Reading view

Apps targeted at US troops contain Chinese and Russian code

A recent examination of hundreds of mobile apps marketed toward US military personnel found more than one in eight contained software built by companies in China, Russia, or other foreign nations, raising fresh concerns that adversary governments could harvest data revealing where service members live, work, and deploy.

According to researchers at Purdue University, the US Military Academy at West Point, and Florida International University, one popular app used by service members to rate living conditions on their own bases include code from Huawei, the Chinese telecom that US regulators flagged as a national security threat in 2020. Two others were built by Russian companies and incorporate the Russian ad service Yandex.

The largely unregulated advertising industry that tracks Americans online treats civilians and service members mostly the same—unless there is profit in telling them apart—despite evidence that exposure can reveal troop deployments, unit movements, and the routines of personnel within intelligence facilities and hardened shelters where nuclear weapons are believed to be stored.

Read full article

Comments

© Tomas Ragina/Getty

  •  

Now, even Russia's most elite hackers are using Clickfix to infect devices

One of the Russian government’s most elite hacking groups has adopted an attack, known as Clickfix, to compromise devices belonging to sensitive organizations in Ukraine, the latter country’s CERT center is warning.

Clickfix has emerged as an effective attack technique that attackers, primarily financially motivated criminals, began using in the last year or so. Websites under the control of the attackers display a CAPTCHA that requires the visitor to copy a jumble of text and paste it into the terminal. The text contains scripts that, once entered, perform malicious actions, typically by installing malware or exfiltrating sensitive data. Ukraine’s CERT said Wednesday that Sandworm, an advanced hacking unit inside the GRU, Russia’s military intelligence arm, is now using the technique.

"GhettoVibe," "ScoutCurl," and many more

The Clickfix attacks began in the spring and have continued through the summer. The campaign has resulted in the network compromise of at least one organization when a connected device was found to be infected by FreakyPoll, the name of one of Sandworm’s custom malware packages. Ukrainian authorities discovered 10 compromised websites that displayed a PowerShell command as part of a fake CAPTCHA that said it had to be passed to ensure a real human was behind the visiting device’s keyboard.

Read full article

Comments

© Getty Images

  •  

Could China and Russia really destroy Starlink? Only with a boomerang.

One week ago, three widely respected European news outlets published the results of an investigation into what they described as a "joint plan" by China and Russia to "defeat Elon Musk's Starlink."

The story was the product of a long-running inquiry by The Insider, Der Spiegel, and Le Monde. Reporters at those publications said they reviewed a cache of documents detailing growing military cooperation between China and Russia. The documents covered discussions between the nuclear powers on integrated air and missile defense systems, autonomous "swarm" loitering munitions, next-generation armored vehicles, and military aviation, the report said.

According to the papers, the investigation found evidence of a partnership between China and Russia in the field of space weapons far deeper than either country has acknowledged. One particular focus for China and Russia has been developing strategies to counter SpaceX's Starlink satellite broadband network.

Read full article

Comments

© SpaceX

  •  

Kremlin suspected of flying drones over Europe using Russian shadow fleet

Mysterious drone flights that disrupted major European airports and flew over NATO member military bases hosting US nuclear weapons may be the work of a coordinated Kremlin campaign launched from Russian-linked commercial ships.

That recent assessment from the UK-based International Institute for Strategic Studies used automatic identification system (AIS) maritime tracking data and other publicly available data to show how Russian-linked ships and “shadow fleet” vessels that transport sanctioned Russian oil were often located nearby during various drone incidents. The report suggests that the drone incidents—which impacted a dozen NATO member countries and Ireland between August 2024 and February 2026—also revealed the vulnerability of European air defenses against surveillance and harassment incursions by low-cost drones.

The IISS report identified 144 drone sightings over Europe during that time period that were unlikely to involve hobbyist recreational drones or drone activity related to the war in Ukraine. About 48 percent of the sightings took place over military bases, 26 percent happened over critical infrastructure such as ports and energy or industrial facilities, and 18 percent occurred over civilian airports. Most occurred at night or in the early morning hours before sunrise, and the drones themselves were typically described in media reports as resembling “professional” or “military-style” drones.

Read full article

Comments

© DAMIEN MEYER/AFP via Getty Images

  •  
❌