Apps Used by US Troops Found to Contain Chinese and Russian Code

A recent study has shed light on the data exposure risks associated with military-specific applications, revealing critical insights into their content and security vulnerabilities. This research, led by Joshua Shinkle, a PhD candidate at Purdue University, aims to heighten awareness among military personnel, developers, and policymakers regarding privacy decisions and the potential shortcomings in current app frameworks.

The researchers conducted a thorough examination of over 220 military-focused applications, ranging from guides for uniforms to promotion exam preparations, as well as banking and dating platforms, sourced from the Google Play Store and military-focused online communities. Alarmingly, nearly 64 percent of these applications were found to incorporate third-party software components, known as SDKs, which are primarily utilized for analytics and advertising but can also track user behavior, including location data, and may share that information with external entities.

The study indicates that approximately 40 percent of these applications disclosed less data in their store listings than they actually collected or shared. Notably, the predominant SDKs belonged to major tech companies such as Google and Facebook, which lead the US digital advertising market. However, a broad range of other SDKs was identified, including those linked to nations considered adversarial by the Pentagon, such as China and Russia. In fact, around 7 percent of the applications included third-party code from these identified adversaries.

One concerning finding was the presence of the HMS Core, a software toolkit from Huawei, across twelve applications, some specifically tailored for state National Guard organizations. While the researchers did not observe any data transmission to Huawei servers, it is essential to acknowledge that SDKs can be updated remotely, meaning existing dormant code may become malicious without notice. In one instance documented in the study, Huawei’s code was integrated without the developers’ knowledge, surfacing as a dependency in a commercial notification tool.

Given these revelations, it is critical for business leaders to consider their vulnerability to similar data privacy issues. The risk associated with third-party code integration parallels tactics outlined in the MITRE ATT&CK Matrix, particularly in areas such as initial access and persistence. Adversaries may employ strategies that leverage software dependencies to introduce malicious code while remaining under the radar of developers and system administrators.

As the cybersecurity landscape continues to evolve, the findings of this study serve as a timely reminder of the importance of rigorous app scrutiny and proactive measures to mitigate data exposure risks, particularly in applications tied to sensitive sectors such as the military. Engaging in ongoing dialogue with developers, platform owners, and policymakers is crucial in addressing the existing vulnerabilities and establishing comprehensive strategies to safeguard user data.

Source