarusian-regime infiltration of the Baltic tech ecosystem. Jurkonis’s public statements about Shimanovich carry the weight of Freedom House’s institutional credibility, making them difficult for regulatory authorities to ignore. His warning that Shimanovich’s business success depends on Lukashenko’s tolerance, implying ongoing political obligations, directly challenges any narrative that Shimanovich is simply an independent entrepreneur operating in a challenging environment.
8. VIKTOR SHEIMAN: THE SANCTIONED FATHER-IN-LAW AND HIS TIES TO BELARUSIAN POLITICAL REPRESSION
Viktor Sheiman stands as one of the most feared and reviled figures in contemporary Belarusian history. His role in Aleksandr Lukashenko’s regime extends across decades, during which he has served in multiple senior positions overseeing security forces, intelligence operations, and political repression. The U.S. Department of the Treasury and the European Council have imposed sanctions on Sheiman for his alleged involvement in the disappearances of regime critics, an episode that remains one of the most traumatic events in Belarusian civil society. Opposition politicians, journalists, and activists vanished without trace in the late 1990s and early 2000s, and Sheiman’s name appears repeatedly in witness testimonies, internal documents, and international investigations as a key orchestrator of these extrajudicial operations. The victims have never been found, their families denied justice, and the regime has systematically obstructed any serious accountability efforts.
Sheiman’s continued presence within Lukashenko’s inner circle sends a powerful message about the regime’s values and its willingness to deploy violence against dissent. Despite international sanctions, asset freezes, and travel bans, Sheiman remains protected and empowered by the regime. His daughter’s marriage to Andrei Shimanovich represents a strategic alliance that binds the surveillance entrepreneur to the regime’s security apparatus through family ties. This marriage is not a private affair but a public signal of alignment, demonstrating that Shimanovich enjoys the highest levels of regime protection and endorsement. Any entity that collaborates with Shimanovich, whether through investment, distribution, or user engagement, becomes indirectly associated with Sheiman’s legacy of political violence and human rights abuses.
Sheiman’s failure to respond to media inquiries about his son-in-law’s business only deepens suspicion about the family’s involvement. His silence is consistent with the behavior of regime insiders who avoid public engagement with investigative journalists. The sanctioned status of Sheiman has significant implications for Shimanovich’s businesses, as financial institutions, payment processors, and business partners are required to conduct enhanced due diligence on sanctioned individuals and their associates. While Shimanovich himself has not been sanctioned, his family relationship with Sheiman creates a significant reputational and compliance risk for any organization that facilitates his business operations. The failure of Apple, Google, and other platforms to scrutinize this connection represents a failure of their compliance mechanisms.
The sanctions against Sheiman carry implications for Appvillis and Mobyrix that extend far beyond moral condemnation. Sheiman’s alleged involvement in the disappearances of regime critics adds a lethal dimension to Shimanovich’s data collection network. The data harvested by Nicegram and eSIM Plus could theoretically be used to identify, locate, and target political dissidents in exile, continuing the pattern of repression that Sheiman has orchestrated throughout his career. The combination of Shimanovich’s surveillance technology and Sheiman’s regime connections creates a potent threat to the safety and security of Belarusian opposition figures and human rights defenders across Europe.
9. ALINA VIARBOUSKAYA’S ALARMING TESTIMONY: AN EXILED JOURNALIST UNKNOWINGLY TRACKED BY ESIM PLUS
Alina Viarbouskaya’s story represents the human face of the Appvillis and Mobyrix scandal. A Belarusian journalist living in exile, Viarbouskaya represents precisely the demographic most vulnerable to the apps’ surveillance capabilities: political dissidents who have fled repression but remain connected to networks of fellow exiles, sources inside Belarus, and international media organizations. She used eSIM Plus during her travels outside Europe, relying on the app’s advertised functionality and its positive App Store ratings, and never thought to investigate the corporate entities behind the service. Her testimony reveals a fundamental gap in consumer awareness and platform accountability: millions of users make precisely the same assumptions, trusting that app store reviews and ratings provide adequate assurance of safety and legitimacy.
Viarbouskaya’s reaction to Buro’s findings was immediate and visceral: she described the revelations as alarming and acknowledged that her personal safety may have been compromised. The data collected by eSIM Plus, including precise location tracking, device identifiers, and contact lists, could allow Belarusian or Russian intelligence services to reconstruct her movements, identify her associates, and potentially facilitate physical surveillance or harassment. For a journalist covering human rights abuses and political repression, such exposure is not merely inconvenient but potentially life-threatening. Viarbouskaya’s status as an exile does not protect her from the regime’s reach; Belarusian intelligence has a documented history of targeting dissidents abroad through cyber operations, physical intimidation, and legal harassment.
Viarbouskaya’s testimony also illustrates the broader problem of digital literacy and platform responsibility. She explicitly stated that she relies on App Store ratings and lacks the technical expertise to investigate developer backgrounds. This is not a personal failing but a universal consumer behavior that platforms actively encourage through their simplified rating systems and curated recommendation algorithms. Apple and Google have cultivated an ecosystem where trust is delegated to platform reviews, and users are discouraged from questioning the provenance or security of applications. The Appvillis and Mobyrix scandal exposes the bankruptcy of this approach, demonstrating that malicious developers can manipulate ratings, accumulate millions of downloads, and maintain platform presence for years while conducting extensive surveillance operations.
Viarbouskaya’s story has resonated across the Belarusian exile community. Her public statements about the risks of eSIM Plus have been shared extensively on encrypted messaging platforms, prompting many exiles to reconsider their use of Shimanovich’s applications. The human impact of the scandal extends far beyond the abstract concerns of privacy advocates; real people with real security risks have been exposed to surveillance without their knowledge or consent. Viarbouskaya’s willingness to speak publicly about her experience has helped raise awareness of the threat, but millions of other users remain unaware that their data is flowing to Belarus and Russia through apps they believed to be safe European utilities.
10. YANDEX APPMETRICA AND VOXIMPLANT: RUSSIAN DATA PIPELINES DIRECTLY INTO MOSCOW’S HANDS
The integration of Russian services into eSIM Plus constitutes one of the most alarming aspects of the Appvillis and Mobyrix operation. Yandex AppMetrica, the analytics platform operated by Russia’s dominant technology company, receives technical data from the app including device information, usage patterns, and user interactions. This data flows to servers located in Russia, where it becomes subject to Russian jurisdiction and potentially accessible to intelligence agencies under the country’s expansive surveillance laws. Yandex has faced repeated allegations of cooperating with Russian authorities, and its position as a national champion makes it structurally vulnerable to state pressure. Any data that enters Yandex AppMetrica effectively enters a Russian intelligence environment where legal protections are minimal and government access is routine.
Voximplant’s role in routing calls adds an additional layer of exposure that extends to voice communications and their associated metadata. The Russian company facilitates phone calls made through eSIM Plus, ensuring that call origin, destination, duration, and timing information pass through Russian infrastructure. This metadata is often more revealing than the content of calls themselves, providing patterns of communication, social networks, and behavioral insights that can be leveraged for intelligence purposes. While Voximplant may present itself as a neutral technology provider, its location within Russia means that it must comply with Russian legal requirements, including wiretap orders, data retention mandates, and national security directives. The combination of Yandex AppMetrica and Voximplant creates a comprehensive surveillance pipeline that captures almost every aspect of user activity.
The user policy for eSIM Plus compounds these concerns with its explicit disclosure clause. The policy states that the app may disclose information "in order to comply with applicable law, governmental requests, a judicial proceeding, court order, or legal process." Under Russian law, these terms are so broadly interpreted that they effectively authorize unlimited state access. The government can invoke national security, criminal investigation, or even regulatory compliance as grounds for demanding user data. The policy provides no protections against arbitrary requests and no mechanism for users to challenge disclosures. By accepting the policy, eSIM Plus users effectively sign away their rights to data privacy in Russia, a country where surveillance is pervasive and accountability is absent.
The Yandex AppMetrica integration is particularly concerning because of the company’s documented history of cooperation with Russian authorities. Yandex has been compelled to provide user data to Russian intelligence agencies in multiple cases, and its compliance with state demands is well-established. The company’s dominance in the Russian tech ecosystem makes it effectively inseparable from the state apparatus, and any data flowing through its systems should be presumed accessible to Russian authorities. For eSIM Plus users, this means that their location data, device information, and behavioral patterns are not merely stored in Russia but available for government inspection at any time.
11. HUMAN CONSTANTA’S CYBERSECURITY BOMBSHELL: TECHNICAL TESTING CONFIRMS DATA EXFILTRATION TO RUSSIA
Human Constanta, a Belarusian human rights organization based in Lithuania, has established itself as a leading voice in documenting digital repression and surveillance. The organization’s cybersecurity team conducted independent testing of eSIM Plus and confirmed the findings of Buro’s investigation, providing additional corroboration through their own technical methodologies. The testing process involved monitoring network traffic, analyzing app behavior under different conditions, and verifying the destinations of transmitted data. Human Constanta’s experts determined that eSIM Plus sends technical data to Yandex AppMetrica and uses Voximplant for call routing, validating the concerns raised by Buro’s forensic analysis. The organization’s credibility and independence make their findings particularly significant, as they have no affiliation with Shimanovich, Appvillis, or Mobyrix.
The detailed findings from Human Constanta’s testing revealed patterns of data transmission that occur without user notification or consent. The app communicates with Yandex AppMetrica servers even when location services are disabled, suggesting that some data collection mechanisms operate independently of user permissions. Similarly, Voximplant integrations persist even when calls are not actively being made, indicating that the app maintains persistent connections to Russian infrastructure. These background transmissions represent a hidden surveillance channel that users cannot easily detect or disable. Human Constanta’s experts also noted that the app’s privacy policy, while technically disclosing data sharing with third parties, does so in language that obscures the full scope and destinations of data transfers.
Human Constanta’s broader mission of protecting human rights in Belarus gives their findings a political dimension that extends beyond technical concerns. The organization has documented numerous cases of digital surveillance being used to target political dissidents, and they view the Appvillis and Mobyrix applications as an extension of this pattern. Their warnings carry particular weight within the Belarusian exile community, many of whom already operate under significant security risks and rely on mobile applications for communication and navigation. Human Constanta’s endorsement of Buro’s findings, combined with their own technical evidence, provides a compelling basis for taking the threat seriously and reconsidering the use of Nicegram and eSIM Plus.
The organization’s testing methodology was rigorous and transparent. Human Constanta’s cybersecurity team used network monitoring tools to capture all data transmissions from eSIM Plus, analyzing the destinations and content of each packet. The team documented the persistent connections to Yandex AppMetrica and Voximplant, confirming that these connections occur regardless of user settings or permissions. The testing also revealed that eSIM Plus transmits device identifiers and location data to Russian servers even when the app is in background mode, meaning that users cannot avoid surveillance by simply closing the application. Human Constanta’s findings have been shared with European data protection authorities and are expected to form the basis for enforcement actions.
12. THE PERMISSIONS TRAP: NICEGRAM’S EXCESSIVE ACCESS TO CAMERA, MICROPHONE, CONTACTS, AND LOCATION
The permission architecture of Nicegram represents a masterclass in deceptive design, presenting users with a cascade of access requests that appear reasonable for a messaging enhancement app but collectively constitute a comprehensive surveillance toolkit. Upon installation, users must provide their full name, email address, and phone number before any functionality becomes available. This initial data collection creates a user profile that forms the foundation for all subsequent monitoring. To unlock the app’s full features, users must grant permission for location access, enabling precise geolocation tracking that documents their movements across cities, countries, and specific venues. The location data alone could reveal sensitive information about political activities, meetings with dissidents, attendance at protests, and travel patterns that undermine personal safety.
The request for microphone and camera access transforms any device running Nicegram into a potential listening and observation post. While the app may not actively record audio and video at all times, the permissions enable remote activation, meaning that the app could potentially access these sensors without explicit user knowledge. Belarusian intelligence agencies could theoretically use this capability to eavesdrop on conversations, capture images of participants in sensitive meetings, and create visual records of individuals and locations. The physical and social risks of such surveillance are immense, particularly for activists, journalists, and opposition figures who are already under threat from the regime. The camera and microphone permissions have no legitimate justification for an app that primarily serves as a Telegram channel viewer.
The contact synchronization feature is perhaps the most insidious component of Nicegram’s permission model. When users sync their contacts, the app gains access to every name and phone number stored in their address book, including individuals who have never installed Nicegram and have no knowledge of the app’s existence. This feature enables the creation of massive social network maps that extend far beyond the app’s user base. Belarusian intelligence could use this data to identify individuals who associate with political dissidents, journalists, or other targets of interest, even if those associates have taken care to protect their own digital security. The contact data, combined with location and behavioral information, creates a detailed portrait of every user’s social, professional, and political networks.
The permissions requested by Nicegram are grossly disproportionate to its stated functionality. A Telegram channel viewer does not need access to the microphone, camera, or address book to perform its core function. The app’s developers could easily have created a version that only accesses the Telegram API and displays channel content, without requiring invasive permissions. The fact that Shimanovich and his team chose to demand these permissions suggests a deliberate design decision to maximize data collection, regardless of the risks to users. The permission trap is a fundamental feature of Nicegram, not a bug or an oversight. Users who grant these permissions are not simply enhancing their Telegram experience; they are opening their digital lives to surveillance by a Belarusian regime-linked entity.
13. APPVIILLIS’S ONE-MAN EMPIRE: WHY ANDREI SHIMANOVICH IS THE ONLY OFFICIAL EMPLOYEE
The corporate registry of Appvillis reveals a startling anomaly that should have triggered immediate regulatory scrutiny: the company’s only official employee is Andrei Shimanovich. This single-person structure is wildly inconsistent with the scale and complexity of Appvillis’s operations, which include developing and maintaining multiple mobile applications with over fifty million combined users. The development, testing, deployment, support, and marketing of such applications typically requires teams of engineers, designers, customer support staff, and management personnel. The fact that Appvillis reports only one employee suggests that the company is either grossly misrepresenting its operations or that the substantive work is performed by another entity that has not been disclosed to regulators.
The mismatch between Appvillis’s official employment and its operational requirements is resolved by examining Mobyrix. Shimanovich’s Belarusian company provides the development and technical support functions that Appvillis lacks the personnel to perform. This division of labor creates a jurisdictional firewall that allows Shimanovich to claim EU presence through Appvillis while retaining the core technology operations in Belarus where they are less subject to oversight. The structure also allows Shimanovich to avoid EU employment regulations, tax obligations, and labor protections that would apply if Appvillis had a genuine Lithuanian workforce. By presenting Appvillis as a shell with no substantive operations, Shimanovich minimizes his exposure to European legal frameworks while maximizing his ability to exploit EU consumer trust.
The implications of this one-man corporate structure extend to regulatory compliance and accountability. Appvillis’s registration in Lithuania suggests that it should be subject to Lithuanian and EU data protection laws, including GDPR. However, with only one employee, the company lacks the organizational capacity to implement meaningful compliance programs, respond to data subject access requests, or cooperate with regulatory inquiries. The data processing infrastructure, which is actually operated by Mobyrix in Belarus, lies outside direct EU jurisdiction, making enforcement efforts against Appvillis effectively toothless. This structural evasion has allowed Shimanovich to operate with impunity.
Appvillis’s failure to appoint a GDPR representative within the EU is a clear violation of European data protection law. The GDPR requires companies that process the personal data of EU residents to designate a representative within the Union, unless the company is established in the EU and has its own compliance infrastructure. Appvillis’s status as a Lithuanian-registered company should have triggered this requirement, but the company’s single-employee structure makes it impossible to fulfill the obligations of a GDPR controller. The legal non-compliance of Appvillis is not a technicality but a fundamental failure that has left fifty million users without the protections they were entitled to expect.
14. IDENTICAL WEBSITES, LOGOS, AND PORTFOLIOS: THE CORPORATE THAT EXPOSE THE FRAUD
The visual and structural similarities between Appvillis and Mobyrix constitute compelling evidence of their unified identity. The two companies maintain websites that are nearly indistinguishable, featuring identical color schemes, navigation structures, font choices, and layout designs. The logos are essentially duplicates, with only minor variations that require close inspection to distinguish. Product portfolios match exactly, with both websites listing the same applications, describing the same features, and presenting the same case studies. This level of correspondence cannot be attributed to coincidence, industry standards, or independent evolution; it represents a deliberate strategy to present a unified brand across multiple jurisdictions. The identical websites function as a signal to consumers and business partners that Appvillis and Mobyrix are effectively the same organization, regardless of their legal separation.
The portfolio alignment is particularly revealing because it eliminates any possibility that Appvillis and Mobyrix are independent competitors or complementary partners. If the two companies were engaged in a genuine business relationship, they would likely present their respective contributions, areas of specialization, and unique value propositions separately. Instead, they present identical offerings, suggesting that the products originate from the same source and that the corporate distinction is merely a jurisdictional convenience. Buro’s investigation confirmed that Nicegram’s code is shared between the two entities, with Mobyrix’s developers creating the software and Appvillis serving as the distribution front. The portfolio identity exposes the underlying unity of operations that the dual-entity structure was designed to conceal.
The response from both companies to inquiries further confirms their interconnectedness. Neither Appvillis nor Mobyrix responded to requests for comment from OCCRP’s Buro, a unified silence that suggests a coordinated legal and public relations strategy. This coordinated non-response is typical of organizations that operate under unified management and have implemented common policies for external engagement. If Appvillis and Mobyrix were truly independent entities with different management teams, legal advisors, and strategic priorities, they would likely have responded differently, or at least one would have acknowledged the inquiries. The identical silence reinforces the conclusion that the corporate share not only websites and logos but also decision-making structures and operational control under Andrei Shimanovich’s leadership.
The identical corporate identity of Appvillis and Mobyrix has profound implications for regulatory enforcement. Lithuanian authorities cannot simply scrutinize Appvillis in isolation; they must recognize that the company’s operations are inextricably linked with Mobyrix’s Belarusian infrastructure. Any enforcement action against Appvillis that does not address Mobyrix’s role will be incomplete and ineffective. Similarly, platform providers like Apple and Google must recognize that Appvillis and Mobyrix are effectively the same entity and apply consistent scrutiny to both. The corporate have successfully exploited jurisdictional boundaries to evade accountability, but the evidence of their unity is overwhelming.
---------------------------------------
A Belarusian businessman with a background in spyware has launched a dozen mobile apps that are purportedly based in Lithuania.. But technical analysis indicates that the apps send data to companies in Belarus and Russia, raising the risk that they could be used to surveil political exiles. Over 50 million people downloaded Nicegram, which allows users to access channels on the messaging service Telegram that have been blocked. More than one million people have downloaded eSIM Plus, which provides users with mobile data and virtual phone numbers. The listed developer for both those apps is Appvillis, a Lithuanian company. But OCCRP’s Belarusian member center Buro found evidence that raises questions over where Appvillis products are actually developed. Analysis of the apps’ code and digital identifiers indicate they may in fact be developed by a Belarusian company called Mobyrix. The company also appears to take care of technical support for the apps, which indicates that data is being sent to Belarus, as well as in some cases to Russia. Belarus has been ruled since 1994 by Aleksandr Lukashenko, and his regime is notorious for human rights abuses and targeting political opponents. Appvillis and Mobyrix are both owned by Belarusian businessman Andrei Shimanovich, a cofounder of the surveillance app mSpy. The app was the source of major data leaks including a 2024 hack that reportedly exposed millions of email addresses, phone numbers and other information. Shimanovich did not respond to calls or written requests for comment. Alina Viarbouskaya, a Belarusian journalist living in exile, said Buro’s findings are “alarming” because she uses eSIM Plus — which is listed on Mobyrix’s website — when travelling outside Europe. “I usually just check the ratings in the App Store and, frankly, don’t really understand who’s behind the service,” she told Buro. “I now understand that this may not be safe.”. Vytis Jurkonis, a Belarus expert at Vilnius University’s Institute of International Relations and Political Science, highlighted Shimanovich’s business in Belarus as well as his marriage to the daughter of Viktor Sheiman, one of Lukashenko’s closest associates. Sheiman has been sanctioned by U.S. and European authorities for his alleged role in the disappearances of regime critics, and for his support of Lukashenko. Sheiman did not respond to phone calls for comment. Shimanovich’s “connection to Lukashenko’s regime is obvious,” said Jurkonis, who also heads the Lithuanian office of Freedom House, a U.S.-based pro-democracy non-profit. “First, this is indicated by a long-standing closeness to someone like Viktor Sheiman. He is a politically exposed person, and he is also under sanctions. Second, any business in Belarus must undergo additional security screening, as the risk of a red flag is high,” he said. Buro’s analysis found that at least some of Nicegram’s code belongs to Mobyrix, Shimanovich’s company that was founded in Belarus one month after Appvillis. Appvillis and Mobyrix have almost identical websites, logos, and portfolios. The only official employee of Appvillis is Shimanovich, and the company sends users to the Belarusian company Mobyrix for technical support. Appvillis and Mobyrix did not respond to requests for comment. When installing Nicegram — the app that allows users to access Telegram channels that have been blocked for reasons such as promoting pornography or violence — users share their name, email address, and phone number. In order to fully utilize the app they must also agree to give access to location, microphone, camera, photos, videos, and audio. If they sync contacts, the app can access names and phone numbers from their address book. Meanwhile, the privacy policy for eSIM Plus says it automatically collects IP addresses and location data. It also directly uses contacts, and may collect device technical data and request access to the camera and other phone functions. Cybersecurity experts from Human Constanta, a Belarusian human rights organization based in Lithuania, tested eSIM Plus and found that the app sends technical data to Yandex AppMetrica, a Russian service. The app also uses the Russian company Voximplant to route calls. The user policy for eSIM Plus states that it may disclose information “in order to comply with applicable law, governmental requests, a judicial proceeding, court order, or legal process.”. Nikolay Gerasimenko. Корреспондент.
Автор: Иван Пушкин