Agent 00SIM
Which apps with millions of users are linked to Shimanovich – and why cybersecurity experts describe them as dangerous. In which offshore jurisdictions Shimanovich established his companies – and which notorious figures did he collaborate with. In which European country Shimanovich obtained a residence permit despite his spyware background – and how his relatives settled down.
POWER COUPLE
September 10, 2016, Pershamaiski District, Minsk. A young but already high-profile couple is exchanging vows of love and fidelity at the local civil registry office.
The newlywed is Olga Sheiman, the only daughter of Viktar Sheiman, who is Aleksandr Lukashenko’s right-hand man. The woman’s chosen one is named Andrei Shimanovich. He is a successful investor. The press has dubbed him the most successful young businessman from Belarus.

The wedding of Andrei Shimanovich and Olga Sheiman. Source: Andrei Shimanovich’s mother’s Instagram account
By the time of the wedding, Shimanovich had graduated from a British university and founded a venture capital fund. However, he had also found himself embroiled in an international scandal. Viktar Sheiman’s son-in-law was one of the co-founders of a spy app and its public face.
Shimanovich continues to develop unsafe applications in Belarus today and also runs European companies linked to individuals implicated in international corruption scandals. However, this did not stop him from obtaining a residence permit in Lithuania.
This investigation will take an in-depth look at the career of Andrei Shimanovich and his connections to the Sheiman family.
AROUND THE WORLD
Andrei Shimanovich was born in Minsk in 1987. His parents worked in construction and retail. Although the companies they managed were small, they were likely quite profitable. Andrei was sent to London when he was 18. He graduated from the prestigious Queen Mary University of London, after which he joined the team at boutique investment firm Bowline Capital Partners. The firm confirmed to Buro that Shimanovich worked for them as an external consultant from 2012 to 2013.
Around the same time, he became close to Olga Sheiman. This is evidenced by the numerous joint trips abroad taken by the two in the early 2010s, which Buro discovered in CyberPartisans’ databases.

Andrei Shimanovich and Olga Sheiman on vacation. Source: Andrei Shimanovich’s mother’s Instagram account
Andrei Shimanovich also travelled with his future in-laws, Viktar and Sergei Sheiman (Olga’s father and brother).
Now, we’ll take a brief detour to remind you who Viktar Sheiman is. For decades, he has been Aleksandr Lukashenko’s closest ally. They started working together during the first presidential campaign. Following Lukashenko’s rise to power, Sheiman held several senior government positions. These included the Secretary of the Security Council, the Prosecutor General, and Lukashenko’s Chief of Staff.
However, Belarusians remember Sheiman for other reasons. During the 1990s and early 2000s, he was associated with the “death squads” responsible for killing Lukashenko’s political opponents. In the 2010s, a smuggling empire centred on Sheiman emerged, transporting sanctioned goods from Belarus to Russia. Later, Sheiman “made a name for himself” by curating Belarusian projects in Africa and Latin America.
While in that position, Sheiman allegedly made profitable deals with the Zimbabwean government on behalf of Belarus. It was assumed that Belarus would supply this African country with equipment in exchange for access to its gold deposits. However, investigative journalists discovered that the Belarusian government held no stake in Sheiman’s project. The profits were then shared between his son, Sergei Sheiman, and his business partner, Aleksandr Zingman. These individuals owned the gold mining enterprise through a network of offshore companies.
Viktar Sheiman’s trips abroad at the start of his African adventure included his future son-in-law, Andrei Shimanovich. The data provided by CyberPartisans shows that the first tour took place in July 2016.
They were accompanied by Aliaksandr Siamiokhin, an interpreter for the Security Council, and Yury Barkouski, a member of Lukashenko’s security detail. Also present were key figures in the future Zimbabwean project, including beneficiaries Sergei Sheiman and Aleksandr Zingman, as well as Yauhen Zhouner, a co-owner of the company developing the gold deposits. Incidentally, the company was founded only one month before the trip.
Four days later, everyone except Zhouner returned to Minsk. The flight destination is unclear. However, the first day of their trip coincided with talks between the Belarusian delegation and the Zimbabwean ambassador in Moscow.
Buro found that Andrei Shimanovich and Viktar Sheiman had taken 11 flights together. In addition to those already mentioned, among the people travelling with the son-in-law and father-in-law were Olga Sheiman, businessman Vitali Fishman and security official Mihail Baranov.
According to CyberPartisans, Andrei Shimanovich has travelled with Sergei Sheiman on 29 occasions since 2012.
All of this suggests that Shimanovich was close to his wife’s family and their inner circle. However, there is no documentary evidence to suggest that he was involved in their businesses. At the same time, it is known that, during the aforementioned trips, Shimanovich was busy working on his own IT projects. Their companies were just as scandalous as Sheiman’s.
THE BIG BROTHER
Andrei Shimanovich’s first known project was a huge success. The mSpy service was launched in 2011. By 2013, it had already amassed one million users.
The app allowed users to remotely monitor another person’s phone, tablet or computer and view their messages, location, photos, social media activity, call history and search history. The service operated in stealth mode, meaning a person might not even have realised they were being monitored.
The developers marketed mSpy as a parental control tool. Andrei Shimanovich reportedly drew inspiration for this design from his sister, who caused him a great deal of trouble during her teenage years.
“She was constantly tapping away at her smartphone, missing classes, and being quite terrible with curfew, so I was worried about her well-being. Personally, I was lobbying the idea of developing a product that would allow parents to have a tighter control over what their kids are up to on their smartphones,” Shimanovich said in an interview.
However, users soon discovered another purpose for mSpy. Business owners have started using the service to monitor their employees, and jealous partners have used it to spy on their significant others. In 2013, the developers acknowledged that only 40% of the app’s users were parents concerned about their children. The team was all the more pleased.
“Seeing the number of customers we have and how they are using it further drives our excitement and commitment to this product,” commented Andrei Shimanovich.
In an interview with Forbes, he admitted to essentially creating spyware, yet refused to accept responsibility for how it was used.
“It is the same question with the gun producer. If you go out and buy a gun and go shoot someone, no one will go after the gun producer. People who shoot someone will be responsible for this. Same thing for mSpy. We just provide the services which can solve certain tasks,” Shimanovich explained in another interview.
However, the problem wasn’t just about the service’s ethics; mSpy had also become a repository for a vast quantity of highly sensitive data, and users expected it to provide reliable protection for that information. The company failed to do so: in 2015, the personal data of 400,000 people was leaked to the dark web. It was cybersecurity experts, not the mSpy team, who reported the breach. In fact, they continued to deny the incident for another week.
In 2018, the mSpy service suffered an even larger data breach involving approximately two million records. The leaked data included usernames, email addresses, login credentials, passwords, and encryption keys.
The third and final known leak occurred in 2024. At that time, the attackers gained access to the millions of support requests that had been submitted to mSpy. They contained email addresses, phone numbers, and other personal information.
American publication Slate called mSpy “the ultimate cyberstalking tool” and included it in its list of the 30 most dangerous technologies of our time. The list includes projects that have violated users’ and customers’ rights or have raised concerns among cybersecurity and legal experts.
Despite all the scandals, mSpy is still operating. A total of 1.5 million people from 180 different countries use the service.
Andrei Shimanovich did not comment on the mSpy leaks. Following this, he essentially stopped speaking publicly about the service and his involvement with it. Apparently, the fact that a surveillance app failed to protect the data it collected did not sit well with the image of a young genius that Shimanovich had begun to cultivate around his new projects.
THE NUMBER ONE BUSINESSMAN
Andrei Shimanovich founded the venture capital fund WeRocks in 2015, establishing offices in London and Silicon Valley. According to media reports, the total investment was $250 million, with the portfolio including dozens of startups.
Bluesmart, for example, is a technology that helps travellers track their luggage. GeoZilla is an app that enables users to find their phone’s location. HelpCrunch is a website tool that collects data on user behaviour. Placemeter is a service that connects to outdoor surveillance cameras and analyses pedestrian traffic to assess footfall across locations, track peak hours, and determine which storefronts attract the most attention.
Unless you know who the investor behind these apps is, they seem harmless. However, it’s hard not to draw parallels with mSpy. As with this controversial project, all of the new developments in Shimanovich’s portfolio involved data collection and surveillance. The only difference was that, rather than being packaged as spyware, they were presented as useful apps for everyday life and business.
Shimanovich’s image has also undergone a rebranding. He started actively promoting himself in Belarus, presenting himself as an extremely successful young businessman with an international profile.
In spring 2015, the Agency for Strategic and Economic Development recognised Shimanovich as the most successful Belarusian entrepreneur under 30. This is the earliest report about the businessman that Buro has found in the Belarusian media, and it’s full of praise. However, the agency has remained silent about the scandals surrounding mSpy and the businessman’s ties to the Sheiman family.
In autumn 2015, Shimanovich was invited to the “Business of the Future” forum, organised by the agency in collaboration with the Pro Business and TUT.BY web portals.
The PR campaign worked. Shimanovich is now a regular fixture on lists of successful businesspeople.
In 2016, he was named in the “Top 50 People in Belarusian IT” list and became the youngest person in the “Top 200 Successful and Influential Businesspeople in Belarus” list. He was also named one of the top three Belarusian entrepreneurs under 30. In 2017, he was once again recognised as one of the top three most successful young entrepreneurs.
For Shimanovich, it seems that his involvement in his homeland was a least-evil solution. The spy scandal had tarnished his reputation in the West. New startups weren’t taking off, and his multimillion-dollar venture capital fund was gradually dwindling. However, in Belarus, there was a reliable pillar of support in the form of Viktar Sheiman, who was considered the second-most-powerful person in the country.
Having established a stellar reputation in the media, Shimanovich launched a company called Mobyrix in his home country in 2018. The company started developing mobile apps.
THE CLONE
Mobyrix is still operational, with Andrei Shimanovich as its sole beneficiary since its founding. The company’s website features a portfolio of ten applications. However, a different company is listed as the developer on the App Store and Google Play: the Lithuanian firm Appvillis. Its website is identical to Mobyrix’s. The logos and products in the portfolio match. This is no coincidence. As Buro discovered, both firms were founded by Andrei Shimanovich, just one month apart.
We looked into these companies and concluded that they are working together. The Belarusian company Mobyrix develops the apps, and the Lithuanian company Appvillis publishes and monetises them.
For example, one app in the App Store lists Appvillis as its developer, but its Bundle ID – the unique “digital passport” – is linked to Mobyrix. The code of another publicly promoted Appvillis product also mentions Mobyrix. On the App Store page for the third app, the developers introduce themselves as the “Appvillis team” in response to a user’s question. However, they ask users to contact Mobyrix via email for technical support.
Finally, while the Belarusian company employs 28 people, the Lithuanian company only employs one: Andrei Shimanovich.

The Mobirix team is pictured with Andrei Shimanovich (in the centre). Source: The Mobirix website
There are several reasons why a business model based on the separation of powers can be beneficial. First, the Lithuanian company is located in the European Union. To international partners, such a business obviously appears more reliable than a Belarusian firm. Secondly, having a European “base” is more convenient for a mobile developer: it makes it easier to work with Apple and Google, as well as payment services and advertisers. Thirdly, manufacturing in Belarus may be more cost-effective, given that salaries for IT specialists are lower there than in Lithuania. And let’s not forget the unique benefits of knowing the “right” people in Belarus. By the time Mobyrix and Appvillis were launched, Shimanovich had already been Viktar Sheiman’s son-in-law for two years.
It is not the business division plan itself that raises questions; this is standard practice for IT companies. The problem lies in a lack of transparency, exacerbated by a deliberate attempt to confuse users.
A user sees that an app was developed in Lithuania – a European country with high data protection standards – and installs it without hesitation. However, hidden traces of the downloaded programme can be traced back to Belarus – an authoritarian state whose government has enshrined its right to engage in digital espionage in law. Additionally, the app owner’s father-in-law was part of the government in question. He was suspected of political repression and murder and was associated with a corruption network. The owner had previously discredited himself as an investor in spyware when data from it was leaked onto the dark web.
To determine whether Mobyrix and Appvillis’s products pose a risk to customers, Buro reviewed their privacy policies and user agreements and sought advice from cybersecurity experts.
THE BENEFIT OF THE DOUBT
Andrei Shimanovich’s flagship app is Nicegram. It’s an add-on for Telegram. By linking your Telegram account to Nicegram, you can gain access to additional features, including an AI assistant and access to channels that may be blocked.
When users install Nicegram, they provide the app with their name, email address, and phone number. They also grant the app access to their geolocation, microphone, camera, and photos, videos, audio, and other media stored on their device. Enabling contact synchronisation allows the app to retrieve first and last names and phone numbers from the customer’s address book.
According to cybersecurity experts from the human rights organisation Human Constanta, Nicegram is no different from the original Telegram in this regard. At Buro’s request, they scanned Shimanovich’s apps for malware and spyware.
Although experts did not detect any viruses in Nicegram, they said this does not address the app’s most critical security concern.
“The main risk isn’t the virus itself, but the change in the trusted party. Any third-party Telegram client can secretly download your chat history, access all your messages in plain text, weaken encryption, and inject ads. Telegram itself officially warns against using unofficial clients [such as Nicegram – ed. note], precisely because of these risks,” Human Constanta explained.
Therefore, the security of Nicegram depends on how responsible its owner is. It seems Andrei Shimanovich has exhausted his trustworthiness.
Buro noted that even though the app has added many new features, including AI tools, Nicegram’s privacy policy was last updated in 2022. Customers are kept in the dark about how these new features collect and process their sensitive data.
It is also noteworthy that Nicegram is not mentioned on the website of Shimanovich’s Belarusian company. This is the only difference between its public portfolio and the catalogue of the Lithuanian clone. However, Buro discovered a technical link to Mobyrix in the app’s code. This proves Nicegram’s connection to Belarus, a fact that Shimanovich deliberately keeps hidden.
As of today, Nicegram boasts 10.5 million active users and has been downloaded over 50 million times.
Shimanovich’s other popular app is eSIM Plus. It provides virtual numbers and internet access while travelling, eliminating the need for roaming. According to the privacy policy, the app collects users’ IP addresses, technical data, and device identifiers. It also accesses their precise location, contacts, camera, and other unspecified features of their phone.
Experts at Human Constanta called the use of precise location data unnecessary:
“eSIMs and calls don’t require it. The country can be determined based on the network alone.”
During testing, the specialists discovered that when launched, the app sends telemetry data to Yandex AppMetrica, meaning the data is sent to Russia. eSIM Plus also works with the Russian company Voximplant for call routing.
Additionally, the app reserves the right to share collected data with affiliated companies, business partners, government agencies, courts, and law enforcement. Although the specific jurisdictions to which information may be transferred are not specified, the privacy policy permits the transfer of data outside the customer’s country. If the app is sold, all collected data will be transferred to the new owner.
Over a million people have downloaded eSIM Plus from Google Play. The app is also available on the App Store, but the download statistics are hidden.
Cybersecurity experts from the Resident NGO project told Buro that an app’s availability in official stores does not guarantee its security.
“Apps are reviewed before being published on the official Google Play Store or App Store. However, new versions are reviewed less thoroughly. We are aware of cases where existing apps with access to the photo gallery began scanning all photos after updates to find access to cryptocurrency wallets or other information and send it to the app owners, unnoticed. This feature wasn’t available right away; it was added later. Therefore, if you work with confidential information, install as few third-party applications as possible – and only from vendors you trust who respond appropriately to security incidents.”
The next program in Andrei Shimanovich’s catalogue is InLab, a photo editor. Although it does not request access to the camera, microphone, contacts, or location, it does have very broad permissions regarding user content.
Shimanovich’s company automatically obtains a license for your photo when you upload it to this editor. It is lifetime, transferable, free, and universal. This gives the app owner the freedom to use your photo for advertising and commercial purposes.
InLab may share the data it collects with affiliated companies, business partners, government agencies, courts, and the app’s new owners.
The situation is similar regarding StickyLab, which is a program for creating stickers. The experts at Human Constanta deemed its functionality the safest of all the programs they analysed. Although StickyLab does not request excessive access privileges or collect customers’ personal data, there are some concerning clauses in the user agreement.
For example, Appvillis owns all materials uploaded to the app and may use the content as it sees fit. However, if a third party makes a claim, the user is responsible for compensating for damages.
The agreement also states that StickyLab can be used to record phone calls – a strange feature for an app that creates stickers.
Finally, in the privacy policy, the term “company” refers to Appvillis, which is registered in Latvia, not Lithuania. There is no such company.
StickyLab has been downloaded over 100,000 times from Google Play. The app is also available on the App Store.
The newest program in Shimanovich’s catalogue is Aivan, an AI assistant. Just as Nicegram is a Telegram add-on, this app is a wrapper for ChatGPT.
Aivan collects technical data from devices, requests access to the camera, microphone, storage, location, and other unspecified features, and analyses customer interactions with the AI. Aivan offers some paid features. Users enter their information, including their card security code, when making a purchase. The app collects this information, yet it does not disclose where it stores it. The “Provider” field in the privacy policy is left blank. The document also states that data may be shared with Appvillis’s partners, law enforcement agencies, and the app’s new owners.
This last point is important because some programs have already been sold. Buro investigated who now owns them.
IN “GOOD” HANDS
You can find the Recordeon call recording app in the Mobyrix and Appvillis app catalogues. Unlike a voice recorder that simply saves audio to your phone, it connects an external line to the call for recording. Therefore, such a call can no longer be considered private because it is listened to, stored, and processed by the Recordeon owner.
The App Store listing indicates that the app was owned by Appvillis – Shimanovich’s Lithuanian company – at least until the end of 2020. Its team responded to user feedback. However, the app is currently listed as being owned by Smertrios Limited, which is based in Cyprus.
Although the company does not disclose Recordeon’s privacy policy or terms of use, Buro has uncovered general guidelines that apply to all of its products.
In accordance with these policies, Smertrios Limited collects the following information from customers: personal information, technical data about their devices, subscription and payment information, and all user-generated content. In the case of Recordeon, the last point most likely refers to call history and recordings. The company notes that it may use the collected content “as they see fit,” including selling it.
By installing apps from Smertrios Limited, users consent to having their activity monitored and acknowledge that they do not expect privacy. At the same time, personal data is stored indefinitely – “for no longer than it is necessary”.
A company like this was the recipient of the rights to Andrei Shimanovich’s product, and not just one, but multiple products. Smertrios Limited acquired the Voicelator, an audio-and-photo translator. Its users agree to the same terms and conditions as those of Recordeon’s customers. Another risk is that Voicelator could connect to other apps that use the keyboard.
According to its App Store listing, Voicelator is currently owned by Appjiggly Limited, a third-party company registered in Hong Kong. In reality, however, the app was simply rebranded. The previous owner is based in Cyprus and is part of a holding company owned by the Swiss firm AppCapital. The new Hong Kong-based company is managed from Switzerland through its parent company, Bloxolid. These Swiss entities are all registered at the same address and are all headed by Mathias Schmid.
This businessman has held – and continues to hold – executive positions at numerous companies across sectors including IT, consulting, mining, technology, and construction.
One of Schmid’s companies has become embroiled in an international scandal. The company had planned to mine lithium in the Republika Srpska (Bosnia and Herzegovina). The idea was supported by Milorad Dodik, the territory’s then-incumbent president, who was subject to U.S. and British sanctions. Residents, however, voiced their opposition to the project.
Various media outlets have published critical reports about Schmid’s project. They cited clandestine drilling, changes in legislation favouring the mining company, environmental damage, and local opposition. The project was put on hold as of January 2026.
Mathias Schmid is not the only controversial businessman Andrei Shimanovich has done business with.
THE WRONG CROWD
In addition to companies in Belarus and Lithuania, Andrei Shimanovich’s business portfolio includes Strongtech Corporation, a Scottish asset. Shimanovich became the controlling shareholder of this company in 2017.
Two companies based in Belize transferred control of the company to Shimanovich. These companies registered Strongtech Corporation in 2015. Tiffany Nicole Brown, a resident of that offshore territory, managed both companies. She is mentioned in the “Panama Papers”. This is the largest leak of confidential financial data in history. It has exposed the extent to which the global elite evade taxes.
The documents revealed that influential people had used offshore companies and straw men to secretly hide their income, hold assets, and launder money. Brown was, in fact, one of those front figures.
For example, her name surfaced in an offshore network through which, according to media reports, the former Ukrainian president, Petro Poroshenko, and his associates paid for overseas expenses and charter flights.
Tiffany Nicole Brown is associated with dozens of companies in various jurisdictions. She often worked with Matthew Bradley, another Belize resident who was on the UN “blacklist.” He is reportedly a confidant of Ukrainian oligarch Serhiy Kurchenko. Kurchenko was involved in businesses in the oil, gas, and media sectors. He was also close to the family of former Ukrainian president Viktor Yanukovych. During the Euromaidan, Kurchenko fled to Russia. Tens of millions of dollars’ worth of assets were seized in his home country, including seven aircraft and 38 cars.
OFFSHORE PARADISE
The company Strongtech Corporation, which Shimanovich acquired from Tiffany Nicole Brown, is notable not only for its founder but also for its ownership structure. This Scottish limited partnership structure is notorious for its historical use in money laundering. Such companies were not required to disclose their financial statements, and their foreign income was not subject to British taxation unless their owners lived in the United Kingdom.
Andrei Shimanovich took advantage of these opportunities. Strongtech Corporation did not submit any financial documents to the registries. The company’s line of business had not been disclosed, but Buro found a clue on its website. The website is virtually identical to those of Mobyrix and Appviliis, which are Belarusian and Lithuanian companies owned by Shimanovich. This suggests that the Scottish firm is connected to them. For example, as financial reports indirectly suggest, profits from mobile apps may be allocated there.
In 2024, Appvillis’s revenue totalled nearly 2 million euros. However, more than 1.5 million euros were recorded under “cost of inventories and resources consumed,” and an additional 326,000 euros were recorded as “miscellaneous expenses.” Consequently, the net profit is less than 3,000 euros. However, long-term assets, which include rights to applications, are not reported in the company’s financial statements.
Mobyrix generated 3.3 million Belarusian rubles in revenue in 2024 but ultimately incurred a loss. Most of the payments went toward salaries, taxes, and administrative expenses. The company’s total value of intangible assets was just 9,000 Belarusian rubles. For a company with a portfolio of ten mobile apps, that’s too little.
In other words, Appvillis’s reports show sales, while Mobyrix’s show team expenses. However, none of these companies seems to own their most valuable asset: the apps themselves. Against this backdrop, Strongtech appears to be the likely owner of the rights – and thus the recipient of the bulk of the profits – given its opaque accounting practices.
Why are Scottish limited partnerships still a convenient tool for hiding assets? Ben Cowdock, senior investigations lead at Transparency International UK and one of Britain’s leading experts on combating international corruption and money laundering, explained to Buro:
“Transparency reforms mean it’s harder to hide who owns SLPs; however, in the wrong hands, they can still be used to hide assets and launder money, with no requirements to file accounts for those owned by offshore partners. We highlighted the ongoing marketing of Limited Partnerships to Parliament last year.”
Andrei Shimanovich’s questionable assets extend beyond the Scottish firm. He also heads Lestebrond Assets, which is a Cyprus-registered company. Shimanovich was appointed director for the first time in 2019, but only for one day. He returned to the position in 2024 and has held it ever since.
Cyprus is known for its favourable tax conditions and closed registries. These features have earned Cyprus a reputation as an offshore jurisdiction. Buro found no evidence of Shimanovich’s company conducting business in that country. There are no website, products, media mentions, or reviews.
On the other hand, Lestebrond Assets displays the hallmark features of a Cypriot shell company. The firm’s secretary also works for six other local companies. Five of them are registered at the same address as Lestebrond Assets. The previous director oversaw 15 other businesses, all registered to the same address. The shareholder is a company based in the Seychelles. It is one of the most popular offshore jurisdictions.
In this light, Lestebron Assets seems to be just another asset in Shimanovich’s portfolio. It was not created to conduct business, but rather to hold and move money in a less transparent jurisdiction.
Additionally, Buro found that Andrei Shimanovich owns a business in the UAE. He has been running Reynard Invest since at least 2022. Its specified activity profile is the mining of ores and precious metals. The company’s license expired in 2025.
Reynard Invest is registered in the Sharjah Airport International Free Zone. It is a closed jurisdiction that allows foreigners to establish companies and to transfer funds freely and swiftly. However, financial statements and information about the ultimate owners are not disclosed.
Andrei Shimanovich was able to settle in the European Union despite his involvement in shady business dealings and his ties to the top echelons of the Belarusian government.
A WINDOW TO EUROPE
Andrei Shimanovich obtained a residence permit in Lithuania as a startup founder in 2023 and renewed it in 2025. Buro uncovered this information with the help of colleagues from the Lithuanian investigative centre, Siena.
“Consultations were held with the Lithuanian State Security Department on both occasions before the temporary residence permits were issued. In both cases, the department responded that ‘the foreign national’s presence poses no threat’”, the Lithuanian Migration Service commented.
Buro journalists believe that Andrei Shimanovich was divorced from Olga Sheiman when he received his residence permit. She hasn’t appeared in his family photos in several years. Since late 2022, she has been listed in the Social Security Fund database under a different last name. It was likely his divorce that enabled Shimanovich to pass the screening by the Lithuanian authorities.
However, when the business was registered in Lithuania in 2018, Andrei Shimanovich was undoubtedly a member of the Sheiman family. According to data from CyberPartisans, his marriage to Olga lasted at least until the end of 2021.
Furthermore, a Lithuanian company served as an attractive European showcase for Shimanovich’s apps. The apps were developed in Belarus and collected sensitive user data from around the world.
Shimanovich’s first major project, mSpy, has not been left behind either. The covert surveillance service remains operational and has millions of users. However, it continues to be embroiled in data breach scandals.
Add to this picture his trips with Viktar and Sergei Sheiman, his involvement with companies in opaque jurisdictions, and his partnerships with individuals of questionable reputation – and you have a man with an extremely alarming background. This doesn’t stop Shimanovich and his family from enjoying a comfortable lifestyle.
GRACIOUS LIVING
Andrei Shimanovich’s younger sister earned her master’s degree in London. She now lives in Warsaw and works in IT. The young woman regularly shares photos from her travels around Europe, and she also visits Belarus. She owns an 87-square-meter apartment on Talbukhina Street in Minsk, estimated at $228,000.
Shimanovich’s father and mother live in Minsk. They own two apartments: a 142-square-meter apartment on Kuzmy Chornaha Street and a 195-square-meter apartment on Instrumentalny Lane. This property’s total estimated value is over $700,000. Additionally, the Shimanoviches own three houses. One is located on Anharski Lane and covers 57 square meters. The other two are in the Vileika District. One is 40 sq. m., and the other is 223 sq. m. The family’s patriarch also owns a 115-square-meter commercial premises on Mayakouskaha Street in the capital.
The couple enjoys travelling together throughout Europe and Asia. Judging by their social media posts, the Shimanoviches have travelled to the United Kingdom, the UAE, Türkiye, and Poland several times over the past year and a half alone. They have also visited Switzerland, Italy, and Austria.
Andrei Shimanovich himself keeps a low profile, but he appears in family photographs. For example, from joint trips to London and Dubai. The businessman periodically spends time in Belarus.

Andrei Shimanovich (in the centre) with his family in the UAE. Source: Andrei Shimanovich’s mother’s Instagram account

Andrei Shimanovich (on the left) with his family in Belarus. Source: Andrei Shimanovich’s mother’s Instagram account
Andrei Shimanovich didn’t respond to calls from Buro journalists. At the time of publication, we had also received no response from Shimanovich to our written request for comment. Shimanovich’s companies – Mobyrix, Appvillis, and Strongtech Corporation – likewise didn’t respond to Buro’s requests.