A recent exam of hundreds of mobile apps marketed to U.S. military personnel found that more than one in eight contained software created by companies in China, Russia or other foreign nations, raising new concerns that adversary governments could collect data that reveals where service members live, work and deploy. According to researchers at Purdue
A recent exam of hundreds of mobile apps marketed to U.S. military personnel found that more than one in eight contained software created by companies in China, Russia or other foreign nations, raising new concerns that adversary governments could collect data that reveals where service members live, work and deploy.
According to researchers at Purdue University, the U.S. Military Academy at West Point and Florida International University, a popular app used by service members to rate living conditions on their own bases includes code from Huawei, the Chinese telecommunications company that U.S. regulators flagged as a national security threat in 2020. Two others were built by Russian companies and incorporate the Russian advertising service Yandex.
The largely unregulated advertising industry that tracks Americans online treats civilians and service members virtually the same (unless there is profit in differentiating them), despite evidence that exposure can reveal troop deployments, unit movements, and the routines of personnel inside intelligence facilities and hardened shelters where nuclear weapons are believed to be stored.
WIRED investigations have previously shown location data collected from ordinary apps tracking U.S. service members to their homes, their children’s schools and off-base establishments where seeing troops is prohibited. Experts have warned that the same data could help foreign spies identify personnel with access to sensitive sites, map when a facility is less guarded or reveal other compromising details.
What is at stake is no longer hypothetical. In April, US Central Command acknowledged in a letter to Senator Ron Wyden that it had received multiple reports of threats from adversaries exploiting commercial location data to attack or surveil US personnel in the Middle East, where US forces remain locked in a standoff with the Iranian military over the Strait of Hormuz. Lawmakers called it the first official confirmation that troops in an active war zone were being targeted through the data broker economy, a threat that the Pentagon’s own contractors and researchers had warned about for nearly a decade.
The new study takes a first look at one part of that exposure: what’s really inside the apps created and marketed specifically for the military.
“We are grateful for the opportunity to bring greater attention to these issues,” says Joshua Shinkle, a doctoral researcher at Purdue University and lead author of the study. “We hope the research helps military-affiliated personnel, developers, and platforms make more informed privacy decisions and encourages continued discussion with developers, platforms, and policymakers about how to address these gaps.”
Researchers examined more than 220 such apps, from uniform guides and promotion exam prep to banking and dating apps, pulled from the Google Play store and military subreddits. Nearly two-thirds (or 64 percent) contained third-party code, known as SDKs: pre-built software components, typically used for analytics and advertising, that can also track user behavior, including their locations, and share that information with outside companies.
The researchers found that forty percent of the apps collected or shared more data than they disclosed in their Google or Apple store listings.
The most common SDKs come from Google and Facebook, the two companies that dominate digital advertising in the United States. But 76 in total turned up, including code traced to China, Russia, Israel, India, Germany and others. About 7 percent of the apps carried third-party code from a nation considered troublesome by the Pentagon.
Twelve of the apps contained HMS Core, a software kit from Huawei that advertises the ability to map user locations, deliver ads, and store images and videos. Several were built for state National Guard organizations.
The researchers noted that there was no data reaching Huawei’s servers. But an SDK can be updated remotely at any time. Code that is inactive today may still be spyware tomorrow. In at least one case, noted by the study, Huawei code arrived without the knowledge of the app developer, smuggled in as a dependency on a commercial notification tool.
For more tech updates, stay tuned to our blog.

















