惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
N
Netflix TechBlog - Medium
F
Fortinet All Blogs
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
宝玉的分享
宝玉的分享
Y
Y Combinator Blog
博客园 - 聂微东
WordPress大学
WordPress大学
酷 壳 – CoolShell
酷 壳 – CoolShell
B
Blog RSS Feed
小众软件
小众软件
The GitHub Blog
The GitHub Blog
S
SegmentFault 最新的问题
Hugging Face - Blog
Hugging Face - Blog
Jina AI
Jina AI
Microsoft Azure Blog
Microsoft Azure Blog
V
V2EX
B
Blog
H
Help Net Security
D
Docker
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
罗磊的独立博客
月光博客
月光博客
博客园 - 司徒正美

Latest from TechRadar in News

VodafoneThree gets Ofcom approval to bring satellite connectivity to your smartphone NYT Connections today – my hints and answers for April 16 (#1040) Quordle hints and answers for Thursday, April 16 (game #1543) NYT Strands hints and answers for Thursday, April 16 (game #774) Is this the tipping point for AI at work? New Gallup survey finds half of all US employees now use it in some way Allbirds — the shoe viral company — just pivoted into AI, and I wish this were an Onion headline 'Every Apple user needs to know about this nasty scam': Fake warnings tell users their iCloud data will be… 'Makes it even more disappointing': Microsoft backs fossil fuel big time with $7 billion deal in race for AI… 'Maybe it’s not science fiction': Solar panels are causing rainwater to fall in one of the driest places… Maine becomes first US state to pass data centre construction ban Dozens of WordPress plugins hijacked to target thousands of sites Drone-killing laser weapons greenlit for use in US airspace – FAA and Defense Department say high-energy weapons are ‘ready to protect all air travelers from illicit drone use’ despite airspace restrictions and friendly-fire incidents 'We are currently being extorted' — crypto giant Kraken says it is facing extortion attack, here's… McGraw Hill becomes latest to see its Salesforce data hacked Looking for a new PC? Now might be great time to upgrade, as Gartner figures claim shipments are rising — while… Farewell Surface Hub — Microsoft kills off its super-sized touchscreen displays, but you might still be able to get one if you act fast 'We have no interest in patient data in the UK': Palantir UK head defends record as criticisms rise Amazon’s new AI Bio Discovery tool can provide ‘every researcher’ with ‘lab-in-the-loop drug discovery’ – 40+ AI biology models can filter 300,000 novel antibody candidates down to the top results for testing in just weeks Over 100 Chrome Web Store extensions found stealing user data from thousands of accounts OpenAI reveals its Mythos rival designed for cybersecurity pros NYT Connections hints and answers for Tuesday, April 14 (game #1038) Forget Dr Doolittle, study finds animals might not only want to use tech, but they also want to talk to us with it… 'The decision is deeply troubling': Tesla gets a green light for Full Self-Driving in Europe — but not… OpenAI flags third-party data issue — all macOS users should update now Microsoft says Copilot is for ‘entertainment' not work, Meta’s Muse Spark and 7 other AI stories you… Man Utd vs Leeds Live Streams: How to watch Premier League 2025/26 from anywhere in the world, team news What is the release date for Invincible season 4 episode 7 on Prime Video? Linux rules on using AI-generated code - Copilot is OK, but humans must take 'full responsibility for the… The Lenovo Legion Go 2 handheld costs more than two Nvidia RTX 5080 GPUs — and that's genuinely absurd Secretlab is launching its first Diablo desk, with a design that 'traces the infernal history' of the series
Russian researcher claims state-backed MAX app secretly r...
chiara.castr · 2026-05-21 · via Latest from TechRadar in News
The Max logo appears on a smartphone screen with the Russian flag in the background
(Image credit: Photo Illustration by Samuel Boivin/NurPhoto via Getty Images)

  • Security researcher suggests Russia's MAX app includes surveillance features
  • MAX rejects allegations, deeming the analysis "a fake"
  • RKS Global confirms most claims, saying that "none are outright false"

A user on the Russian security forum Habr has claimed that Russia's state-backed messaging service, MAX, includes invasive tools to spy on users' activities.

The researcher claims to have reverse-engineered the application's APK and found at least 15 security issues.

The analysis alleges the app can take screenshots of conversations, secretly record audio, create fake chats, and erase messages directly. MAX was also allegedly found to bypass Google Play to force updates, share address book details with its servers, and detect if users have a virtual private network (VPN) enabled.

The press team at MAX was quick to reject all allegations, directly reaching out to the author of the post and calling the analysis "fake." The company added: "MAX does not monitor users, does not collect their personal data and does not dare to have the technical possibility of listening to calls," insisting that "all user data is securely protected."

These findings follow similar claims regarding the app's ability to monitor VPN usage, which were first shared by another user on Habr in March. In April, the Russian digital rights group RKS Global also found that MAX was among 30 Android apps detecting active VPN connections.

Developed by VK — the Russian tech giant behind the Mail.ru email service and VKontakte — the messaging app is deeply integrated with government services. It first launched in March 2025 and, since September 2025, has been mandatory to pre-install on every new smartphone and tablet sold in Russia.

Last year, other security researchers found the application to have "an enormous surveillance potential." More recently, the US-based hosting infrastructure giant Cloudflare labeled MAX as "spyware," though the label was removed 24 hours later, according to independent Russian news outlet Meduza.

Experts say no claims are "outright false"

Shape of Russia filled with Russian flag-colored internet codes on a black hacking background

(Image credit: Getty Images)

While TechRadar could not independently verify these claims, we asked experts at RKS Global for their assessment. A spokesperson told us that of the 25 technical claims contained in the Habr post, "14 are fully confirmed in the code, six are partially confirmed, five we could not verify statically, and none was outright false."

RKS Global found that MAX's alleged ability to take screenshots of conversations was the "weakest" of the claims. "We did not find code that captures a screenshot of the user’s screen and sends it home," the group's spokesperson told TechRadar.

Experts did confirm, however, that MAX can record users' chats, erase messages, and detect VPN usage. They also partially confirmed the allegation that the app can create fake chats, but only on the RuStore build — Russia's state-backed alternative app market.

Overall, RKS Global points out that the Habr post does overstate some of the allegations. "Where the article was wrong, it was on naming/specifics (obfuscated class names that drift between builds), not on substance," they say.

It is worth noting that RKS Global's experts carried out a static analysis only. This means they decompiled the APKs to read the underlying code, but did not run the binary on a rooted device or capture live network traffic.

"The five unverified claims (call-recording privacy default, TamtamSpam URI push handler, LocationRequest silent push behaviour, six IP checkers, sensor fingerprinting inside MyTracker) require a dynamic test on a controlled handset," the group's spokesperson told us.

TechRadar has approached MAX for comment.

How to stay safe

As the Kremlin keeps pushing for MAX to become an essential app in citizens' everyday lives, security experts are sharing recommendations on how to mitigate potential risks.

  • Treat MAX as a non-private channel. Unlike WhatsApp or Signal, MAX has no end-to-end encryption by default. This means that every message, contact, and group-call audio stream is theoretically in scope for server-side access. "Anything you would not say into a phone call to a state-run carrier should not be said in MAX," RKS Global warns.
  • Keep app permissions to the bare minimum. RKS Global strongly advises against granting Contacts, Microphone, Camera, or Phone permissions unless absolutely needed, and recommends revoking them immediately after use.
  • Avoid the RuStore-distributed build. RKS Global's findings suggest that the Google Play distribution may be slightly safer and that the RuStore build has a materially larger attack surface.
  • Assume that using a VPN isn't a protection. Experts warn that a standard VPN will not protect your privacy on this app as you might expect. This is because MAX allegedly has the ability to detect VPN use, disable features when a VPN is active, and use external IP-checker services to uncover a user’s real exit IP..
  • If you must use MAX, keep it sandboxed. Whenever possible, experts recommend using MAX on a secondary Android profile or a dedicated device. Sign in with a secondary phone number, avoid linking it to your real contacts, and disable microphone access until the exact moment of a call.
  • Avoid sharing sensitive information. For private conversations, RKS Global suggests using an end-to-end encrypted alternative—like Signal or a self-hosted Matrix client—while treating MAX exactly as you would a state-monitored phone line.

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!


Chiara is a multimedia journalist committed to covering stories to help promote the rights and denounce the abuses of the digital side of life – wherever cybersecurity, markets, and politics tangle up. She believes an open, uncensored, and private internet is a basic human need and wants to use her knowledge of VPNs to help readers take back control. She writes news, interviews, and analysis on data privacy, online censorship, digital rights, tech policies, and security software, with a special focus on VPNs, for TechRadar and TechRadar Pro. Got a story, tip-off, or something tech-interesting to say? Reach out to chiara.castro@futurenet.com