For nearly a year, Japan’s Ground Self-Defense Force (JGSDF) operated computers connected to sensitive military networks while using counterfeit USB flash drives preloaded with malware that investigators have now linked to Chinese hacking operations. The breach, uncovered through leaked internal documents and investigated by Nikkei Asia, reveals how easily compromised hardware can bypass standard security controls when normal procurement procedures are suspended during emergencies.
How Infected USB Drives Reached the Japanese Military
The poisoned flash drives were delivered to the JGSDF in March 2024 during disaster relief operations following a major earthquake in central Japan. Because the drives entered through emergency supply channels rather than standard military procurement, they were never subjected to the usual security screening and verification processes. Internal documents indicate that six out of eight USB drives tested after the discovery contained identical malicious code.
The malware was first detected in February 2025 when personnel at JGSDF’s Middle Army headquarters in Itami, near Osaka, noticed a computer running unusually slowly. A subsequent investigation revealed that the infected USB drives had been connected to more than 50 computers, with nearly half of those systems used to handle classified data — including information related to troop movements.
Malware Traced to Chinese Hacking Operations
Investigators matched the strain of malware to code previously documented by a US cybersecurity firm, which had attributed it to a Chinese hacking group. Neither the specific malware family nor the hacking group has been publicly identified in the reports, but the attribution comes from a private-sector threat intelligence source that has tracked the group’s activities across multiple campaigns.
Japan’s Defense Ministry has sought to downplay the severity of the infection, stating that the malware was a legacy type limited to self-replication behavior and did not perform information exfiltration or external communication. However, the presence of any active malware on systems handling classified military data raises serious questions about operational security and the adequacy of current defenses.
Unanswered Questions About the Origin of the Drives
The chain of custody for the counterfeit drives remains unclear. A spokesperson for the Ishikawa Prefectural Government — which was alleged in the leaked documents to have provided the USB drives during the 2024 earthquake relief effort — stated that no record of procuring or paying for such drives could be confirmed. Neither the prefecture nor the military has been able to produce a paper trail, leaving the origin of the compromised hardware a mystery.
This gap in documentation highlights a critical vulnerability: during emergencies, when speed takes priority over process, counterfeit or tampered equipment can enter sensitive environments without leaving any auditable trace.
Broader Availability and Ongoing Risk
The threat extends well beyond the JGSDF. Nikkei Asia reports that USB flash drives preloaded with the same malware have been sold across major online retail platforms at prices 30 to 50 percent below authentic brands. Infections have been detected at factories and research facilities across multiple industries in Japan, and the seller accounts were traced to China.
Despite the discovery, the JGSDF did not disclose the infection within its network, and the counterfeit drives remain widely available for purchase online. The Defense Ministry says it is continuing to investigate how the drives were acquired and intends to enforce mandatory virus-scanning safeguards going forward.
What Organizations Should Do Now to Mitigate USB-Based Threats
Any organization that relies on removable media — and most do, at some point — should treat this incident as a warning to review their policies immediately. The risk of pre-infected USB drives is well documented. Malware can remain dormant on a drive until the moment a user plugs it into a system, at which point it can execute without any user action if autorun or autoplay features are enabled.
The first step is to ensure that all removable media is sourced exclusively from verified and trusted vendors. Products selling at suspiciously low prices should be treated with extreme caution. Before any USB drive is connected to a corporate network, it should be scanned on a dedicated, isolated system that has no access to sensitive data. Disabling autorun and autoplay functionality across all endpoints is a basic but essential control that prevents malicious code from executing automatically upon attachment.
Beyond these immediate measures, organizations should consider deploying a multi-layer endpoint protection solution that includes behavioral analysis and real-time threat detection. No single tool can guarantee safety against every threat, but layered defenses significantly reduce the chance that a single compromised USB drive can lead to a network-wide infection. Regular security awareness training for all personnel — especially those involved in procurement and emergency operations — should emphasize the risks of relying on unverified hardware, even when speed is critical.