logo

Apps targeted at US troops contain Chinese and Russian code

ID: 3824f014-afd1-596c-ba0a-013381eba876

STIX ID: report--3824f014-afd1-596c-ba0a-013381eba876

Feed Name: Ars Technica Security (category)

Threat Score
35/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Dell Cameron, wired.com

...
...

A Purdue-led study examined over 220 military-focused apps from Google Play and related subreddits and found that 64% included third-party SDKs (analytics/ads) and 40% collected or shared more data than disclosed; SDKs traced to multiple countries — including ones the Pentagon considers adversarial — appeared in roughly 7% of apps and Huawei's HMS Core was present in 12 apps (some used by state National Guard). The researchers observed no active data exfiltration to Huawei, but warned that SDKs can be updated remotely or be included unknowingly via dependencies, creating a supply-chain/privacy risk for military-affiliated users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.