Advertisement
Advertisement
Advertisement
22 July 2026·5 min read·By Konrad Weber

Apps targeted at US troops contain Chinese and Russian code

Apps targeted at US troops contain Chinese and Russian code, with researchers finding foreign SDKs in over one in eight apps.

Apps targeted at US troops contain Chinese and Russian code

Apps targeted at US troops contain Chinese and Russian code

Apps targeted at US troops contain Chinese and Russian code. That's a finding that has sparked concern over the potential for foreign intelligence collection, and recent investigations into mobile software marketed toward military personnel reveal that more than one in eight applications rely on code developed by firms in Russia, China, and other foreign nations. These findings highlight a vulnerability. So adversary governments could track the habits and locations of those serving in the armed forces.

The Hidden Digital Footprint

Mobile apps aren't built from scratch by a single developer anymore. But these same components can facilitate the harvesting of sensitive data, including precise location tracking. The ubiquity of advertising and analytics software means they incorporate third-party components known as software development kits, or SDKs, which help creators monetize their work through ads or gain insights into user behavior. It's a trade-off.

Apps targeted at US troops contain

The results were startling. Researchers examined more than 220 applications, ranging from uniform guides and test-prep resources to banking and social tools, and they found that nearly 64 percent of them contained third-party code. So 76 distinct kits were identified, including those traced back to foreign states, and roughly 7 percent of the apps carried code originating from nations the Pentagon considers cyber adversaries. But many of these kits originate from major American advertising companies.

Risks Beyond The Screen

The danger isn't merely theoretical. It's frighteningly real. An app might function as a simple utility, but the underlying SDKs can be updated remotely at any time, meaning code appearing dormant today could transform into spyware tomorrow without warning. But consider this: in one instance, Huawei software kits were discovered inside applications without the developer even realizing the code had been included as a dependency in a common notification tool.

This exposure carries real-world risks. Location data gathered from seemingly harmless apps has previously shown the ability to trace service members to their homes, schools for their children, and sensitive locations where they are prohibited from being seen. It's dangerous. And such information can assist foreign intelligence in mapping unit movements or identifying personnel with access to restricted sites.

We are grateful for the opportunity to bring greater attention to these issues. We hope the research helps military-affiliated personnel, developers, and platforms make more informed privacy decisions and encourages continued discussion with developers, platforms, and policymakers about how to address these gaps, says Joshua Shinkle, a PhD researcher and lead author of the study.

Soldiers In The Dark

The current digital landscape offers little protection for those in uniform. It's a dangerous gap. Most users can't verify the origin of the code running on their devices, and neither the Google Play store nor the Apple App store requires disclosures regarding the country of origin for the software inside an app. So institutional guidance on personal mobile device usage is often lacking.

Survey participants expressed discomfort regarding these data practices, especially when foreign adversaries are involved. The findings regarding user sentiment include:

  • More than 83 percent of participants reported using at least one app that engaged in data practices making them uncomfortable.
  • Between 76 and 83 percent of participants stated they were extremely uncomfortable with apps containing code from China, Russia, Iran, or North Korea.
  • Nearly two-thirds of military-affiliated respondents said they received little or no guidance on personal app use.
  • Nearly three-quarters of those who did receive guidance described the information as inadequate.

The Path To Accountability

It's a chilling reality. Military personnel are now tracked through the data-broker economy. In April, US Central Command confirmed in a letter to Senator Ron Wyden that it had received reports of adversaries using commercial location data to surveil American personnel in the Middle East. That's an official admission. And it validates a threat researchers have warned about for nearly a decade.

To mitigate these risks, military-affiliated users suggest a shift in policy. It's a simple but urgent fix. Alert systems that notify users when foreign or unknown third-party code is detected on a device ranked as the most desired solution, and they can't afford to ignore such vulnerabilities. Other potential safeguards include federal laws that would restrict data brokers from selling information on military personnel and the implementation of independent privacy audits for apps marketed to the armed forces. But that's not all we've considered.

The Pentagon hasn't commented on the findings. So the burden of managing this digital exposure falls largely on the individual service member, even as the gap between private industry interests and national security requirements continues to widen without any easy fix in sight.

Frequently Asked Questions

What percentage of apps targeted at US troops were found to contain code from nations considered cyber adversaries by the Pentagon?

Roughly 7 percent of the apps carried code originating from nations the Pentagon considers cyber adversaries. This finding highlights a vulnerability where adversary governments could track the habits and locations of those serving in the armed forces.

Why are these apps able to harvest sensitive data like precise location tracking?

Mobile apps incorporate third-party components known as software development kits (SDKs) from advertising and analytics companies. These SDKs help creators monetize their work through ads or gain insights into user behavior, but they can also facilitate the harvesting of sensitive data, including precise location tracking.

How did a Huawei software kit end up inside an app without the developer's knowledge?

In one instance, Huawei software kits were discovered inside applications without the developer even realizing the code had been included as a dependency in a common notification tool. This demonstrates how foreign code can inadvertently find its way into apps.

What evidence from the article confirms that adversaries use commercial location data to surveil American military personnel?

In April, US Central Command confirmed in a letter to Senator Ron Wyden that it had received reports of adversaries using commercial location data to surveil American personnel in the Middle East. This official admission validates a threat researchers have warned about for nearly a decade.

What solution did military-affiliated users rank as the most desired to mitigate risks from foreign code in apps?

Alert systems that notify users when foreign or unknown third-party code is detected on a device ranked as the most desired solution. Other potential safeguards include federal laws restricting data brokers from selling information on military personnel and independent privacy audits for apps marketed to the armed forces.

Konrad Weber
Written by
Infosec and Threats Writer

Konrad Weber writes about the security landscape, from emerging threats to the tools that guard against them. He is focused on helping readers understand risk in a connected world.

💬 Comments (0)

Sign in to leave a comment.

No comments yet. Be the first!

Advertisement