← BACK TO FEED
military securitydata privacyHuaweiSDKssurveillance

Military Apps Riddled With Chinese and Russian Code, Study Finds

A study by researchers from Purdue University, West Point, and Florida International University found that over one in eight apps marketed to US military personnel contain code from companies in adversarial nations, including China and Russia, potentially enabling foreign governments to track troop movements and locations. Nearly two-thirds of the 220+ examined apps included third-party tracking software, with roughly 7 percent carrying code from Pentagon-designated adversaries, and 40 percent collected more data than disclosed in their store listings. Despite growing evidence of real-world threats — including a US Central Command acknowledgement that adversaries have exploited commercial location data to target troops in the Middle East — service members receive little institutional guidance on app privacy, and neither major app store discloses the national origin of code running inside apps.

Researchers from Purdue University, West Point, and Florida International University have gone through more than 220 mobile apps aimed at US military personnel and found that over one in eight contain software components built by companies in China, Russia, or other foreign nations. The implications are about as comfortable as you'd expect.

Among the findings: a well-used app that lets service members rate living conditions on their own bases contains code from Huawei, the Chinese telecom that US regulators formally designated a national security threat back in 2020. Two other apps were developed by Russian companies and bake in Yandex's advertising infrastructure. Neither detail appears to have been widely known by the people using them.

The broader problem is the advertising ecosystem that underpins most of the modern internet. It treats soldiers and civilians identically, which sounds superficially fair but is actually a serious intelligence vulnerability. Location data harvested from mundane apps has already been shown, through previous WIRED investigations, to trace service members to their homes, their kids' schools, and off-limits establishments. The same data streams can theoretically map patrol patterns, identify personnel with access to sensitive sites, or reveal when a base is understaffed. The nuclear storage angle isn't speculation either — some of the facilities in question are believed to house nuclear weapons.

The threat stopped being theoretical in April, when US Central Command confirmed in writing to Senator Ron Wyden that it had received multiple reports of adversaries using commercial location data to track or surveil American troops in the Middle East. Lawmakers described it as the first official acknowledgement that soldiers in an active operational zone were being hunted through the commercial data broker market, something Pentagon-adjacent researchers had been warning about for the better part of a decade.

The new study drills into one specific slice of this problem: what's actually embedded in the apps built and sold for military audiences.

Nearly two-thirds of the apps studied contained third-party SDKs — prebuilt software components typically used for analytics and advertising. Forty percent collected or shared more data than they disclosed to users through their app store listings. Seventy-six different SDKs appeared across the dataset, with code tracing back to China, Russia, Israel, India, Germany, and elsewhere. Around 7 percent of apps carried third-party code from a country the Pentagon formally considers adversarial.

Twelve apps contained Huawei's HMS Core, a software kit with capabilities including location mapping, ad delivery, and media storage. Several of these were built for state National Guard organisations.

To be clear, the researchers did not observe data actually transmitting to Huawei servers. But that's a limited reassurance. SDKs can be updated remotely at any point, and dormant code can become active without notice. In at least one documented case, the Huawei code arrived inside an app without the developer's knowledge, bundled as a dependency within a third-party notification tool they had deliberately chosen.

The team also surveyed 103 military-affiliated Americans — active duty, reservists, veterans, DoD civilians, and family members — on their own app habits. More than 83 percent were using at least one app with data practices they found uncomfortable. On average, each person used more than three such apps. Between 76 and 83 percent said they were extremely uncomfortable with apps containing code from China, Russia, Iran, or North Korea specifically. Yet none of them had any reliable way of knowing which apps carried such code, because neither Google's Play Store nor Apple's App Store requires disclosure of the national origin of embedded software components.

Perhaps the most pointed finding: participants reported feeling more comfortable with data collection when an app was branded as military-specific. Which is precisely backwards, given what this study found sitting inside those apps.

Almost two-thirds of respondents said they had received little to no institutional guidance on personal app use. Of those who had received some, nearly three-quarters found it inadequate.

The Pentagon declined to comment.

When asked what fixes they would actually support, participants ranked in-phone alerts flagging foreign or unidentified third-party code as the most effective and most palatable option. Federal restrictions on data brokers trading in military personnel data, independent privacy audits, and stricter controls on foreign code in military-marketed apps all received nearly equal support.

The fixes are not complicated. The will to implement them is apparently another matter.

READ NEXT
Meta's Apps Hoover Up Three Times More User Data Than Apple's, Study ClaimsApple Pings Users in 110 Countries Over Mercenary Spyware ThreatsAI on the Battlefield: How Automated Kill Chains Leave Humans Mostly Out of the Loop