24 July 2026

Apps Marketed to US Troops Are Shipping Chinese and Russian Code

Wired  |  Dell Cameron

A collaborative study by Purdue University, the US Military Academy at West Point, and Florida International University reveals that over 12 percent of mobile apps targeted at US military personnel contain software development kits from foreign adversaries like China and Russia. This widespread integration of foreign code exposes service members to covert location tracking and data harvesting by hostile intelligence services.

Commercial advertising networks and unregulated data brokers routinely aggregate these digital footprints, transforming benign activities like base housing reviews or promotion prep into actionable intelligence. The operational risks are acute, as US Central Command recently confirmed that adversaries have already exploited commercial location data to target American forces in the Middle East. Despite these vulnerabilities, nearly two-thirds of surveyed military personnel report receiving inadequate institutional guidance regarding personal device security. Consequently, researchers are urging the implementation of in-phone warning systems to alert users when unauthorized third-party code is active.

Comment
Adversarial software development kits in military-adjacent applications mirror the vulnerabilities exposed during the 2018 Strava fitness tracker leak in Helmand Province. To counter this vector, the Indian Army issued a comprehensive directive in 2020 banning 89 mobile applications from personnel devices. Such vulnerabilities necessitate the establishment of centralized, sovereign application repositories for defence personnel to bypass commercial marketplaces. Ultimately, tactical operational security in modern conflict zones requires treating personal mobile devices as active electronic warfare targets.

No comments: