Military Apps Found Teeming with Foreign Code, Raising Espionage Fears
A new study reveals that over one in eight mobile applications marketed to US military personnel contain software components from companies in adversarial nations like China and Russia. This discovery raises significant concerns about the potential for foreign governments to harvest sensitive data, including location information, on service members.
A recent investigation into hundreds of mobile applications targeting **US military personnel** has uncovered a disturbing trend: more than one in eight contain software built by companies in nations considered adversarial, including **China** and **Russia**. This finding intensifies concerns that foreign governments could exploit these apps to collect intelligence on service members' residences, workplaces, and deployments.
Researchers from **Purdue University**, the **US Military Academy at West Point**, and **Florida International University** led the study. They found that a popular app used by service members to rate base living conditions included code from **Huawei**, the Chinese telecom company designated a national security threat by US regulators in 2020. Additionally, two other apps were developed by Russian companies and incorporated **Yandex**, a Russian advertising service.
### The Unregulated Ad Industry's Role
The largely unregulated digital advertising industry, which extensively tracks Americans online, typically treats civilians and service members identically. This practice persists despite ample evidence that exposure through such data can reveal troop deployments, unit movements, and the routines of personnel in sensitive facilities, including those potentially housing nuclear weapons.
Previous investigations have highlighted how location data harvested from ordinary apps has traced US service members to their homes, children's schools, and off-base establishments. Experts have warned that this data could assist foreign spies in identifying personnel with access to sensitive sites, mapping facility vulnerabilities, or uncovering other compromising details.
### Real-World Consequences Confirmed
The threat is no longer theoretical. In April, **US Central Command** acknowledged in a letter to Senator Ron Wyden that it had received multiple reports of adversaries exploiting commercial location data to target or surveil American personnel in the Middle East. Lawmakers have cited this as the first official confirmation of troops in an active war zone being hunted through the data-broker economy β a risk that the Pentagon's own contractors and researchers had warned about for nearly a decade.
This new study provides a crucial first look into the internal components of apps specifically designed and marketed for military use.
βWe are grateful for the opportunity to bring greater attention to these issues,β stated **Joshua Shinkle**, a Purdue University PhD researcher and the studyβs lead author. βWe hope the research helps military-affiliated personnel, developers, and platforms make more informed privacy decisions and encourages continued discussion with developers, platforms, and policymakers about how to address these gaps.β
### Deep Dive into App Components
The researchers analyzed over 220 such apps, ranging from uniform guides and promotion-exam prep to banking and dating applications, sourced from the **Google Play Store** and military subreddits. Nearly two-thirds (64%) contained third-party code, known as **SDKs** (Software Development Kits). These prebuilt software components are typically used for analytics and advertising but can also track user behavior, including location, and share this information with external companies.
The study found that 40% of the examined apps collected or shared more data than they disclosed in their Google or Apple store listings.
While **Google** and **Facebook** SDKs were the most prevalent, a total of 76 unique SDKs were identified, with origins traced back to China, Russia, Israel, India, Germany, and other countries. Approximately 7% of the apps contained third-party code from a nation considered adversarial by the Pentagon.
Specifically, twelve of the apps incorporated **HMS Core**, a Huawei software kit advertised with capabilities for mapping user locations, delivering ads, and storing images and video. Several of these apps were developed for state National Guard organizations.
Although the researchers did not observe any data actively being transmitted to Huawei servers, an SDK can be updated remotely at any time. Code that appears dormant today could potentially become spyware tomorrow. In at least one instance, the Huawei code was integrated without the app developer's knowledge, smuggled in as a dependency within a commercial notification tool.