Japan’s Ground Self-Defense Force reportedly connected counterfeit USB flash drives carrying malware to computers on sensitive military networks, exposing more than 50 systems, including machines handling classified troop movement information. Leaked internal documents cited by Nikkei say the compromised drives entered use during earthquake relief operations in central Japan in March 2024, bypassed normal procurement controls, and remained in circulation until the malware was discovered in February 2025 after abnormal system behavior at Middle Army headquarters in Itami.
Investigators reportedly found the same malicious code on six of eight tested drives, and the malware was linked in internal reporting to a strain previously associated by a U.S. cybersecurity firm with a China-backed hacking group. Japan’s Defense Ministry publicly confirmed only that a USB drive obtained by Middle Army headquarters contained malware, while saying the code was an older self-replicating type that did not exfiltrate data or communicate externally. The incident has raised wider supply-chain concerns because similar counterfeit infected drives were reportedly sold online and had also reached factories and research institutions across Japan.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
Subsequent investigation found the same malicious code on six of eight tested drives and determined that the infected media had been connected to more than 50 computers, including systems handling classified troop movement information. The malware was described as an older self-replicating type, and leaked documents said it matched a strain previously linked by a U.S. cybersecurity firm to a China-backed hacking group.
Nikkei reported that the compromise had lasted from March 2024 until its discovery in February 2025 and that the JGSDF kept the matter internal rather than broadly disclosing it. The report also said similarly infected counterfeit USB drives were being sold online and had spread to factories and research institutions across Japan.
In February 2025, abnormal system performance at JGSDF Middle Army headquarters in Itami led to the discovery of malware on a USB drive acquired by the force. The GSDF publicly confirmed only that a malware-infected USB drive was found at the headquarters that month.
Leaked internal documents indicate counterfeit USB flash drives were brought into use by Japan's Ground Self-Defense Force during earthquake disaster relief operations in central Japan, bypassing normal procurement controls. These drives were later reported to have been manufactured in China and infected with malware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcebitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.