Drooid Logo
Back to story perspectives

Full Breakdown

China-Linked Malware Spread via Counterfeit USB Sticks in Japan’s Ground Self-Defense Force

6/26/2026, 1:39:57 AM

Core Incident Overview

In March 2024, counterfeit USB flash drives delivered to Japan’s Ground Self-Defense Force (GSDF) during disaster-relief after a central-Japan earthquake introduced a China-linked virus into the ministry’s closed, classified network. The infection remained undetected for nearly a year, was identified in February 2025 when a soldier in Itami, near Osaka, reported a slow computer. Scanning confirmed malware that activates on insertion.

Background and Context

Japan’s Defense Ministry uses both open and isolated IT systems, with a closed network for classified data. Portable storage devices are allowed for external data transfer. In 2024, U.S. intelligence warned that China-linked hackers were embedding malware in allied systems via “pre-positioning,” a method different from traditional cyber-espionage.

Timeline of Events

  • March 2024: Eight counterfeit USB sticks made in China and sold cheaper than originals were given to GSDF units for disaster-relief data exchange.
  • February 2025: A GSDF soldier in Itami reported a slow computer; a scan showed infection by the China-linked virus.
  • Post-detection: Investigation found six of eight drives infected and over 50 computers had used them, about half handling classified data.

Data and Statistics

  • USB sticks delivered: 8; infected: 6.
  • Computers linked to infected drives: >50, about half handling classified data.
  • Counterfeit drives: made in China, widely available online.

Official Statements and Responses

Japan’s Defense Ministry has not commented. U.S. intelligence agencies warned of “pre-positioning” by China-linked actors. The Chinese government says it does not conduct cyberattacks against the United States and accuses U.S.-linked actors of hacking Chinese systems.

Criticism and Opposition

The GSDF’s failure to disclose the breach, despite safeguards requiring external media scanning, drew criticism. The infection occurred even though protocols mandated drive inspection on receipt and during use. Use of cheap counterfeit hardware, widely sold online, raises supply-chain security concerns.

On-the-Ground Report

An unnamed GSDF soldier in Itami reported abnormal computer performance, prompting a scan that uncovered the malware.

Why It Matters

If activated in a crisis, the malware could disable communications, transportation, water and power systems, delaying government response in wartime. The incident also shows the risk of unauthorized data exfiltration and espionage, as nearly half of the affected computers stored classified unit-movement data.

Conflicting Reports and Gaps

  • Japan’s Defense Ministry has not responded.
  • The brand of the counterfeit USB sticks is unnamed.
  • Exact numbers of compromised classified computers are undisclosed; only “nearly half” of the >50 connected machines are said to have handled classified data.