Mon 20 Jul 2026 / 22:19 ET
Kernel
Internet 4 min read

Military apps carry foreign ad and analytics code, study finds

Researchers found third-party software from China, Russia and other countries inside apps aimed at US service members.

Dana Voss

By Dana Voss / Security Correspondent

Military apps carry foreign ad and analytics code, study finds
img: WIRED

Mobile apps pitched to US troops and their families are carrying third-party software from foreign companies, including code tied to China and Russia, according to researchers at Purdue University, the US Military Academy at West Point, and Florida International University. For service members, that is not a theoretical privacy annoyance. Commercial app data can expose where people sleep, train, socialize, and deploy.

The researchers examined more than 220 Android apps marketed to military users, drawing the apps from Google Play and military-focused Reddit communities. The set included uniform guides, promotion test tools, banking apps, dating apps, and other military-branded services.

Nearly two-thirds of the apps contained third-party software development kits, or SDKs, the study found. These prebuilt components are the duct tape of the app economy: developers add them for ads, analytics, notifications, mapping, and other features, then the SDK provider may receive data from the app. Depending on permissions and implementation, that data can include user behavior and location.

The study found that more than one in eight of the apps included code made by companies in China, Russia, or other foreign countries. About 7 percent contained third-party code from countries the Pentagon treats as adversarial. Across the sample, researchers identified 76 SDKs, with Google and Facebook the most common, alongside code traced to China, Russia, Israel, India, Germany, and other countries.

Huawei and Yandex turned up in the code

Twelve apps included HMS Core, a Huawei software kit. Huawei has been treated by US regulators as a national security risk since 2020. HMS Core advertises functions including location mapping, ad delivery, and storage for images and video. Several of the apps carrying it were built for state National Guard organizations, according to the study.

The researchers said they did not observe data flowing to Huawei servers. That finding limits what can be claimed: the presence of an SDK is not proof that Huawei received troop data. It is still a supply-chain risk. SDKs can be changed through updates, and the developer who ships an app may not fully understand every dependency buried inside commercial tooling. In one case cited by the researchers, Huawei code arrived through a notification product without the app developer knowing it was there.

Two apps in the study were made by Russian companies and used Yandex, Russia’s ad service, according to the researchers.

The disclosure problem is blunt. Google’s Play Store Data Safety section and Apple’s App Store Privacy Labels do not list the country of origin for code inside an app. The researchers also found that 40 percent of the apps collected or shared more information than their Google or Apple store listings disclosed.

Service members do not get much warning

The team also surveyed 103 military-affiliated Americans, including active-duty personnel, reservists, veterans, Defense Department civilians, and family members. More than 83 percent used at least one app with data practices they said made them uncomfortable. On average, participants used more than three such apps.

Between 76 percent and 83 percent of participants said they were extremely uncomfortable with apps containing code from China, Russia, Iran, or North Korea, the four countries the Pentagon designates as cyber adversaries. Participants also reported more comfort with data collection when an app was branded for military users, a useful reminder that camouflage on the icon is not a privacy control.

Nearly two-thirds of surveyed participants said they had received little or no institutional guidance on personal app use. Among those who had received guidance, almost three-quarters described it as inadequate. The Pentagon declined to comment.

The concern sits inside a broader data-broker problem. WIRED has previously reported that location data from ordinary apps can trace US service members to homes, schools, restricted off-base locations, and sensitive facilities. In April, US Central Command told Senator Ron Wyden it had received multiple threat reports about adversaries using commercial location data to target or surveil US personnel in the Middle East.

When asked about fixes, survey participants favored phone-level alerts that would warn when installed apps contain foreign or unidentified third-party code. They also supported restrictions on brokers buying or selling data about military-affiliated people, outside audits of app privacy disclosures, and tighter limits on foreign code in apps marketed to the military.

This story draws on original reporting from WIRED.

More Internet/

view all ↗