A sweeping analysis of mobile applications marketed to U.S. military personnel has uncovered that more than one in eight apps contain software developed by companies based in China, Russia, or other foreign nations—raising urgent national security concerns about data exfiltration and surveillance of American troops.

Researchers from Purdue University, the U.S. Military Academy at West Point, and Florida International University examined hundreds of apps available on official app stores and found that many included code from Huawei, the Chinese telecommunications giant labeled a national security threat by U.S. regulators in 2020, as well as the Russian advertising service Yandex. One popular app used by service members to rate living conditions on bases was found to contain Huawei code, potentially allowing adversaries to access sensitive location data.

Scope of the Problem

The findings, reported by Ars Technica and Wired, align with a Reuters investigation that revealed Russian software disguised as American had found its way into U.S. Army and CDC apps. The Reuters report detailed how a Russian company marketed its software development kit as American-made, only to be discovered embedded in official government applications. This trend is not limited to the U.S.: a separate Tech Transparency Project report found that Apple’s App Store offers apps with ties to the Chinese military, while the BBC has questioned whether TikTok—owned by Chinese company ByteDance—poses a danger to Western users.

“The largely unregulated advertising industry that tracks Americans online treats civilians and service members mostly the same—unless there is profit in telling them apart,” the researchers noted, warning that exposure can reveal troop deployments, unit movements, and routines of personnel within intelligence facilities and hardened shelters where nuclear weapons are believed to be stored.

Broader Geopolitical Context

The app security revelations come amid a cascade of reports highlighting escalating cyber and intelligence activities by Russia and China. According to The Wall Street Journal, U.S. officials have warned that Russia is secretly sharing the location of U.S. targets with Iran, while CNN reported that Russia is aiding Iran’s war effort by providing intelligence on U.S. military targets. In a separate development, the WSJ also reported that two U.S. troops were killed and one is missing after an Iranian missile attack in Jordan, underscoring the real-world consequences of intelligence sharing.

On the cyber front, Reuters and The Record have documented Russian-backed hackers breaching Signal and WhatsApp accounts of officials and journalists, with the Netherlands issuing a warning about state-sponsored targeting. Google warned that Russian hackers are hijacking Signal to spy on Ukrainian soldiers, and a separate report from The Hacker News detailed how hackers exploit Signal’s linked devices feature via malicious QR codes. The UK’s NCSC also issued a warning about messaging app targeting by Russia-linked actors.

Chinese Cyber Threats

China’s cyber capabilities are equally concerning. The New York Times reported that “unrestrained” Chinese cyber attackers may have stolen data from almost every American, while The Guardian revealed that the U.S. nuclear weapons agency was among 400 organizations breached by Chinese hackers. Recorded Future noted that China’s PLA Unit 61419 is purchasing foreign antivirus products, likely for exploitation. Meanwhile, a leaked Russian intelligence document reported by the NYT shows deep suspicion of China, with Russia’s FSB reportedly calling China “the enemy”—a revelation that complicates the narrative of a unified Russia-China front.

U.S. Response and Vulnerabilities

The U.S. government has taken some steps to address these threats. Reuters reported that the Pentagon has threatened to prosecute Senator Mark Kelly by recalling him to Navy service, though the connection to cybersecurity is unclear. More directly, CNN reported that secret U.S. cyber operations shielded the 2024 election from foreign trolls, but the Trump administration has gutted those protections. The Pentagon has also stated that the U.S. is not veering into a new, endless war, even as tensions with Iran escalate.

However, the presence of foreign code in military apps suggests a systemic vulnerability. The largely unregulated app ecosystem allows third-party code to be integrated without thorough vetting. “This is a classic supply chain attack,” said a cybersecurity expert quoted by NTD. “Adversaries don’t need to hack into a system if they can simply embed their code in a trusted app.”

Expert Views and Implications

Noah Smith, writing on his blog, posed the question: “Are we in the foothills of World War 3?” The convergence of cyber espionage, intelligence sharing, and kinetic attacks—such as the missile strike in Jordan—suggests a new era of hybrid warfare. The Chatham House analysis of advanced military technology in Russia, including AI applications, indicates that both Russia and China are investing heavily in cyber and electronic warfare capabilities.

The implications for U.S. national security are profound. If adversaries can track troop movements via apps, they can target them more effectively. The Pentagon’s assurance that it is not seeking endless war may ring hollow if troops’ locations are compromised through everyday technology.

Conclusion

The discovery of Chinese and Russian code in apps used by U.S. military personnel is a wake-up call. It highlights the need for stricter app vetting, supply chain security, and international cooperation to counter state-sponsored cyber threats. As the line between digital and physical warfare blurs, the security of service members—and the nation—depends on addressing these vulnerabilities before they are exploited on the battlefield.

“This is a classic supply chain attack. Adversaries don’t need to hack into a system if they can simply embed their code in a trusted app.” — Cybersecurity expert quoted by NTD