iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Werner Enterprises Posts Highest Revenue Per Truck Growth in One-Way Segment in a Decade CMA CGM and Stonepeak Launch United Ports LLC in $2.4 Billion Terminal Joint Venture UPS shift away from Amazon shows bigger payoff Lanesurf: 62% of Loads Get Vetted Carrier Offers Before Brokers Arrive India-China Border Trade Via Lipulekh Resumes Aug 1; China Permits 20 Traders Geopolitics Drives CMA CGM Q2 Profit Surge of 42% as Volumes and Rates Climb Benchmark Diesel Price Rises Third Week as Futures Plunge; Spread Hits Record Indian Government Limits Sugar Dealers to 400 Tonnes Stock Until November to Curb Hoarding Tenants signing longer leases for larger warehouses as 3PLs lock in capacity US stock market flat as S&P 500 and Dow barely move, Nasdaq slides over 1% on chip rout Werner Enterprises Posts Highest Revenue Per Truck Growth in One-Way Segment in a Decade CMA CGM and Stonepeak Launch United Ports LLC in $2.4 Billion Terminal Joint Venture UPS shift away from Amazon shows bigger payoff Lanesurf: 62% of Loads Get Vetted Carrier Offers Before Brokers Arrive India-China Border Trade Via Lipulekh Resumes Aug 1; China Permits 20 Traders Geopolitics Drives CMA CGM Q2 Profit Surge of 42% as Volumes and Rates Climb Benchmark Diesel Price Rises Third Week as Futures Plunge; Spread Hits Record Indian Government Limits Sugar Dealers to 400 Tonnes Stock Until November to Curb Hoarding Tenants signing longer leases for larger warehouses as 3PLs lock in capacity US stock market flat as S&P 500 and Dow barely move, Nasdaq slides over 1% on chip rout
Home ›› Technology ›› Cybersecurity ›› Study Finds Mobile Apps Marketed to US Troops Contain Chinese and Russian Code

Study Finds Mobile Apps Marketed to US Troops Contain Chinese and Russian Code

A study by Purdue University, West Point, and Florida International University examined 220+ mobile apps marketed to US troops, finding that more than one in eight contained software from foreign adversaries like China and Russia. 64% had third-party SDKs, 40% collected more data than disclosed, and 12 apps included Huawei's HMS Core, posing risks for troop location tracking.

iG
iGEN Editorial
July 20, 2026
Study Finds Mobile Apps Marketed to US Troops Contain Chinese and Russian Code

A recent examination of hundreds of mobile apps marketed toward US military personnel found more than one in eight contained software built by companies in China, Russia, or other foreign nations, raising fresh concerns that adversary governments could harvest data revealing where service members live, work, and deploy. According to researchers at Purdue University, the US Military Academy at West Point, and Florida International University, one popular app used by service members to rate living conditions on their own bases include code from Huawei, the Chinese telecom that US regulators flagged as a national security threat in 2020. Two others were built by Russian companies and incorporate the Russian ad service Yandex.

Study Methodology and Key Findings

The researchers examined more than 220 such apps—from uniform guides and promotion-exam prep to banking and dating apps—pulled from the Google Play store and military subreddits. Nearly two-thirds—or 64 percent—contained third-party code, known as SDKs: prebuilt software components, typically used for analytics and advertising, that can also track user behavior, including their locations, and share that information with outside companies. Forty percent of the apps collected or shared more data than they disclosed in their Google or Apple store listings, the researchers found. The most common SDKs came from Google and Facebook, the two companies that dominate US digital advertising. But 76 SDKs turned up in all, including code traced back to China, Russia, Israel, India, Germany, and others. Roughly 7 percent of the apps carried third-party code from a nation considered adversarial by the Pentagon.

Specific Threats: Huawei and Yandex

Twelve of the apps contained HMS Core, a Huawei software kit that advertises the ability to map user locations, deliver ads, and store images and video. Several were built for state National Guard organizations. The researchers observed no data actually going to Huawei servers. But an SDK can be updated remotely at any time. Code that is dormant today can still be spyware tomorrow. In at least one case, the app integrated code from a Russian company using Yandex's advertising services.

Real-World Consequences and Official Acknowledgment

The stakes are no longer hypothetical. In April, US Central Command acknowledged in a letter to Senator Ron Wyden that it had received multiple threat reports of adversaries exploiting commercial location data to target or surveil American personnel in the Middle East, where US forces remain locked in a standoff with the Iranian military over the Strait of Hormuz. Lawmakers called it the first official confirmation that troops in an active war zone were being hunted through the data-broker economy—a threat the Pentagon's own contractors and researchers had warned about for nearly a decade. WIRED investigations have previously shown location data harvested from ordinary apps tracing US service members to their homes, their children's schools, and off-base establishments where troops are prohibited from being seen. Experts have warned the same data could aid foreign spies in identifying personnel with access to sensitive sites, map when a facility is least guarded, or surface other compromising details.

Implications for Enterprise and Supply Chain Security

For technology procurement leaders and CTOs, this study underscores the risk of third-party code in mobile applications, particularly those used by defense-related personnel. The presence of SDKs from adversarial nations in apps built for military use highlights the need for rigorous software supply chain vetting. As the researchers suggest, the findings should encourage "more informed privacy decisions" and continued discussion among developers, platforms, and policymakers. Joshua Shinkle, a Purdue University PhD researcher and the study’s lead author, stated: "We are grateful for the opportunity to bring greater attention to these issues. We hope the research helps military-affiliated personnel, developers, and platforms make more informed privacy decisions and encourages continued discussion with developers, platforms, and policymakers about how to address these gaps."


Sources: WIRED – Top Stories

Keep Reading

Recommended Stories

Ukraine's Tanker and Refinery Campaign Deepens Russia's Fuel Crisis Logistics

Ukraine's Tanker and Refinery Campaign Deepens Russia's Fuel Crisis

Ukraine escalated its campaign against Russian maritime and refinery infrastructure, hitting over 20 shadow fleet tankers in the Kerch Strait and disabling major refineries including Omsk, deepening a fuel crisis that now affects more than 50 Russian regions. The campaign has also sparked diplomatic tensions with Greece after a Ukrainian sea drone was found near Lefkada.

July 9, 2026
Cyberattack on Refrigerated Warehouse Disrupts Glico, KFC Japan, and Sushi Deliveries Technology

Cyberattack on Refrigerated Warehouse Disrupts Glico, KFC Japan, and Sushi Deliveries

A cyberattack on Japan's largest refrigerated warehouse operator, Nichirei, has disrupted supplies for Ezaki Glico, KFC Japan, and Kura Sushi. The incident highlights critical vulnerabilities in food supply chain technology and logistics networks.

July 16, 2026
War Game Reveals Catastrophic Fallout from Chinese Cyberattack on US Water Supply Technology

War Game Reveals Catastrophic Fallout from Chinese Cyberattack on US Water Supply

In a simulated cyberattack on US water utilities, a war game orchestrated by former CISA strategist Joshua Corman showed cascading failures across food refrigeration, drug manufacturing, data centers, and hospitals. The scenario, tied to Chinese military hackers from Volt Typhoon, forced insurance executives to allocate scarce resources under extreme pressure.

July 8, 2026
EU Politician Investigating Pegasus Spyware Was Hacked With the Same Malware, Citizen Lab Finds Technology

EU Politician Investigating Pegasus Spyware Was Hacked With the Same Malware, Citizen Lab Finds

A new analysis by Citizen Lab reveals that Greek MEP Stelios Kouloglou, a member of the European Parliament's PEGA Committee investigating Pegasus spyware, had his iPhone hacked multiple times with the same spyware. The incident marks the first time a committee member has been identified as a victim and highlights the brazen targeting of European lawmakers. Researchers could not identify the attacker but warn of severe security implications for parliamentary work.

July 3, 2026