Tech

Study reveals foreign code in apps targeting US military personnel

More than one-eighth of 220 apps analysed contained third-party software from adversarial nations, raising concerns over troop location data despite no observed data transmission to Huawei servers in the specific cases studied.

Author
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: Ars Technica · original
Apps targeted at US troops contain Chinese and Russian code
Purdue University and West Point researchers find Chinese and Russian SDKs in banking, dating and living condition tools

A joint study by researchers from Purdue University, the US Military Academy at West Point, and Florida International University has identified significant cybersecurity vulnerabilities within mobile applications marketed to US military personnel. The examination of more than 220 apps, including those for banking, dating, and living conditions, found that over one-eighth contained software development kits (SDKs) from companies based in China, Russia, or other foreign nations. These third-party components possess the capability to track user location and behaviour, creating potential avenues for data harvesting by adversary governments.

The research, which pulled data from the Google Play store and military subreddits, revealed that nearly two-thirds of the analysed apps contained third-party code. While the most common SDKs originated from US firms such as Google and Facebook, the study identified 76 instances of code traced back to nations including China, Russia, Israel, India, and Germany. Approximately 7 percent of the apps carried third-party code from nations considered adversarial by the Pentagon. Notably, twelve apps contained HMS Core, a Huawei software kit capable of mapping user locations and storing media, with several of these built for state National Guard organisations.

Despite the presence of foreign code, the researchers observed no data being transmitted to Huawei servers in the specific cases analysed. However, experts warn that the risk remains acute because SDKs can be updated remotely. Code that is dormant at the time of analysis could be activated later to function as spyware. In at least one instance, Huawei code was found to have been smuggled into an app as a dependency within a commercial notification tool, without the knowledge of the app’s developer.

These findings align with broader security concerns already acknowledged by US military leadership. In April, US Central Command confirmed in a letter to Senator Ron Wyden that it had received multiple threat reports of adversaries exploiting commercial location data to target or surveil American personnel in the Middle East. This threat is particularly relevant given previous investigations showing that location data harvested from ordinary apps has been used to trace service members to their homes, schools, and off-base establishments.

Survey data from the study indicated that 83 percent of military-affiliated participants used at least one app engaging in data practices they found uncomfortable, with many expressing extreme discomfort regarding apps containing code from China, Russia, Iran, or North Korea. Participants reported a lack of institutional guidance on app usage and noted that neither Google’s Play Store nor Apple’s App Store discloses the country of origin for software within apps. Respondents ranked in-phone warnings about foreign code as the most effective mitigation, alongside support for federal laws restricting data broker access to military personnel information.

Continue reading

More from Tech

Read next: Open-source tool claims 97 per cent token savings for AI agents
Read next: Valvoline Unveils August 2026 Promotional Offers for Service and Retail Buyers
Read next: Developer Antirez releases native MiniMax H3 inference engine for Apple Silicon