Apps targeted at US troops contain Chinese and Russian code
Summary
A significant portion of applications found on app stores, particularly those potentially used by US military personnel, contain code from Chinese and Russian sources. Over 12% of apps analyzed were found to have this foreign code, raising concerns about potential security risks and data exfiltration.
IFF Assessment
The presence of foreign code in applications used by military personnel poses a risk of espionage, data compromise, and potential control by adversarial nations.
Defender Context
Defenders need to be aware of the potential for embedded malicious code or backdoors in applications, especially those used in sensitive environments. This highlights the importance of robust application vetting and supply chain security measures for critical infrastructure and personnel.