Military Apps Contain Code From China, Russia, Study Finds
More than one in eight apps marketed to U.S. service members include software from adversary nations, raising espionage and surveillance concerns.
First comprehensive audit reveals foreign code in military apps
A groundbreaking analysis of mobile applications marketed to U.S. military personnel has uncovered that more than one in eight contain software components built by companies in China, Russia, and other nations the Pentagon classifies as adversaries.
Researchers from Purdue University, the U.S. Military Academy at West Point, and Florida International University examined over 220 apps specifically targeting service members—ranging from uniform guides and promotion exam preparation tools to banking and dating platforms. The team found that roughly 13 percent included third-party code from countries considered hostile by the Department of Defense.
According to WIRED, which first reported the findings, one popular app used by troops to rate base living conditions contains code from Huawei, the Chinese telecommunications firm that U.S. regulators designated a national security threat in 2020. Two other apps were built by Russian companies and incorporate the Russian advertising service Yandex.
Why it matters
This research arrives as U.S. Central Command has confirmed receiving multiple threat reports of adversaries exploiting commercial location data to target American personnel in the Middle East. The study provides the first systematic look at what's actually inside military-focused apps, revealing a previously unmapped attack surface that could enable foreign intelligence services to track troop movements, identify personnel with security clearances, or map when sensitive facilities are least guarded.
Hidden data collection widespread
The researchers discovered that nearly two-thirds of the examined apps contained third-party software development kits (SDKs)—prebuilt code components typically used for analytics and advertising that can also track user behavior and location data.
Forty percent of the apps collected or shared more data than they disclosed in their Google Play or Apple App Store listings. The study identified 76 different SDKs in total, with code traced to China, Russia, Israel, India, Germany, and other nations. While Google and Facebook SDKs were most common, approximately 7 percent of apps carried third-party code from Pentagon-designated adversary nations.
Twelve apps contained HMS Core, a Huawei software kit capable of mapping user locations, delivering advertisements, and storing media files. Several were built for state National Guard organizations. In at least one case, Huawei code arrived without the developer's knowledge, embedded as a dependency within a commercial notification tool.
Service members lack guidance and transparency
The research team surveyed 103 military-affiliated Americans, including active-duty personnel, reservists, veterans, and Defense Department civilians. More than 83 percent used at least one app with data practices they found uncomfortable, averaging more than three such apps per person.
Between 76 and 83 percent of participants said they were extremely uncomfortable with apps containing code from China, Russia, Iran, or North Korea. However, neither Google's Play Store nor Apple's App Store currently discloses the country of origin for software running inside applications.
Nearly two-thirds of respondents reported receiving little or no institutional guidance on personal app use. Of those who received some guidance, nearly three-quarters called it inadequate. The Pentagon declined to comment on the findings.
When asked about potential solutions, participants ranked in-phone warnings—alerts when foreign or unknown third-party code is detected—as both the most effective and most likely to gain their support. Federal restrictions on data brokers selling military personnel information, independent privacy audits, and stricter bans on foreign code in military-marketed apps drew nearly identical support.
The details were first reported by Dell Cameron at WIRED.
This is an original analysis by the Omega editorial team. Source reporting: WIRED.
Want systems like this working for your business?
Book a Call
