Japan Defense Forces Used China-Linked Malware USB Drives on Classified Systems

Japan’s Ground Self-Defense Force (JGSDF) used counterfeit USB drives infected with China-linked malware on computers connected to sensitive military networks for nearly a year and then chose not to publicly disclose the incident, a Nikkei investigation has revealed.

The breach came to light in February 2025 after personnel at the JGSDF’s Middle Army headquarters in Itami, near Osaka, noticed a computer behaving abnormally.

A forensic examination of a recently inserted USB drive confirmed the presence of malware, triggering a wider internal review of all removable media used across the organization.

Japan Defense Forces Used China-Linked Malware USB Drives

Investigators ultimately identified six of eight infected USB drives that had been introduced into the military environment, raising immediate concerns about the integrity of connected systems.

According to leaked internal documents cited by Nikkei, the regional headquarters received the eight USB drives during disaster relief operations following the January 2024 Noto Peninsula earthquake.

The drives were transferred from Ishikawa Prefecture in March 2024, though investigators were reportedly unable to determine how they had been originally procured.

This gap in the chain of custody is a serious supply chain security failure. The origin of a device directly connected to classified military infrastructure remains entirely unknown.

Of approximately 480 computers examined during the internal investigation, more than 50 had at some point been connected to one of the six compromised devices.

Nearly half of those systems were reportedly linked to isolated networks handling highly classified information, including unit command-and-control data.

The malware was confirmed to execute automatically upon USB insertion, meaning no deliberate user action was required to trigger the initial compromise. The USB drives were identified as counterfeit products manufactured in China.

Rather than using standard flash memory chips, they used inexpensive microSD cards for internal storage and falsely advertised a capacity of 1 TB while delivering only approximately 240 GB of usable space, a known hallmark of fraudulent storage devices commonly sold through online marketplaces.

Notably, the compromised drives had been excluded from endpoint antivirus scans for reasons investigators could not determine, allowing the malware to evade detection for nearly a year despite JGSDF policy mandating USB scans during both procurement and active use.

The malware matched a strain previously documented by a U.S. cybersecurity firm as associated with a China-linked hacking group.

Despite this attribution and awareness that identical counterfeit drives remained available for purchase online, the JGSDF issued only a minimal public statement confirming that “a USB drive acquired by the JGSDF Middle Army headquarters was found to contain malware,” widely regarded as an insufficient response given the true scale of the exposure.

The deliberate suppression of broader disclosure denied allied defense partners and the public the information needed to assess and contain residual risk across the region.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories