Ethical Hacking News
Foreign code in apps marketed to US troops raises serious concerns about data privacy and potential espionage by adversary governments.
The study found that nearly two-thirds of mobile apps marketed towards US military personnel contained third-party code (SDKs) from foreign companies, including China, Russia, and Israel. Forty percent of the apps collected or shared more data than they disclosed in their Google or Apple store listings, highlighting a lack of transparency in the app development process. The most common SDKs came from Google and Facebook, two companies that dominate US digital advertising. A total of 76 different SDKs were found, including code traced back to China, Russia, Israel, India, Germany, and other nations considered adversaries by the Pentagon. Twelve apps contained HMS Core, a Huawei software kit that advertises location mapping and advertising capabilities. Over 83 percent of military-affiliated Americans reported using at least one app engaging in data practices they found uncomfortable, with many being unaware of how to identify and avoid foreign code in their apps.
The United States military has long been a bastion of security and precision, with its personnel often facing life-threatening situations on a daily basis. However, a recent analysis by researchers at Purdue University, the US Military Academy at West Point, and Florida International University has revealed that even the most seemingly innocuous apps marketed to US service members may be harboring foreign code. This alarming discovery raises serious concerns about data privacy and the potential for adversary governments to harvest sensitive information from troops.
The study examined over 220 mobile apps marketed towards US military personnel, which were pulled from the Google Play store and military subreddits. The researchers found that nearly two-thirds of these apps contained third-party code (SDKs), known as prebuilt software components used for analytics and advertising purposes. These SDKs can also track user behavior, including locations, and share this information with outside companies.
Forty percent of the apps collected or shared more data than they disclosed in their Google or Apple store listings, a worrying trend that highlights the lack of transparency in the app development process. The most common SDKs came from Google and Facebook, two companies that dominate US digital advertising. However, 76 turned up in all, including code traced back to China, Russia, Israel, India, Germany, and other nations considered adversaries by the Pentagon.
The study also revealed that twelve of the apps contained HMS Core, a Huawei software kit that advertises the ability to map user locations, deliver ads, and store images and video. Several of these apps were built for state National Guard organizations. While the researchers observed no data actually going to Huawei servers at the time of their investigation, an SDK can be updated remotely at any time. This raises serious concerns about the potential for code that is dormant today to become spyware tomorrow.
Furthermore, the study surveyed 103 military-affiliated Americans, who were active-duty service members, reservists, veterans, DoD civilians, and their families. More than 83 percent of these participants reported using at least one app engaging in data practices they found uncomfortable. On average, those participants used more than three such apps. Between 76 and 83 percent of the survey respondents said they were extremely uncomfortable with apps containing code from China, Russia, Iran, or North Korea – the four nations the Pentagon designates as cyber adversaries.
A lack of institutional guidance on personal app use was a common theme among the survey participants, who reported being unaware of how to identify and avoid foreign code in their apps. The researchers found that nearly two-thirds of the surveyed individuals had received little or no guidance on this issue. Those who did receive some guidance reported that it was inadequate.
In response to these concerns, the researchers proposed several potential mitigations, including in-phone warnings (alerts when foreign or unknown third-party code is present in an installed app) and stricter bans on foreign code in military-marketed apps. Additionally, a federal law restricting data brokers from buying or selling data on military-affiliated personnel was suggested.
The Pentagon has declined to comment on the study's findings, leaving many questions unanswered about their plans for addressing this issue. As the US military continues to face increasing threats from adversary governments, it is essential that they prioritize the security and privacy of their personnel. This includes taking steps to ensure that apps marketed to troops are free from foreign code and do not compromise sensitive information.
In conclusion, the discovery of foreign code in apps marketed to US troops highlights the need for greater transparency and regulation in the app development process. The Pentagon must take immediate action to address these concerns and protect the data privacy of its personnel.
Related Information:
https://www.ethicalhackingnews.com/articles/Unveiling-the-Hidden-Dangers-Foreign-Code-in-Apps-Marketed-to-US-Troops-ehn.shtml
https://www.wired.com/story/apps-marketed-to-us-troops-are-shipping-chinese-and-russian-code/
Published: Mon Jul 20 05:33:15 2026 by llama3.2 3B Q4_K_M