Japan Ground Self-Defense Force Used Malware-Infected USB Drives on Sensitive Systems


Japan’s Ground Self-Defense Force used counterfeit USB flash drives infected with China-linked malware on computers connected to sensitive military networks for nearly a year, according to a Nikkei investigation.

The malware was discovered in February 2025 after a computer at the JGSDF Middle Army headquarters in Itami, near Osaka, began running slowly. A wider internal review found that multiple infected USB drives had already been connected to dozens of systems.

The incident highlights a basic but serious cybersecurity risk: low-cost removable hardware can become an entry point into high-security environments when procurement checks, scanning rules, and device controls fail.

How the USB Malware Reached Military Systems

The infected drives were reportedly counterfeit products made in China and sold as high-capacity USB storage devices. Investigators found that some devices advertised 1TB of storage but actually used cheaper microSD cards with far less usable capacity.

According to CyberInsider, internal records cited by Nikkei said the regional headquarters received eight USB drives during disaster relief operations after the January 2024 Noto Peninsula earthquake. The drives were transferred from Ishikawa Prefecture in March 2024.

Six of the eight drives were reportedly found to contain the same malware. Investigators could not determine exactly how the devices were originally procured, which points to a supply chain and procurement control gap.

DetailReported Information
Organization affectedJapan Ground Self-Defense Force
Discovery dateFebruary 2025
LocationMiddle Army headquarters in Itami, near Osaka
Initial clueA computer started running unusually slowly
Devices examinedEight USB drives
Infected drivesSix drives reportedly carried the same malware

More Than 50 Computers Were Connected to the Drives

The internal review reportedly examined about 480 computers. More than 50 had been connected to one of the infected USB drives at some point.

Nearly half of those affected systems were reportedly tied to isolated networks used for highly sensitive information, including command-and-control data. That does not mean the malware successfully stole classified data, but it shows how close the incident came to Japan’s most sensitive military environments.

The Defense Post reported that the Self-Defense Forces said they found no evidence of system compromise or leakage of sensitive information. The SDF also said antivirus screening procedures have since been strengthened.

The Malware Was Linked to Chinese Threat Activity

The malware found on the counterfeit drives matched a strain that a U.S. cybersecurity company had previously linked to a Chinese hacking group, according to reporting based on the Nikkei findings.

The malware reportedly ran automatically when an infected USB drive was inserted into a computer. That behavior would make the attack more dangerous in environments where users may assume a removable drive is safe after routine procurement or antivirus checks.

The case shows why USB malware remains a practical threat, especially in segmented or closed networks. Attackers may use infected removable media when direct internet-based intrusion is harder.

  • The drives were reportedly counterfeit and falsely advertised higher storage capacity.
  • The malware could execute when the USB drive was connected.
  • Multiple screening procedures failed to stop the infected devices.
  • The malware remained undetected for almost a year.
  • The affected systems included computers linked to sensitive networks.

Why the Incident Was Not Publicly Disclosed Earlier

The JGSDF reportedly kept the incident internal after the malware was found. That decision drew concern because similar counterfeit drives were still available through online marketplaces.

The risk was not limited to military users. The Edge Malaysia, citing Nikkei Asia, reported that fake USB sticks loaded with China-linked malware had also reached computers at factories and research facilities in different industries.

Nikkei also examined low-rated reviews for top USB products listed on Amazon Japan and Amazon U.S. The review found complaints that suggested similar counterfeit storage problems had appeared in both markets, with more complaints emerging since 2024.

What Failed Inside the Security Process

The incident appears to involve several failures rather than a single mistake. The drives entered a sensitive environment, passed through or avoided expected checks, and remained in use long enough to touch more than 50 systems.

Reports said the JGSDF had procedures for scanning USB devices during procurement and use. However, the compromised drives were reportedly excluded from some endpoint security scans for reasons investigators could not fully explain.

That gap matters because removable media controls depend on consistency. A policy that exists on paper cannot protect sensitive systems if field processes, procurement workflows, and endpoint tools do not enforce it every time.

Security LayerReported WeaknessRisk Created
ProcurementCounterfeit USB drives entered useUntrusted hardware reached military systems
Device scanningSome checks failed or did not run as expectedMalware remained active for months
Network separationDrives reached computers tied to sensitive networksPotential exposure of classified environments
DisclosureThe broader risk was not publicly warned about earlierOther buyers may have remained unaware of infected devices

Counterfeit USB Drives Are a Wider Supply Chain Risk

The military incident fits a broader pattern of counterfeit storage devices being sold online. These products often advertise unrealistic storage capacity at unusually low prices.

In some cases, counterfeit drives report fake capacity to the operating system while using much smaller internal storage. In more serious cases, as this incident shows, the device can arrive with malicious files already present.

The Nikkei investigation raises a larger question for defense agencies and private companies: whether their hardware purchasing rules can detect cheap, fake, and tampered devices before they reach operational networks.

How Organizations Should Respond

Organizations should stop treating removable media as low-risk office supplies. USB drives used in sensitive environments should come only from approved vendors, with documented procurement paths and device inventories.

Security teams should also scan and validate removable media on isolated systems before use. The drive should never move directly from a package or external source to a production, research, or classified environment.

CyberInsider also noted that buyers should avoid unusually cheap products from unknown sellers and validate storage capacity before deployment. Those steps can help detect counterfeit devices before they create a larger compromise.

  • Buy storage devices only from verified vendors and approved procurement channels.
  • Block unapproved USB storage on sensitive systems by default.
  • Scan removable media on isolated machines before operational use.
  • Validate advertised storage capacity before deployment.
  • Log every connection between removable media and sensitive systems.
  • Remove USB exceptions that bypass endpoint protection scans.

Why This Matters Beyond Japan’s Military

The incident shows how old attack methods can still bypass modern security when they exploit trust in physical hardware. A fake USB drive does not need to break through a firewall if someone connects it inside the network.

Factories, research labs, government offices, and defense contractors face the same type of risk. Many still use removable media to move files between isolated systems, test equipment, legacy machines, and secure networks.

The Defense Post report said several control systems stopped functioning as a result of the incident, although the SDF found no evidence of sensitive data leakage. That detail shows why even non-leak incidents can disrupt operations and trigger costly investigations.

What Buyers Should Watch For

Consumers and organizations should be cautious with USB drives that look too cheap for their advertised capacity. Very low prices, unknown sellers, unusual packaging, fake branding, and inconsistent storage behavior can all point to counterfeit hardware.

Businesses should also treat online marketplace reviews as a warning signal. Reports of files that cannot be deleted, strange drive behavior, unexpected executables, and fake capacity should trigger immediate rejection of the product.

The Edge Malaysia reported that Nikkei found similar complaints in Japan and the U.S. marketplace review data. That suggests the problem extends beyond one military incident and remains relevant to everyday buyers.

FAQ

What happened to Japan’s Ground Self-Defense Force?

Japan’s Ground Self-Defense Force reportedly used counterfeit USB drives infected with China-linked malware on computers connected to sensitive military networks for nearly a year before the malware was discovered in February 2025.

How were the infected USB drives discovered?

The malware was discovered after a computer at the JGSDF Middle Army headquarters in Itami, near Osaka, began running unusually slowly. A scan then found malware linked to a recently inserted USB drive.

Did the malware steal classified information?

The Self-Defense Forces said they found no evidence of system compromise or leakage of sensitive information. However, more than 50 computers had reportedly been connected to the infected drives, and some were tied to sensitive networks.

Why are counterfeit USB drives dangerous?

Counterfeit USB drives may advertise fake storage capacity, use low-quality parts, or arrive with malicious files already present. If connected to sensitive systems, they can bypass network defenses and introduce malware directly.

How can organizations prevent USB malware incidents?

Organizations should buy removable storage only from approved vendors, block unapproved USB devices, scan media on isolated systems, validate storage capacity, and log every removable media connection to sensitive computers.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages