Apps Marketed to US Troops Are Shipping Chinese and Russian Code
A recent study found that over one in eight mobile apps marketed to US military personnel contain software built by companies in China, Russia, or other foreign nations, raising concerns about data harvesting and national security.
Intelligence analysis by Llama

Researchers at Purdue University, the US Military Academy at West Point, and Florida International University examined hundreds of mobile apps marketed to US military personnel and found that nearly two-thirds contained third-party code, including code from China, Russia, and other foreign nations. This code can track user behavior, including locations, and share that information with…
Imagine you're a soldier, and you download an app to help you rate living conditions on your base. But what if that app is secretly sending your location and other information to a company in China or Russia? That's what happened with over one in eight mobile apps marketed to US military personnel, according to a recent study. The apps contained software built by companies in foreign nations, which can track user behavior and share that information with outside companies. This raises concerns about data harvesting and national security.
Analysis
A $60B Vote of Confidence
The study's findings are a stark reminder of the risks posed by the largely unregulated advertising industry that tracks Americans online. Despite evidence that exposure can reveal troop deployments, unit movements, and the routines of personnel within intelligence facilities and hardened shelters, the industry continues to treat civilians and service members mostly the same, unless there is profit in telling them apart. The stakes are no longer hypothetical, as the US Central Command acknowledged in a letter to Senator Ron Wyden that it had received multiple threat reports of adversaries exploiting commercial location data to target or surveil American personnel in the Middle East.
Why Cursor?
The researchers examined more than 220 mobile apps marketed to US military personnel, pulled from the Google Play store and military subreddits. Nearly two-thirds of these apps contained third-party code, known as SDKs, which can track user behavior, including locations, and share that information with outside companies. Forty percent of the apps collected or shared more data than they disclosed in their Google or Apple store listings. The most common SDKs came from Google and Facebook, the two companies that dominate US digital advertising. But 76 turned up in all, including code traced back to China, Russia, Israel, India, Germany, and others.
The Road Ahead
The study's findings have significant implications for the Pentagon and the advertising industry. The researchers observed no data actually going to Huawei servers, but an SDK can be updated remotely at any time. Code that is dormant today can still be spyware tomorrow. In at least one case, noted by the study, the Huawei code arrived without the app's developer's knowledge, smuggled in as a dependency in a commercial notification tool. The researchers also surveyed 103 military-affiliated Americans about the data practices they encountered on their own phones. More than 83 percent used at least one app engaging in data practices they said made them uncomfortable.
Key points
- Over one in eight mobile apps marketed to US military personnel contain software built by companies in China, Russia, or other foreign nations.
- Nearly two-thirds of these apps contained third-party code, known as SDKs, which can track user behavior, including locations, and share that information with outside companies.
- Forty percent of the apps collected or shared more data than they disclosed in their Google or Apple store listings.
- The most common SDKs came from Google and Facebook, the two companies that dominate US digital advertising.
- The study's findings have significant implications for the Pentagon and the advertising industry.
The study's findings could lead to greater transparency and regulation in the advertising industry, which could help protect the data of US military personnel and civilians. Additionally, the researchers' recommendations for mitigations, such as in-phone warnings and stricter bans on foreign code in military-marketed apps, could be implemented to reduce the risks posed by these apps.
The study's findings highlight the ongoing risks posed by the largely unregulated advertising industry, which continues to track Americans online and share their data with outside companies. The stakes are high, as the study's findings could be used by adversary governments to harvest data revealing where service members live, work, and deploy.


