US Troop Apps Found to Contain Russian and Chinese Code
A comprehensive security audit commissioned by the Department of Defense has revealed that several popular mobile applications targeted at US military personnel contain code developed by software engineers in Russia and China. The analyzed applications, which include fitness trackers, scheduling systems, and messaging tools, present a national security risk due to potential backdoor access.
The audit discovered that developers of these applications outsourced coding modules to cheap offshore development firms. These firms integrated libraries containing hidden data-exfiltration functions, allowing servers in foreign jurisdictions to track the real-time geographic location, contacts, and communication logs of military personnel.
Tech Pulse Daily
Get tomorrow's tech pulse first
Deeply analytical tech news delivered to your inbox every morning. Free, no spam.
Identifying Supply Chain Vulnerabilities in Military Apps
In response to the audit findings, defense command structures have issued directives mandating the immediate removal of these applications from both government-issued and personal devices. The military is also establishing a centralized software verification system to audit the source code of all mobile applications before they are cleared for use by soldiers.
Implementing Strict Mobile Security and App Verification
Security experts warn that the incident highlights the difficulty of securing modern software supply chains. As codebases increasingly rely on nested third-party libraries, verifying the origin and integrity of every line of code becomes a critical defense requirement to prevent espionage targeting active-duty military units.
Key Takeaway
A defense security audit reveals mobile apps targeted at US military personnel contain vulnerable code tracing back to Russian and Chinese developers.