Apps Marketed to US Troops Are Shipping Chinese and Russian Code

By GrowthMax Agency Published July 20, 2026 • 5 min read

The Unseen Dangers of Military Apps

A recent study of over 220 mobile apps marketed towards US military personnel has uncovered a disturbing trend: more than one in eight contain software built by companies in China, Russia, or other foreign nations. This raises concerns that adversary governments could harvest data revealing the personal lives, work, and deployments of service members. The largely unregulated advertising industry that tracks Americans online treats civilians and service members similarly, despite evidence that exposure can reveal troop deployments and personnel routines.

The study, conducted by researchers at Purdue University, the US Military Academy at West Point, and Florida International University, found that one popular app used by service members to rate living conditions on their bases included code from Huawei, the Chinese telecom that US regulators flagged as a national security threat in 2020. Two others were built by Russian companies and incorporate the Russian ad service Yandex. This highlights the lack of regulation in the advertising industry and the potential risks associated with foreign code in military apps.

The study also surveyed 103 military-affiliated Americans about their data practices and found that over 83% used at least one app that engaged in data practices that made them uncomfortable. On average, those participants used more than three such apps. The majority of participants were extremely uncomfortable with apps containing code from China, Russia, Iran, or North Korea, but no user has a straightforward way to know which apps carry such code.

The Mechanics of Foreign Code in Military Apps

So, how does foreign code end up in military apps? The study found that 64% of the apps examined contained third-party code, known as SDKs, which can track user behavior, including their locations, and share that information with outside companies. The most common SDKs came from Google and Facebook, but 76 turned up in all, including code traced back to China, Russia, Israel, India, Germany, and others. Roughly 7% of the apps carried third-party code from a nation considered adversarial by the Pentagon.

In some cases, the foreign code arrived without the app’s developer’s knowledge, smuggled in as a dependency in a commercial notification tool. For example, the study found that the Huawei code in one app arrived without the developer’s knowledge. This highlights the need for greater transparency and regulation in the app development process.

The study’s findings also raise questions about the role of Google and Facebook in the advertising industry. While the two companies dominate US digital advertising, their SDKs were found in many of the apps examined. This raises concerns about the potential for data breaches and the need for greater regulation of the advertising industry.

The Winners and Losers in the Military App Market

The study’s findings have significant implications for the military app market. On one hand, the use of foreign code in military apps creates a significant risk for service members and the military as a whole. On the other hand, the study’s findings also highlight the need for greater transparency and regulation in the app development process.

The winners in this scenario are likely to be companies that prioritize transparency and security in their app development process. The losers, on the other hand, are likely to be companies that fail to prioritize these concerns. The study’s findings also highlight the need for greater regulation of the advertising industry and the potential for data breaches.

In terms of specific winners and losers, the study’s findings are likely to impact companies that develop apps for the military. Companies that prioritize transparency and security in their app development process are likely to benefit from the study’s findings, while those that fail to prioritize these concerns are likely to lose out.

The Skeptical Case

One potential skeptical case against the study’s findings is that the use of foreign code in military apps is not necessarily a security risk. After all, many apps use third-party code to track user behavior and share that information with outside companies. However, this argument misses the point that the use of foreign code in military apps creates a significant risk for service members and the military as a whole.

Another potential skeptical case is that the study’s findings are based on a limited sample size and may not be representative of the broader military app market. However, this argument ignores the fact that the study’s findings are consistent with previous research on the topic and highlight a significant risk that needs to be addressed.

The Signal to Watch Next

The signal to watch next in this scenario is the response of the military and the app development industry to the study’s findings. Will the military take steps to regulate the use of foreign code in military apps? Will app developers prioritize transparency and security in their development process?

One potential indicator of the military’s response is the development of new regulations or guidelines for the use of foreign code in military apps. Another potential indicator is the adoption of new technologies or processes that prioritize transparency and security in app development.

Pick one tactic from this post and apply it today. Which one will you start with?

By Daniel Cross, Digital Growth Strategist at TrendFlashy

Ready to launch your own asset?

Check out our guide on Building a Profitable Online Business.

Related Articles