Researchers found Chinese and Russian SDKs in Android apps marketed to U.S. military users, highlighting software supply chain and enterprise privacy risks.
A recent examination of hundreds of mobile apps marketed toward US military personnel found more than one in eight contained software built by companies in China, Russia, or other foreign nations, raising fresh concerns that adversary governments could harvest data revealing where service members live, work, and deploy.
The largely unregulated advertising industry that tracks Americans online treats civilians and service members mostly the sameβunless there is profit in telling them apartβdespite evidence that exposure can reveal troop deployments, unit movements, and the routines of personnel within intelligence facilities and hardened shelters where nuclear weapons are believed to be stored.
One of the Russian governmentβs most elite hacking groups has adopted an attack, known as Clickfix, to compromise devices belonging to sensitive organizations in Ukraine, the latter countryβs CERT center is warning.
Clickfix has emerged as an effective attack technique that attackers, primarily financially motivated criminals, began using in the last year or so. Websites under the control of the attackers display a CAPTCHA that requires the visitor to copy a jumble of text and paste it into the terminal. The text contains scripts that, once entered, perform malicious actions, typically by installing malware or exfiltrating sensitive data. Ukraineβs CERT said Wednesday that Sandworm, an advanced hacking unit inside the GRU, Russiaβs military intelligence arm, is now using the technique.
"GhettoVibe," "ScoutCurl," and many more
The Clickfix attacks began in the spring and have continued through the summer. The campaign has resulted in the network compromise of at least one organization when a connected device was found to be infected by FreakyPoll, the name of one of Sandwormβs custom malware packages. Ukrainian authorities discovered 10 compromised websites that displayed a PowerShell command as part of a fake CAPTCHA that said it had to be passed to ensure a real human was behind the visiting deviceβs keyboard.
One week ago, three widely respected European news outlets published the results of an investigation into what they described as a "joint plan" by China and Russia to "defeat Elon Musk's Starlink."
The story was the product of a long-running inquiry by The Insider, Der Spiegel, and Le Monde. Reporters at those publications said they reviewed a cache of documents detailing growing military cooperation between China and Russia. The documents covered discussions between the nuclear powers on integrated air and missile defense systems, autonomous "swarm" loitering munitions, next-generation armored vehicles, and military aviation, the report said.
According to the papers, the investigation found evidence of a partnership between China and Russia in the field of space weapons far deeper than either country has acknowledged. One particular focus for China and Russia has been developing strategies to counter SpaceX's Starlink satellite broadband network.
Mysterious drone flights that disrupted major European airports and flew over NATO member military bases hosting US nuclear weapons may be the work of a coordinated Kremlin campaign launched from Russian-linked commercial ships.
That recent assessment from the UK-based International Institute for Strategic Studies used automatic identification system (AIS) maritime tracking data and other publicly available data to show how Russian-linked ships and βshadow fleetβ vessels that transport sanctioned Russian oil were often located nearby during various drone incidents. The report suggests that the drone incidentsβwhich impacted a dozen NATO member countries and Ireland between August 2024 and February 2026βalso revealed the vulnerability of European air defenses against surveillance and harassment incursions by low-cost drones.
The IISS report identified 144 drone sightings over Europe during that time period that were unlikely to involve hobbyist recreational drones or drone activity related to the war in Ukraine. About 48 percent of the sightings took place over military bases, 26 percent happened over critical infrastructure such as ports and energy or industrial facilities, and 18 percent occurred over civilian airports. Most occurred at night or in the early morning hours before sunrise, and the drones themselves were typically described in media reports as resembling βprofessionalβ or βmilitary-styleβ drones.