Japan's Ground Self-Defense Force (JGSDF) unknowingly used malware-infected USB drives on classified military networks for almost a year, according to Nikkei's investigation of leaked internal documents. The counterfeit drives, manufactured in China, were distributed during earthquake relief operations in March 2024. The malware ran the instant a drive was plugged in, then sat quietly in the background.
By the time a soldier in Itami noticed his computer slowing down in February 2025, over 50 machines had connected to the infected drives — nearly half of them handling classified troop movement data. The malware matches a strain linked to a China-backed hacking group.
The JGSDF never disclosed the breach publicly, even as identical drives spread to Japanese factories and research institutions.
Source: Cybersecurity News