Full Breakdown
China-Linked Malware Spread via Counterfeit USB Sticks in Japan’s Ground Self-Defense Force
6/26/2026, 1:39:57 AM
Core Incident Overview
In March 2024, counterfeit USB flash drives delivered to Japan’s Ground Self-Defense Force (GSDF) during disaster-relief after a central-Japan earthquake introduced a China-linked virus into the ministry’s closed, classified network. The infection remained undetected for nearly a year, was identified in February 2025 when a soldier in Itami, near Osaka, reported a slow computer. Scanning confirmed malware that activates on insertion.
Background and Context
Japan’s Defense Ministry uses both open and isolated IT systems, with a closed network for classified data. Portable storage devices are allowed for external data transfer. In 2024, U.S. intelligence warned that China-linked hackers were embedding malware in allied systems via “pre-positioning,” a method different from traditional cyber-espionage.
Timeline of Events
- March 2024: Eight counterfeit USB sticks made in China and sold cheaper than originals were given to GSDF units for disaster-relief data exchange.
- February 2025: A GSDF soldier in Itami reported a slow computer; a scan showed infection by the China-linked virus.
- Post-detection: Investigation found six of eight drives infected and over 50 computers had used them, about half handling classified data.
Data and Statistics
Official Statements and Responses
Japan’s Defense Ministry has not commented. U.S. intelligence agencies warned of “pre-positioning” by China-linked actors. The Chinese government says it does not conduct cyberattacks against the United States and accuses U.S.-linked actors of hacking Chinese systems.
Criticism and Opposition
The GSDF’s failure to disclose the breach, despite safeguards requiring external media scanning, drew criticism. The infection occurred even though protocols mandated drive inspection on receipt and during use. Use of cheap counterfeit hardware, widely sold online, raises supply-chain security concerns.
On-the-Ground Report
An unnamed GSDF soldier in Itami reported abnormal computer performance, prompting a scan that uncovered the malware.
Why It Matters
If activated in a crisis, the malware could disable communications, transportation, water and power systems, delaying government response in wartime. The incident also shows the risk of unauthorized data exfiltration and espionage, as nearly half of the affected computers stored classified unit-movement data.
