Apps Targeted at US Troops Contain Chinese and Russian Code

Concerns Rise Over Foreign Software in Military-Targeted Apps

A comprehensive analysis of numerous mobile applications designed for US military personnel has revealed that over 12% are embedded with software developed by companies based in adversarial nations, including China and Russia. This alarming finding raises significant concerns regarding the potential for foreign governments to access sensitive information about service members’ locations, workplaces, and deployment activities.

Researchers from Purdue University, the US Military Academy at West Point, and Florida International University conducted the study, which uncovered that one of the widely used applications among military members for rating on-base living conditions includes code from Huawei, a telecom company designated as a national security risk by US regulators in 2020. Additionally, several other apps developed by Russian firms incorporate the Yandex advertising service, further heightening suspicions about the data security of military-affiliated individuals.

The largely unregulated nature of the online advertising industry allows for civilians and military personnel to be tracked in similar ways, which poses risks of exposing troop movements, unit changes, and internal routines in sensitive locations, including sites where nuclear weapons are stored. Investigations have shown that location data harvested from various applications can pinpoint where service members reside, attend school, or visit off-base locations, where their presence is strategically prohibited.

In a notable acknowledgment, US Central Command recently confirmed that adversaries are actively leveraging commercial location data to track American personnel stationed in the Middle East. This was highlighted in a letter addressed to Senator Ron Wyden, marking the first time officials recognized that active-duty troops were being targeted through the data-broker industry. This poses severe implications for security, particularly given that the Pentagon and its contractors have issued warnings about these vulnerabilities for nearly a decade.

The current study serves as a critical examination of the software lurking behind apps specifically tailored for the military sector. Joshua Shinkle, a Purdue University PhD researcher and lead author of the study, expressed hope that the findings would shed light on these issues, enabling military personnel and developers to make more informed decisions related to privacy and security.

The research scrutinized over 220 apps—including uniform guides, examination preparation tools, banking solutions, and dating platforms—gathered from the Google Play Store and military-related online communities. The findings revealed that approximately 64% of these apps contained third-party software components, known as SDKs, which can track user behavior and share data with external organizations.

Alarmingly, the study disclosed that 40% of the analyzed applications collected or disseminated more data than stated in their store listings. While the predominant SDKs were from Google and Facebook—two giants in the US digital advertising landscape—76 different SDKs were identified overall, with ties to nations including China, Russia, Israel, India, and Germany. Notably, around 7% of the apps featured third-party code from countries considered adversarial by the Pentagon.

Among the findings, twelve of the scrutinized apps included HMS Core, a Huawei software development kit that can map user locations and deliver targeted advertising. While no data was found to be actively transmitted to Huawei servers during the study, concerns remain regarding the possibility of remote updates to the SDK, which could introduce spyware at any moment. In one noted instance, Huawei’s code was reportedly introduced without the app developer’s awareness, embedded within a third-party notification tool.

This developing situation underscores the imperative for vigilant cybersecurity measures and the use of frameworks like the MITRE ATT&CK Matrix to assess and mitigate risks associated with initial access, persistence, and other adversarial techniques. With the increasing convergence of technology and security, the defense sector must actively engage in dialogues to fortify its defenses against the exploitation of mobile applications by foreign entities.

Source