Fake USB sticks used by the Japanese army spread a China-linked computer virus inside a secure network for nearly a year before they were found to contain malware, Japan’s Nikkei newspaper reported on Thursday.

The flash drives were delivered to Japan’s Ground Self-Defense Force during disaster relief operations in March 2024 following an earthquake in central Japan, the paper said, citing internal army documents. The infection was not discovered until February 2025, when a Japanese soldier in Itami, near Osaka, reported that a computer was operating slowly.

A scan revealed that it had been infected by a virus carried on a compromised flash drive previously linked to a Chinese hacker group, the Nikkei said. The malware infects the computer as soon as the USB drive is inserted.

Read More on World

Newsweek reached out to Japan’s Defense Ministry for comment.

Japan’s army uses both open and isolated systems developed for the military and the country’s Defense Ministry, which uses the closed network to house classified information. When necessary, external data can be transferred in using portable storage devices like USB sticks.

An internal investigation detected the same malware on six of the eight USB drives given to the army at the time, and the infection occurred despite multiple safeguards, including requirements to scan external drives upon receipt and during use. More than 50 computers were found to have been connected to the infected drives at some point, the Nikkei said. And nearly half of those handled classified data, such as unit movements.

Members of the Japanese military stand guard in Tokyo on June 24, 2026.

It said Japan’s army did not disclose the malware infection within its network even though the flash drive—a made-in-China counterfeit that sells for cheaper than the original—remained widely available for purchase online.

A separate report by the Nikkei said factories and research institutes with closed systems had also reported similar infections. The newspaper did not name the brand of the flash drives but said the virus could have been installed during manufacturing.

Malware runs quietly in the background and can steal sensitive data or spy on user activity. It can also disable a computer by corrupting its software.

In 2024, U.S. intelligence agencies warned that increasingly sophisticated cyberattacks by China-linked hackers had been embedding malware unnoticed in U.S. and allied IT systems for years.

The practice known as “pre-positioning” was different from traditional patterns of cyber espionage or intelligence gathering, they said. Instead, the infection potentially could shut down systems linked to critical infrastructure—communications, transportation, water and power—in a crisis, severely delaying a government’s response, including in wartime.

China has long denied carrying out cyberattacks on America and has accused U.S.-linked actors of hacking its systems.