The “Max” Messenger as a Digital Surveillance Tool: Risks and Protective Measures

October 5, 2026

Russia’s mandatory “Max” messenger resembles a digital surveillance system far more than a secure communication tool.

In September 2025, “Max” (developed by VK Group) became a mandatory pre-installed application on all smartphones and tablets sold in Russia. In parallel, alternative platforms were systematically restricted: Signal was blocked in August 2024, WhatsApp in February 2026, and Telegram has been subject to mass blocking since March 2026. What is more, both in Russia and in the occupied territories of Ukraine, “Max” is increasingly required to access public services, down to enrolling a child in school.

“Max” was specifically designed to resist external technical analysis. It runs a proprietary protocol protected by Russian state cryptography, implemented by a company licensed by the Federal Security Service (FSB). The app also shuts itself down when it detects analysis tools and stores the addresses of the servers it contacts as scrambled numbers rather than readable text. Earlier researchers could see either the code or the servers the phone talked to, but not the content being exchanged. Nevertheless, researchers at InterSecLab succeeded in analyzing the application’s inner workings by intercepting data directly inside the app, a moment before it is encrypted. The team examined version 26.12.0 of the Android app between March and May 2026 and checked every observation against the code responsible for that behavior.

 What Did the Researchers Discover?

According to InterSecLab’s research, the “Max” application exhibits the following technical characteristics and risks:

  • Lack of End-to-End Encryption (E2EE): Data is encrypted in transit, but only as far as VK’s servers, where every message is readable. The researchers captured a message in plain text at the very moment “Max” handed it to the encryption library. The app offers no mode that would protect message content from the operator.
  • Server-Side Control Without Updates: From its servers, VK can change what the app does for a single account or a group of accounts: switch on network probing, VPN detection, voice-message transcription, or elevated logging, and change the list of services that receive the user’s identity. All of this happens without an app update and without any sign on the screen. As a result, two people running the same version on the same day may in fact be using very different apps, and neither can tell. The researchers call this the single most important technical finding of the report.
  • Network Environment Reporting and VPN Detection: When the relevant setting is on, every time the app opens or moves to the background it looks up the device’s public IP address through up to six external services, checks whether a VPN is running, reads the mobile carrier, and tests whether a list of internet services is reachable, including the Gosuslugi state services portal. All of it goes to VK in a single report. The researchers also found a second, concealed channel that receives an unrestricted list of addresses from the server and tests each one from the user’s device. When it detects a VPN, “Max” stops working: in testing, an attempt to reply to a message triggered a full-screen demand to disable the VPN, with no way around it.
  • Full Address Book Upload: On registration, the user’s entire address book, with names paired with phone numbers, is sent to VK’s servers in plain text. Contrary to a widely cited earlier claim, the numbers are not hashed: the code routine taken for hashing merely normalizes the number format.
  • Online Status Tracking: Anyone can look up any phone number registered on “Max”. The server returns the account’s identifier, display name, and creation time, with no contact relationship required and no notification sent to the person looked up. Within just 1.2 seconds, VK’s servers began streaming that person’s real-time online status to the account that searched, and kept doing so for more than 15 minutes.
  • Server-Side Content Analysis: Every text message carries a flag instructing the server to inspect it for links and shared content. Voice messages are transcribed on VK’s servers, not on the device. And during calls, according to the code, live audio is routed to an on-device model that VK supplies from its servers and can replace without an update.

An Important Caveat – The research describes what “Max” can do. It does not claim that VK or any Russian state body has used these capabilities against any specific person, and no evidence of such use was collected. Some risks were also ruled out: for example, the component capable of listing every app installed on the phone was never activated in the version examined. Still, the findings are a snapshot of a single version: what was dormant for the researchers’ accounts could be switched on tomorrow for another user, who would never notice.

Practical Advice: How to Protect Yourself

If your work or situation forces you to use the “Max” app, follow these security rules. Just remember that none of them protects the content of your messages, which VK can read regardless:

  1. Do Not Share Sensitive Information: Never use “Max” to transmit personal, financial, or confidential work data. Assume that VK can read everything you send through this app.
  2. Set Up a VPN at the Router Level: “Max” looks for a VPN only on the device itself, so a VPN configured on your router goes undetected. This way, you can keep using both “Max” and the tools that get around blocking.
  3. Isolate the App: If possible, install “Max” in a separate Android Work Profile, for example using Shelter or Island, or keep a separate spare phone just for public services.
  4. Restrict Permissions: Do not grant the app access to the camera, microphone, location (GPS), and above all your contacts unless strictly necessary: if you allow access to contacts, your entire address book will be sent to VK.