InterSecLab

The Max Messenger

An Analysis of Russia’s State-Mandated Messaging Application

VK can change what Max does to you, one user at a time. InterSecLab spent nine weeks watching Russia’s mandatory messenger run, reading its traffic from inside the app. This is what it does, what it can be told to do, and what we could not see.

InterSecLab, 24 September 2026

Read the full report The Max Messenger: An Analysis of Russia’s State-Mandated Messaging Application.

Download high-resolution PDF.

A Russian translation, prepared by RKS Global, will be published on this page when it is ready.

Why we did this

In September 2025, Russia made Max, a messaging application developed by VK, compulsory: it must be pre-installed on every smartphone and tablet sold in the country. At the same time the alternatives were removed. Signal was blocked in August 2024, WhatsApp in February 2026, and Telegram has been subject to mass blocking since March 2026. Max is increasingly required to reach government services, in Russia and in the occupied areas of Ukraine, down to enrolling a child in school.

Max was built to resist external examination. It does not use standard web encryption. It runs a proprietary binary protocol wrapped in Russian federal cryptography, implemented by a vendor licensed by the FSB. It shuts itself down when it detects analysis tools, and it stores the addresses it contacts as scrambled numbers rather than readable text. Earlier researchers ran into that wall: they could read the code, or watch which servers the phone talked to, but not read what was said.

So we built a way to read Max’s traffic, capturing it inside the app in the moment before it is encrypted, and we checked everything we saw against the code that produced it. When this report says Max does something, it means we either watched it happen or traced the path that makes it happen, and it says which.

We analyzed version 26.12.0, build 6664, of the Android application between March and May 2026.

What we found

Max has no end-to-end encryption, and “secret chats” are not encrypted. Every message is readable by VK’s servers. We captured a message in plaintext at the moment Max handed it to the cryptographic library. The “secret chat” feature is a disappearing-message timer and nothing more, under the name Telegram uses in Russia for its encrypted mode.

What Max does is set on VK’s servers, per account, without an app update. Network probing, VPN detection, voice transcription, elevated logging, the list of services allowed to receive a user’s identity: all are switched from the server, for one account or for many, with nothing shown in the interface. Two people can run the same version of Max on the same day and be running very different applications, and neither of them can tell. This is the single most important technical fact in the report. Anything we found dormant in our build can be live tomorrow for one person and no one else.

Max reports the user’s network environment to VK. When the setting that controls it is on, each time the app opens or goes to the background it looks up the device’s public IP address through up to six external services, checks whether a VPN is running, reads the mobile carrier, and tests whether a list of internet services is reachable, including the Russian state services portal. All of it goes to VK in one report. Telegram and WhatsApp were on that list until the practice was reported publicly in March 2026. Separately, Max carries a second, concealed reporting channel that takes an unrestricted list of addresses from the server and tests each one from the user’s device. We found its destination only after decoding a hostname the app stores in scrambled form. It ran nineteen times on our test phones, and one of the addresses it was told to test, Apple’s push service, appears nowhere in the app, so it can only have come from the server. The destination, trace-flow.ru, sits in VK’s own network and presented a certificate issued to VK LLC, Moscow.

Max stops working when it finds a VPN. We observed this directly: an attempt to reply to a message produced a full-screen instruction to disable the VPN, with no way around it. The check looks for a VPN on the device itself, so a VPN on a router evades it. A user who does not know that faces a forced choice between the tool that reaches independent media and the app required for state services.

Max uploads the entire address book to VK in cleartext, names paired with numbers. We captured the upload during a fresh registration. A widely cited analysis had reported that the numbers are hashed first. They are not; the routine read as a hash is a formatting normalizer.

Anyone can look up any registered phone number, and the server acts on it. The query returns the account’s identifier, display name and creation time, needs no contact relationship, and sends the person looked up no notification. Within 1.2 seconds VK’s servers began streaming that person’s real-time online status to the account that asked, and kept streaming it for over fifteen minutes. A link between two people was created by one of them looking the other up.

The server reads content, and the machinery to read more is in place. Every text message carries a flag telling the server to inspect it for links and shared content. Voice messages are transcribed on VK’s servers, not the device. During calls, according to the code, live audio is routed to an on-device model that VK supplies from its servers and can replace without an update.

The full report documents each of these with the capture or the code path behind it, and explains where our findings agree with, and where they contradict, the work of the researchers who examined Max before us.

What we do not claim

This report describes what Max can do. It does not claim that VK Group or any Russian state body has used any specific capability against any specific person, and we collected no evidence of such use.

We were also able to rule things out. The component that can list every application installed on a phone is present in Max but was never initialized in the build we examined and could not function without a permission the application does not declare.

Our findings are a snapshot of one build, tested in our lab, at one moment. What we found dormant in the code was dormant only for our accounts, in our build, during our testing window. A different user could receive a different Max, and they would have no way to tell. That is itself a finding, and it means no single analysis can describe Max in full. We have described our method in enough detail for others to repeat it and test it against later builds.

What should happen now

The technical advice is narrow. Max should not be used to communicate anything sensitive; anyone who has it installed should assume that anything sent through it can be read by VK. Where Max is unavoidable, it is possible to run a VPN on a router, isolate Max in a separate Android profile, or keep a separate device for state applications, so that circumvention keeps working while Max does. None of that protects message content, which VK stores unencrypted.

For governments, the sanctions architecture now reaches VK and the entity that operates Max, listed by the EU in July 2026 under its former name, Communication Platform LLC, and by tax number, which is the durable hook. CryptoPro, which supplies the FSB-licensed cryptography on which Max’s transport depends, is not listed under any major Western sanctions regime. Beyond sanctions, the people most at risk from this system need relocation pathways, and since 2024 those have been narrowing rather than widening.

For researchers, this work cannot be done once. Max’s capabilities are a setting on a server, so every analysis of it, this one included, is a photograph of a moving target.

About this report

The analysis was conducted by InterSecLab between March and May 2026. Before publication we put our findings to VK Group, MAX LLC, Apple, Google and the Council of the European Union. The EU responded, through the EEAS Sanctions Division, and its reply is reproduced in full in the report. The others did not respond.

With RKS Global

RKS Global is a think tank of technical specialists, lawyers, journalists and cybersecurity experts working on internet freedom, digital surveillance and digital rights in Russia and across the Eurasian region, and on the export of Russian censorship and surveillance technology to other countries. They published the first behavioral analysis of Max in September 2025 and the study of VPN detection in Russian apps in April 2026, both of which this report builds on. This research would not have been possible without them: the inspiration and motivation, the Max accounts used in testing, the sharing of internal briefings, the Russian translation of this report, and their review of drafts throughout.

With DOXA: the findings in video, in Russian

We shared our findings ahead of publication with DOXA, the independent Russian outlet that began as a student magazine in Moscow and now works in exile. They added their own reporting on the Russian context, which we could not have done, and made a video that explains what Max does in the language and the format that reach the people who have to live with it. It is the first time this research is presented in video.

Corrections: any corrections to the report after publication will be listed on this page, with the date and the version of the PDF they apply to.

How to cite: InterSecLab. The Max Messenger: An Analysis of Russia’s State-Mandated Messaging Application. InterSecLab, September 2026. interseclab.org/research/max

Press and other inquiries: contact@interseclab.org

Translations

Скоро

Translated into Russian by RKS Global

Незабаром

Translated into Ukrainian

Scroll to Top