IC Technology & Cyber — 2026-06-28
Japan Ground Self-Defense Force Used China-Linked Malware USB Drives on Classified Networks for Nearly a Year
BLUFEleven months of undetected access to classified command networks makes Japan's "no exfiltration" claim analytically unsustainable, yet public acknowledgment of data loss by year-end 2026 remains very unlikely absent compelled disclosure.
A Nikkei Asia investigation published June 25 found that JGSDF received counterfeit USB drives infected with China-linked malware during earthquake relief in March 2024, connected them to classified networks, and did not detect the breach until February 2025 1. Internal review identified malware on six of eight examined drives; over 50 of roughly 480 inspected computers had connected to a compromised device, with nearly half on isolated networks carrying classified unit-movement data 234. The malware executed automatically on insertion, original procurement remains unverifiable, antivirus scans had been bypassed for undetermined reasons, and the strain matched one previously documented by a US cybersecurity firm as used by a China-linked hacking group 12. Japan's Defense Ministry told Newsweek the strain was a "legacy type" with no confirmed exfiltration; JGSDF did not publicly disclose the incident despite Nikkei reporting the same counterfeit drives had already infected computers at Japanese factories and research institutions, leaving civilian targets without warning 13.
AnalysisThe Ministry's "no exfiltration" claim is analytically unsustainable without independent forensic access: eleven months of
dwell time on isolated command networks and an unexplained antivirus exclusion are inconsistent with that posture. Attribution to
Mustang Panda, whose documented pattern favors quiet persistence over noisy exfiltration, is consistent with data having been staged without generating observable network anomalies. The pre-positioning pattern is equally consistent with dormant destructive exposure targeting C2 networks in a future crisis rather than an intelligence collection operation. Public confirmation of exfiltration by year-end 2026 is
very unlikely. Analytic confidence is low: no independent technical audit has been published and the Ministry retains full forensic access. If exfiltration is confirmed, allied defense partners must audit what classified unit-movement data shared with JGSDF since March 2024 may be compromised.
5 sources
- Japan defense forces used USB drives with China-linked virus: Nikkei investigation - Nikkei Asia
- Japan Defense Forces Used China-Linked Malware USB Drives on Classified Systems - Cyber Security News
- Fake USB Sticks Spread China-Linked Virus in Japan's Army - Newsweek
- Malware-Laced USBs Breach Japanese Military Networks - GovInfoSecurity
- China-Linked Malware Found in Counterfeit USB Drives Used on Japan Defense Force Classified Networks - GBHackers
View in full brief →