Apps targeted at US troops contain Chinese and Russian code

← Back to the feed

Apps targeted at US troops contain Chinese and Russian code

Ars Technica · 7 hours ago

A study by researchers at Purdue University, the US Military Academy at West Point, and Florida International University has found that more than one in eight mobile apps marketed to US military personnel contain software built by companies in China, Russia or other nations, fuelling concerns that adversary governments could use the code to track where troops live, work and deploy. This follows an April admission from US Central Command that adversaries have exploited commercial location data to target American personnel in the Middle East, marking the first official confirmation that troops in an active conflict zone have been surveilled through the data-broker industry.

The researchers examined more than 220 military-focused apps, from uniform guides to banking and dating apps, sourced from Google Play and military subreddits. They found that 64% contained third-party tracking code (SDKs), 40% collected or shared more data than disclosed in app store listings, and about 7% carried code from nations deemed adversarial by the Pentagon, including Huawei's HMS Core, found in twelve apps, and Russian firms using the Yandex ad service. Google and Facebook remained the most common SDK sources overall, though 76 distinct third-party providers were identified in total, spanning China, Russia, Israel, India, Germany and elsewhere.

  • One in eight military-targeted apps contain Chinese or Russian code
  • 64% of 220+ apps studied carried third-party tracking software
  • Adversaries have already used such data to target US troops abroad

Americas Europe World

Read the full article at the source →