Apple has been removing VPN apps from the Russian App Store at Roskomnadzor’s request for a fourth consecutive year, with the annual rate of takedowns surging from single digits to over a thousand. One confirmed case involves the VPN client Happ. Removed from the store on June 24, 2026, it was republished by its developers just five days later under the name “Happ — Proxy Utility+.” The pattern remains unchanged: renaming delays a repeat removal, but does not prevent it.
Timeline
| Date | What happened |
| 2022–2023 | Apple removes 7 apps from the Russian App Store at the request of Roskomnadzor (RKN, Russia’s federal media and communications regulator) in 2022 and 12 in 2023 (based on Apple’s transparency data). |
| July 4, 2024 | RKN succeeds in getting VPN apps removed from the App Store for the first time. Russian users lose access to Red Shield VPN, Le VPN, Proton VPN, and NordVPN. RKN reports 25 services removed in total. |
| July 10, 2024 | Apple removes 10 more services: a PlanetVPN clone, AdGuard VPN, Ru VPN, TOP VPN, Potato VPN, VPN Super – Proxy Master, Turbo VPN, VPN TM, VPNIFY, and TipTop VPN. AdGuard VPN’s own developer separately confirmed the removal on its official blog. |
| July 4–September 18, 2024 | The GreatFire project documents about 60 more removals that Apple never announced publicly, bringing the total number of VPN services unavailable in the Russian App Store to 98, even though RKN had publicly acknowledged only 25 |
| 2024 (year total) | In total, according to iStories (Important Stories, an independent Russian investigative outlet), Apple removed 171 apps at RKN’s request over the year — about 14 times more than the year before. |
| Mid-March 2025 | RKN sends Google 47 requests to remove VPN apps from the Play Store in a single week. |
| April 2025 | The GreatFire project reported that of the 212 apps named in RKN’s latest requests to Google, only 6 became unavailable, and 3 of those were already gone before Roskomnadzor’s letter. |
| 2025 (year total) | Over the course of 2025, Apple removed 1,213 apps — about 7 times more than the year before. |
| February 25, 2026 | The Tagansky District Court fines Google LLC 22.8 million rubles (about $303,240) “for distributing VPN services.” The company’s representative doesn’t show up in court. |
| Late February 2026 | RKN reports restricting access to 469 VPN services across Russia. This is a network-level blocking figure at the TSPU (technical means for combating threats) level, not a count of App Store or Google Play removals. |
| Late March 2026 | At Roskomnadzor’s request, Apple removes more than 20 VPN clients from the App Store, including Streisand, V2Box, and v2RayTun. |
| March 2026 | Over the course of a month, RKN sends Google 233 requests — a two-year record for a single month. |
| June 24, 2026 | Apple removes Happ — Proxy Utility Plus from the App Store. |
| June 29, 2026 | Happ returns to the App Store under the name Happ — Proxy Utility+. |
The mechanism behind Happ’s removal from the App Store
This is not the first time Happ has been pulled from the Russian App Store. Apple removed the service’s global version in March 2026, prompting the developers to release an adapted version—which was subsequently taken down in June. It returned to the store under the new name “Happ — Proxy Utility+” on June 29 from the same developer account.
Technically, the Network Extension framework (iOS’s system framework for network extensions; entitlement: a capability or permission specified in the app configuration and signing profile) explains why Happ remains, in substance, a VPN tool no matter how the developer, Flyfrog LLC, describes it in the app listing. Tunneling traffic on iOS requires one of this framework’s classes:
- NEPacketTunnelProvider for a full VPN tunnel, or
- NETransparentProxyProvider/NEAppProxyProvider for a transparent proxy. The argument “we’re not a VPN, we’re a proxy client” doesn’t hold up here.
Here, a targeted Roskomnadzor request naming a specific app triggers removal, not an automatic scan for this entitlement. The wave of removals in March 2026 shows this directly. Apple removed the “Happ — Proxy Utility” version, while “Happ — Proxy Utility Plus” from the same developer, with the same functionality and the same protocols, stayed in the App Store simply because the request didn’t name it. If Apple detected VPN functionality technically, by entitlement, both versions would have been removed simultaneously. This means renaming an app on re-release doesn’t protect it permanently — it only delays the next removal. In substance, the app remains a VPN tool and will likely end up on one of Roskomnadzor’s lists again sooner or later. The good news: having the entitlement alone doesn’t trigger automatic removal.
Once Apple receives a request from Roskomnadzor citing a specific legal provision (usually clause 7 of Article 15.1 of the Information Law), it checks the request against its own App Store Review Guidelines and pulls the app from publication without any court process or public proceedings: the developer gets a letter, and within a few days the app becomes unavailable in the Russian App Store region. According to Kommersant, Streisand, V2Box, and v2RayTun were removed the same way earlier.
How many apps has Apple removed at Russia’s request
| Year | Number of apps removed at RKN’s request |
| 2022 | 7 |
| 2023 | 12 |
| 2024 | 171 |
| 2025 | 1213 |
That’s a 173.2-fold increase over the 2022 baseline in just four years. Apple has never publicly challenged any of these requests or changed how it responds to them. The speed and predictability of this process explain why a rise in requests translates almost immediately into a rise in removals.
The timeline we compiled also lets us estimate another figure: the share of removals that Apple and RKN never disclose publicly. In July 2024, RKN reported 25 app removals. By September 18 of that year, an independent GreatFire investigation counted 98 unavailable VPN services. Nobody reported 73 of those 98 removals (almost two-thirds of the total) until independent monitoring caught them.
Google Play
Roskomnadzor applies the same pressure mechanism to Google, but with a different result, which shows where the regulator’s authority runs out. According to the Lumen database (an archive of legal takedown requests hosted at Harvard Law School, where Google forwards the requests it receives), Roskomnadzor sent Google 47 requests in a single week in mid-March 2025, and by March 2026 the monthly volume of requests had grown to a record 233. Over two years, the agency has demanded that Google remove at least 1,379 censorship-circumvention services in total.
At the same time, according to the GreatFire project, of the 212 apps named specifically in the March 2025 requests, only 6 (3%) had become unavailable in the Russian Google Play by April of that year. Half of those six (ExpressVPN, Secure VPN, and Thunder VPN) were already unavailable before Roskomnadzor even contacted Google. Some of the services named in the 2025 requests are still available in the Russian Google Play as of 2026.
The reason lies in how enforcement actually works. For Apple, a request leads directly to removal. For Google, even winning a court case results in a fine, not a guaranteed removal. The agency can keep sending more letters almost without limit, but more letters don’t speed up the courts. Apple’s removal count rises together with the request count, because the outcome depends on one company’s decision. Google’s removal count is capped by how many cases the Tagansky court can process, and it doesn’t scale with the volume of requests. The record request volume in March 2026 didn’t translate into a matching jump in confirmed removals. Google’s model is bottlenecked by a single court’s capacity and doesn’t scale with the number of letters, unlike Apple’s.
This difference has a legal dimension too. The request to Apple rests on Roskomnadzor’s own decision to add a resource to its register under clause 7 of Article 15.1 of the Information Law, not on a court ruling. Apple complies with it as a condition of staying in business in the country. As the trade outlet Kod Durova (a Russian tech and security news publication) noted, none of the apps removed in March 2026 had a court ruling declaring the specific app or its content illegal. The basis is simply the fact of being added to the register, not a violation established by a court. In Google’s one confirmed episode, a court did make the decision, though on the formal grounds of failing to comply with an order, rather than on the substance of whether the VPN service itself was legal.
Positions of Apple, Google, and Roskomnadzor
Roskomnadzor points to a specific legal provision. Commenting on the removal of 25 apps in July 2024, for instance, the agency’s press service explained the move by citing a ban, in effect since March 1, 2024, on distributing information that advertised or promoted censorship circumvention tools.
VPN services sit in a legal gray zone in Russia because of how the authorities have acted. Natalya Abramova, a Russian cybersecurity specialist, has analyzed VPN blocking and noted that Russia treated only a service registered with Roskomnadzor as legal, and tended to restrict everything outside that model. The authorities are not planning to ban VPNs outright for now, but they do want to shrink the number of VPNs available to Russians. Read our earlier analysis on this.
Apple. The company stated its reasoning once and hasn’t revisited it since. In a response to Reporters Without Borders dated December 25, 2024, Apple explained that failing to comply with local legal requirements could mean it can no longer support the App Store or distribute content in Russia. In the company’s view, keeping communication services available to Russians better serves the promotion of democratic principles than leaving the market. Apple never responded to a letter from more than 50 human rights and IT organizations urging it not to assist the Russian authorities. It also didn’t react to other statements from IT-sector and NGO representatives arguing that cooperating with censors is unacceptable.
Google. Alphabet, which owns the brand, stays silent. Company representatives sometimes simply don’t show up for court hearings about removals and blocks.
In May 2025, the outlet The Bell asked Google and Apple to clarify the logic behind the removals; neither company responded.
VPN service developers. They plan to keep operating without publicly challenging the platforms’ decisions. Happ’s developers reacted to the June removal with a short quip: “Guess there’ll be a third one soon!”
Interestingly, around the same time in 2026, Apple removed the entire VK ecosystem (including VKontakte, Odnoklassniki, and Mail.ru) from the App Store worldwide (not just the Russian store), citing compliance with sanctions against Russian companies. App Store leadership is clearly trying to satisfy requirements beyond just Russian law.
Google also removed VK’s services from its main app store. The Russian authorities reacted differently to the two removals, though. There was no clear response to Google’s move, but things got public with Apple. First, the Federal Antimonopoly Service demanded that Apple preinstall the Max messenger on Russian users’ iPhones; Apple didn’t respond. Then, in July, Apple’s website and the App Store started getting selectively blocked. We looked into exactly how that happened.
The situation in other countries
China. In China, Apple started removing VPN apps from the local App Store as far back as 2017 at the government’s request, and the country has had what amounts to a blanket ban on such apps ever since, one that’s never been lifted. China’s model covered the entire VPN category all at once, right from the start.
India. In late October 2024, India’s Ministry of Home Affairs demanded that Apple and Google remove the Hide.me app. The list later grew to at least 6 services, including PrivadoVPN and Cloudflare 1.1.1.1. Both companies removed everything officials asked for. The formal basis was a set of 2022 directives from India’s Computer Emergency Response Team (CERT-In), which require VPN providers to retain user logs for at least five years: providers that don’t comply get blocked.
Recommendations for developers
iOS
The Happ case shows that re-releasing an app under a new name doesn’t offer permanent protection, only a temporary delay. On June 29, the developers republished the app as Happ — Proxy Utility+, but it remains, in substance, a VPN tool regardless of its name, and what will trigger the next removal isn’t technical detection but the new name showing up in Roskomnadzor’s next request. The cycle will most likely repeat the same way it did with Streisand, V2Box, and v2RayTun. Treat any App Store presence in this category as temporary by default, and prepare backup channels in advance:
- TestFlight with external testing. Up to 10,000 external testers per app; the app still goes through beta review, but under looser criteria than a full App Store Review. This channel can be revoked just like the main listing, but it gives you an independent, parallel distribution path.
- Ad-hoc/enterprise distribution via provisioning profile. This ties the app to specific devices by UDID (Unique Device Identifier): up to 100 devices per year for a standard Apple Developer Program membership, or unlimited UDIDs through the Apple Developer Enterprise Program, though the latter carries the risk of Apple revoking the developer certificate if it detects public distribution outside the company.
- Web configuration without Network Extension. A proxy based on SOCKS-over-WebSocket (WebSocket: a protocol for a persistent two-way connection over TCP) or WebRTC (WebRTC, Web Real-Time Communication: a protocol for real-time data transfer in the browser), configured via a .mobileconfig profile or a plain web clip, doesn’t require tunneling entitlements and falls into a different technical distribution class than a full VPN tunnel.
Android
Google Play remains the more resilient channel for now, but that’s a side effect of slow court procedures, not a stable company policy. The general recommendation is not to design your distribution architecture around Play Console alone:
- Separate Play Console tracks (production, closed testing, internal testing app sharing). This reduces the odds that a single request takes out every build version at once, though it doesn’t protect against the entire listing being removed.
- Server-side feature configuration. Publishing a generic network utility in the store and enabling censorship-circumvention features after install, through a remote config (Firebase Remote Config or your own server), reduces what static review can find during submission, though Google is expanding detection of this exact pattern through the Play Integrity API and ongoing behavioral monitoring.
- A backup channel via direct APK (Android Package, the distribution file format for Android apps). Publish a signed APK with a reproducible build and a fixed signing-certificate fingerprint, so users can verify the file’s authenticity outside Google Play, independent of repositories like F-Droid.
Risks of backup distribution channels
Moving away from the official app stores brings its own set of risks worth keeping in mind when choosing a channel. Publishing outside Google Play and the App Store removes the threat of an RKN-driven takedown, but it also removes the review process that at least partly protects users from fake builds.
In May 2026, for instance, researchers documented an app that presented itself as a free VPN service but actually installed a banking trojan on the device: it secretly read SMS messages and push notifications and stole data from banking apps, all against the backdrop of a 14-fold year-over-year increase in downloads of the top 5 VPN apps on Google Play in Russia.
Anna Vyatkina and Sergey Trukhachev, experts at Anti-Malware.ru, note a rise in phishing schemes where attackers slip users a link disguised as a free VPN or proxy, giving themselves access to accounts, messages, and banking apps.
Publishing a signed APK with a reproducible build only protects against this kind of fake when users have an independent way to check the certificate fingerprint against the developer’s official channel (the project’s website, a GitHub repository, a hash published across several independent sources); the mere presence of a signature isn’t enough on its own.
Monitoring takedown requests
The Lumen database publishes a structured record of every takedown notice (sender, recipient, date, target) and is accessible both through a web interface and programmatically. Regularly querying the database with a filter for sender (Roskomnadzor) and recipient (Google) lets you spot a new request before Google has a chance to act on it, and estimate the typical gap between notice and actual removal, if a removal happens at all.
