Russian Apps Hunt for Your VPN, and the State Wants the Data
If you live in Russia and open a banking app or a marketplace, the software on your phone is very likely checking whether a VPN is running, and a good part of it reports what it finds back to the company. That is not a claim from a privacy forum. It comes from a teardown of thirty of the country's most installed Android apps, and it matters this week because Roskomnadzor has just knocked more than twenty VPN services offline at once.
What a teardown of thirty apps found
RKS Global, the digital rights group founded by cyber lawyer Sarkis Darbinyan, decompiled the APK files of thirty of the most popular Russian Android apps and searched them against 80 checkpoints across 12 categories. In the first round, published on 10 April 2026, 22 of the 30 apps could tell that a VPN was switched on, and 19 of those sent that signal to their own servers. When the researchers re-checked at the end of April, every one of the thirty detected a VPN.
The list is not made of obscure utilities. It is the software people open several times a day.
- Banking: Sberbank Online, T-Bank, VTB and Alfa-Bank all carry VPN detection.
- Marketplaces and delivery: Ozon, Megamarket and Samokat.
- Ecosystems: Yandex Browser and Yandex Maps, plus VK properties including Odnoklassniki.
- The deepest reach: seven apps do not stop at the yes-or-no answer. Wildberries, Ozon, Megamarket, 2GIS, MTS, RuStore and Odnoklassniki pull the full list of VPN clients installed on the device.
That last group is the important one. Knowing that a tunnel is up is one thing. Knowing which specific tools a person keeps installed, including the ones they are not using at that moment, is an inventory of behaviour rather than a security check.
The state asked platforms to pass the findings back
On 30 March 2026 the head of the Ministry of Digital Development, Maksut Shadayev, held a closed meeting with representatives of more than twenty large internet companies. According to RBC, whose reporting was picked up across Russian media, the companies were asked to restrict access for users with an active VPN by 15 April. They were to receive from Roskomnadzor the lists of VPN IP addresses already identified, along with guidance on detecting and blocking such services on their own.
The clause that turns a detection feature into an enforcement pipeline is the return leg: data the companies collect on new VPNs is to be handed to the supervisory authorities so the common blocklist keeps growing. The leverage discussed was commercial rather than criminal, including removal from official white lists, loss of IT tax benefits, revocation of IT accreditation and removal from the list of mandatory preinstalled software.
August: the same logic moved to hosting
On 3 August 2026 RBC described the next stage, this time aimed at infrastructure. Hosting providers would monitor the IP addresses sitting on the whitelist of exceptions maintained by Roskomnadzor's monitoring centre. If VPN infrastructure is seen on an address repeatedly over a week, the provider gets a request and one day to answer. Clients verified only by a phone number or a card could be cut off within thirty minutes, while clients verified through Gosuslugi or a corporate contract would be asked to remove the infrastructure first. Providers judged uncooperative risk having whole subnets restricted.
A day later, on 4 August, more than twenty VPN services went down together as entire hoster subnets were cut, the shift we covered in our report on Russia moving from blocking VPN apps to blocking their hosting.
What is documented and what is inference
This story is easy to overstate, so it is worth separating the two.
- Documented: the detection code is in the apps, some of it collects the inventory of installed VPN clients, and part of it travels to company servers. The research is public and reproducible from the APKs.
- Documented: the authorities formally asked platforms to feed their VPN findings back to regulators to expand the blocklist. This rests on RBC's sources rather than a published decree, and no official document has been made public.
- Inference: that the specific list used on 4 August was built from data harvested by banking apps and marketplaces. Darbinyan has connected the spring rollout of these modules to the summer escalation, and the sequence is suggestive, but no evidence has been published tying that blocklist to that telemetry.
What this changes for people using a VPN
The practical shift is that circumvention is no longer only a contest between protocols and filters. A second channel now runs through software the user installed voluntarily and cannot easily refuse, because the alternative is losing access to a bank account or a grocery order. Uninstalling a marketplace app is a real option for some people and no option at all for others.
It also changes what a person should look for in a provider. Resistance to network level filtering is only half the problem when the other half is an inventory taken on the handset, so infrastructure that does not depend on a single reachable address, and the ability to change entry points quickly, matter more than raw speed rankings.
• RKS Global: 22 из 30 популярных российских Android-приложений обнаруживают VPN - Хакер
• Эксперты RKS Global: из 30 популярных российских Android-приложений теперь все детектируют VPN - Хабр
• Минцифры поручило IT-компаниям ограничить доступ пользователей с VPN - Фонтанка
• Зачистка «белых списков», полчаса на ликвидацию и бан подсетей - SecurityLab