# Counterfeit China-Made USB Drives with Self-Replicating Malware Infect 50+ Japan Ground Self-Defense Force Computers (Nikkei Investigation)

> A Nikkei investigation revealed that counterfeit, China-manufactured USB flash drives distributed to Japan's Ground Self-Defense Force (JGSDF) Middle Army during March 2024 Noto Peninsula earthquake relief operations carried self-replicating malware matching a strain previously documented by a U.S. cybersecurity firm as linked to Chinese hacking activity. The malware auto-executed via AutoRun on insertion, evaded endpoint antivirus scanning, and went undetected for roughly 11 months until a soldier in Itami reported degraded system performance in February 2025, by which point 50+ computers were infected, nearly half connected to isolated networks handling classified troop-movement data.

- **Published:** 2026-07-11T00:00:00Z
- **Last reviewed:** 2026-07-11T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1240
- **ID:** TL-2026-1240
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)

## Description

In January 2024, following the Noto Peninsula earthquake, eight USB flash drives were acquired by disaster-relief personnel in Ishikawa Prefecture and transferred in March 2024 to JGSDF Middle Army headquarters in Itami, near Osaka. The drives were counterfeit products manufactured in China: they were marketed as 1TB flash-memory devices but were physically built around lower-cost, slower MicroSD cards yielding only approximately 240GB of genuine usable storage, with the remainder falsely reported to the host OS — a hallmark of cheap counterfeit flash-storage fraud. Malicious code had been embedded into the drives during production or a subsequent supply-chain touchpoint before they reached end users; six of the eight drives, when later forensically examined, were found to contain malware.

The malware auto-executed when a drive was inserted into a Windows host (consistent with AutoRun/AutoPlay-triggered execution, MITRE ATT&CK T1547.014 combined with T1091 Replication Through Removable Media), then self-replicated onto other removable media and connected hosts without requiring further user interaction. It was engineered to evade the endpoint antivirus/security-scanning tools in use across JGSDF systems, allowing it to persist undetected for roughly 11 months. A U.S. cybersecurity company that analyzed a sample assessed that the code matched a malware strain previously associated with Chinese state-linked hacking operations, though neither the specific malware family nor the specific threat-actor group was named in reporting, and JGSDF/Japan's Ministry of Defense has not made a fuller public attribution.

Discovery occurred in February 2025 when a JGSDF soldier in Itami noticed his computer had become unusually slow and reported it; a subsequent scan identified the infection. JGSDF's internal review reportedly found the malware present on 50+ of roughly 480 examined computers, with close to half of the infected machines connected to physically isolated ('closed') networks used for classified command-and-control functions, including data related to troop movements. Japan's Ministry of Defense characterized the malware as a 'legacy type' limited to self-replication behavior, stating it did not perform information exfiltration or establish external command-and-control communications — a claim that, if accurate, would limit this incident's confirmed impact to availability/persistence risk on classified networks rather than confirmed data theft, though the counterfeit hardware's undocumented provenance and 11-month dwell time leave residual uncertainty about undetected capabilities.

The supply-chain exposure extends beyond the military: reporting confirmed that visually similar counterfeit USB drives, sold at 30-50% below the price of authentic branded products through major online retail platforms, remained widely available for purchase after the JGSDF incident was discovered, and that factories and research institutions operating physically isolated ('closed') networks in Japan separately reported similar infections from drives obtained through the same online counterfeit-hardware ecosystem. Neither Ishikawa Prefecture nor JGSDF could produce documentation tracing the acquisition chain of the original eight drives, and no brand name was publicly disclosed for the counterfeit product. Japan's Ministry of Defense committed to investigating the acquisition circumstances and to enforcing mandatory virus-scanning procedures for any removable media introduced to JGSDF systems going forward.

This incident sits within a well-documented pattern of China-linked APT USB-worm tradecraft. Check Point's technical analysis of the closely analogous 'Camaro Dragon' toolkit (tracked elsewhere as Mustang Panda / LuminousMoth) documents the reference architecture for this class of attack: a USB launcher component ('HopperTick') and a unified infector/backdoor payload ('WispRider') that detects new drives via WM_DEVICECHANGE, deploys itself alongside decoy/legitimate files, deletes revealing extensions (.exe/.lnk/.scr/.com/.vbs/.hta) from the infected volume, and establishes host persistence via both an HKCU Run-key entry pointing at a legitimate side-loading target and a scheduled task invoking a sideloaded DLL with a hardcoded anti-sandbox argument. WispRider communicates over raw sockets with per-request XOR-keyed traffic to an embedded IPv4:port or a fallback DNS name, and a companion 'Disk Monitor' component stages and HTTPS-exfiltrates targeted document/media file types. IBM X-Force and Security Affairs separately document the same actor cluster (tracked as Hive0154/Mustang Panda) iterating this tradecraft into a newer 'SnakeDisk' USB worm alongside an updated 'Toneshell' backdoor as of early 2025. Publicly tracked clusters in this pattern — Mustang Panda / Camaro Dragon / TEMP.Hex / Earth Preta — have repeatedly used self-propagating USB malware (SOGU, SnowyDrive, WispRider, SnakeDisk) to bridge air-gapped and physically isolated networks, a TTP class directly analogous to what is described in the JGSDF incident. These are documented as comparative reference tradecraft for the broader China-linked USB-worm threat class; no public reporting to date has formally attributed the JGSDF incident itself to Mustang Panda, Camaro Dragon, or any other specific named group, the unnamed U.S. analysis firm did not disclose a family match, and this threat record documents the JGSDF incident as reported rather than asserting shared authorship or shared code with the Camaro Dragon/SnakeDisk toolset.

## MITRE ATT&CK

- T1091 Replication Through Removable Media
- T1195 Supply Chain Compromise
- T1195.003 Compromise Hardware Supply Chain
- T1204.003 Malicious Image
- T1204.002 Malicious File
- T1569 System Services
- T1547.014 Active Setup
- T1547.001 Registry Run Keys / Startup Folder
- T1053.005 Scheduled Task
- T1564 Hide Artifacts
- T1685 Disable or Modify Tools
- T1036 Masquerading
- T1036.005 Match Legitimate Resource Name or Location
- T1574.001 DLL
- T1120 Peripheral Device Discovery
- T1091 Replication Through Removable Media
- T1025 Data from Removable Media
- T1119 Automated Collection
- T1074.001 Local Data Staging
- T1071.001 Web Protocols
- T1095 Non-Application Layer Protocol
- T1565 Data Manipulation

## Sources

- [Nikkei Warns of Japan's Ground Self-Defense Force Used USB Drives Infected with a China-linked Malware](https://cybersecuritynews.com/nikkei-warns-of-japans-ground-self-defense-force-used-usb-drives/)
- [Japan defense forces used USB drives with China-linked virus: Nikkei investigation](https://asia.nikkei.com/spotlight/cybersecurity/japan-defense-forces-used-usb-drives-with-china-linked-virus-nikkei-investigation)
- [Japan's army used USB drives with Chinese malware for a year](https://cyberinsider.com/japans-army-used-usb-drives-with-chinese-malware-for-a-year/)
- [Fake USB Sticks Spread China-Linked Virus in Japan's Army](https://www.newsweek.com/fake-usb-sticks-spread-china-linked-virus-japan-army-12120117)
- [USB drives carrying China-linked malware infected Japanese military networks for nearly a year](https://www.bitdefender.com/en-us/blog/hotforsecurity/usb-drives-carrying-china-linked-malware-infected-japanese-military-networks-for-nearly-a-year)
- ['Counterfeit' Chinese USB Drives Infiltrate Japan Self-Defense Force Systems](https://www.visiontimes.com/2026/06/25/counterfeit-chinese-usb-drives-infiltrate-japan-self-defense-force-systems.html)
- [Japanese Military Used USB Drives With China-Linked Virus: Report](https://www.theepochtimes.com/china/japanese-military-used-usb-drives-with-china-linked-virus-report-6054017)
- [China-Linked Malware Found on Counterfeit USB Drives Sold Widely Online, Infecting Factories and Labs](https://finance.biggo.com/news/992369d2-4ffb-44a0-9932-026e5ab4f328)
- [Beyond the Horizon: Traveling the World on Camaro Dragon's USB Flash Drives](https://research.checkpoint.com/2023/beyond-the-horizon-traveling-the-world-on-camaro-dragons-usb-flash-drives/)
- [Malicious USB Drives Targeting Global Targets with SOGU and SNOWYDRIVE Malware](https://thehackernews.com/2023/07/malicious-usb-drives-targetinging.html)
- [Hive0154, aka Mustang Panda, drops updated Toneshell backdoor and novel SnakeDisk USB worm](https://www.ibm.com/think/x-force/hive0154-drops-updated-toneshell-backdoor)
- [China-linked Mustang Panda deploys advanced SnakeDisk USB worm](https://securityaffairs.com/182257/apt/china-linked-mustang-panda-deploys-advanced-snakedisk-usb-worm.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1240
