Apps Marketed to US Troops Are Shipping Chinese and Russian Code
A study by researchers at Purdue University, the US Military Academy at West Point and Florida International University has found that more than one in eight mobile apps marketed to US troops contain software built by companies in China, Russia and other foreign nations, fuelling concerns that adversary governments could gather data on where service members live, work and deploy. The findings matter because such data has previously been shown to reveal troop movements, unit locations and personnel routines at sensitive sites, including facilities where nuclear weapons are believed to be stored, and US Central Command confirmed in April that adversaries had already used commercial location data to target American personnel in the Middle East.
The researchers examined more than 220 military-focused apps, from uniform guides to banking and dating apps, and found 64% contained third-party tracking code, or SDKs, with 40% collecting or sharing more data than they disclosed. While Google and Facebook supplied the most common SDKs, 76 different providers were identified in total, including firms from China, Russia, Israel, India and Germany, with around 7% of apps containing code from nations considered adversarial by the Pentagon. Twelve apps, some built for state National Guard organisations, contained Huawei's HMS Core kit, which can map user locations, while others used the Russian ad service Yandex.
- Over 1 in 8 military-marketed apps contain Chinese, Russian or foreign-built code
- 64% of 220+ apps studied had tracking SDKs; 40% over-collected data
- Researchers warn this data could expose troop locations to adversaries