Researchers found Chinese and Russian SDKs in Android apps marketed to U.S. military users, highlighting software supply chain and enterprise privacy risks.
A recent examination of hundreds of mobile apps marketed toward US military personnel found more than one in eight contained software built by companies in China, Russia, or other foreign nations, raising fresh concerns that adversary governments could harvest data revealing where service members live, work, and deploy.
The largely unregulated advertising industry that tracks Americans online treats civilians and service members mostly the sameβunless there is profit in telling them apartβdespite evidence that exposure can reveal troop deployments, unit movements, and the routines of personnel within intelligence facilities and hardened shelters where nuclear weapons are believed to be stored.
One of the Russian governmentβs most elite hacking groups has adopted an attack, known as Clickfix, to compromise devices belonging to sensitive organizations in Ukraine, the latter countryβs CERT center is warning.
Clickfix has emerged as an effective attack technique that attackers, primarily financially motivated criminals, began using in the last year or so. Websites under the control of the attackers display a CAPTCHA that requires the visitor to copy a jumble of text and paste it into the terminal. The text contains scripts that, once entered, perform malicious actions, typically by installing malware or exfiltrating sensitive data. Ukraineβs CERT said Wednesday that Sandworm, an advanced hacking unit inside the GRU, Russiaβs military intelligence arm, is now using the technique.
"GhettoVibe," "ScoutCurl," and many more
The Clickfix attacks began in the spring and have continued through the summer. The campaign has resulted in the network compromise of at least one organization when a connected device was found to be infected by FreakyPoll, the name of one of Sandwormβs custom malware packages. Ukrainian authorities discovered 10 compromised websites that displayed a PowerShell command as part of a fake CAPTCHA that said it had to be passed to ensure a real human was behind the visiting deviceβs keyboard.
One week ago, three widely respected European news outlets published the results of an investigation into what they described as a "joint plan" by China and Russia to "defeat Elon Musk's Starlink."
The story was the product of a long-running inquiry by The Insider, Der Spiegel, and Le Monde. Reporters at those publications said they reviewed a cache of documents detailing growing military cooperation between China and Russia. The documents covered discussions between the nuclear powers on integrated air and missile defense systems, autonomous "swarm" loitering munitions, next-generation armored vehicles, and military aviation, the report said.
According to the papers, the investigation found evidence of a partnership between China and Russia in the field of space weapons far deeper than either country has acknowledged. One particular focus for China and Russia has been developing strategies to counter SpaceX's Starlink satellite broadband network.