惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Proofpoint News Feed
云风的 BLOG
云风的 BLOG
Apple Machine Learning Research
Apple Machine Learning Research
Hugging Face - Blog
Hugging Face - Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Google DeepMind News
Google DeepMind News
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
雷峰网
雷峰网
B
Blog
月光博客
月光博客
博客园 - 【当耐特】
WordPress大学
WordPress大学
Microsoft Azure Blog
Microsoft Azure Blog
I
InfoQ
The GitHub Blog
The GitHub Blog
Engineering at Meta
Engineering at Meta
Jina AI
Jina AI
博客园 - Franky
MyScale Blog
MyScale Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Last Week in AI
Last Week in AI
B
Blog RSS Feed
H
Help Net Security

Consumer Insights

The ransomware negotiator who was working for the other side After years on the run, alleged Ryuk ransomware operator pleads guilty INTERPOL crackdown shows scammers shifting to social media Meta lets strangers remix your public Instagram photos with AI—here’s how to opt out Invited to a "job interview" with Netflix or OpenAI? Beware! Your Google password could be at risk Two arrested over credit card phishing - as the Netherlands is named Europe's worst for payment fraud India pauses WhatsApp username feature over security concerns Alleged teen ransomware hustler faces US charges after arrest in Finland WhatsApp usernames explained: how to reserve yours and stay safe Scammers race to cash in on Venezuelan earthquake disaster WhatsApp tests new safety prompt before you chat with strangers Social media is worth celebrating. It's also worth protecting. Polish police dismantle SIM-swap gang accused of crypto theft Operation Endgame deals fresh blow to StealC and Amadey malware networks Hacker hijacks Brazil's national alert system, sending "misanthropy" to millions of phones Cybercrime now rivals traditional crime across parts of Asia Apple's Hide My Email tweak leaves privacy fans fuming Americans lost $3.5 billion to imposter scams last year — and the scams are getting harder to spot Scammers have killed the physical Steam Gift cards Crypto investment scam sends couriers to collect victims' cash, FBI warns Maine forced to take down data breach portal after fake notices filed with authorities Privacy own-goal: World Cup blunder leaks Lionel Messi's passport details Why schools remain one of cybercriminals' favourite targets WhatsApp detects new spyware activity from Israel’s NSO Group despite court order Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 Europol cracks down on illegal streaming globally Hackers didn't hack Instagram; they just asked Meta AI FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup Virtual knife, real lawsuit: Counter-Strike skin dispute ends in court As Deepfakes Spread, YouTube Makes AI Labels Harder to Miss
USB drives carrying China-linked malware infected Japanes...
Graham CLULEY · 2026-06-30 · via Consumer Insights

Leaked internal documents have revealed that for nearly a year Japan's Ground Self-Defense Force (JGSDF) used counterfeit USB flash drives infected with malware on computers connected to sensitive military networks. The USB drives have been linked to Chinese hacking operations, according to an investigation by Nikkei Asia.

Nikkei Asia reports that the poisoned flash drives were delivered to the JGSDF in March 2024, during disaster relief operations following an earthquake in central Japan. Via this route they were able to enter military use without having passed through standard procurement channels.

The malware was discovered in February 2025, after personnel at JGSDF's Middle Army headquarters in Itami, near Osaka, noticed a computer running unusually slowly. Subsequent investigations found that six out of eight USB drives tested contained the same malicious code.

The infected USB drives had been attached to over 50 computers, with nearly half of those systems used to handle classified data, including information about the movement of troops.

Investigators matched the malware to a strain previously documented by an unnamed US cybersecurity firm, which had linked it to a Chinese hacking group. Neither the malware family nor the hacking group has been publicly named in reports.

Japan's Defense Ministry has downplayed the threat, with a spokesperson saying:

"The malware was a legacy type one limited to self-replication behaviour and did not perform information exfiltration or external communication."

Adding to the confusion, the Epoch Times reports that a spokesperson for the Ishikawa Prefectural Government - which had been alleged in the leaked internal documents to have provided the USB drives to the JGSDF during the 2024 earthquake relief effort - said that "we could not confirm any record of procuring the USB drives or paying for their purchase."

With neither the prefecture nor the military able to produce a paper trail, the origin of the counterfeit drives remains a mystery, raising further questions about how easily compromised hardware can slip into sensitive environments when normal processes are bypassed during an emergency.

Nikkei Asia says that the threat posed by the infected drives extends beyond the JGSDF. USB flash drives preloaded with the same malware have been sold across major online retail platforms, and infections have been seen at factories and research facilities across multiple industries in Japan. The counterfeit drives, priced 30 to 50 percent below authentic brands, were traced to seller accounts in China.

According to Nikkei Asia, the JGSDF did not disclose the infection within its network, despite the counterfeit drives remaining widely available for purchase online. The Defense Ministry says it is continuing to investigate the circumstances surrounding acquisition of the drives and intends to enforce mandatory virus-scanning safeguards.

Regular readers of Hot for Security will be well aware of the threat posed by pre-infected USB drives, where malware can hide until a user inserts it into their computer.

Clearly organisations need to check that they are only buying storage devices from verified and trusted vendors, and treat products selling for a suspiciously low price with caution.

Furthermore, it would be wise to scan removable media on a dedicated isolated system prior to connecting it to any corporate network. In addition, computers should have any autorun or autoplay functionality disabled to prevent malicious code on a USB drive from being automatically activated upon attachment.