(And it would also be very hard to do this without getting caught. Even harder than most people would think. Particularly at the point where you're trying to make money.)
http://www.bloomberg.com/news/2011-02-24/exxon-shell-bp-said...
This is a serious APT that's been ongoing for 4-5 years and benefits chinese oil exploration.
I still wouldn't touch that with a 10 foot pole. Even with China covering for you, it's not a game to play lightly for anyone who has a home and life in the US.
Neither of these contribute significantly to your exposure any more than something like a laptop or netbook. Concealment helps protect against casual detection, but many offices are littered with spare laptops that no one pays any attention to any way. This is especially true in IT departments where systems may sit on shelves for days or weeks waiting for repair. The notion that a plug computer may be hard to find once identified sounds scary, but in practice, it's a non-issue. You simply identify the port to which the device is connected, unplug it, then trace the cable back to its termination point. I'm going to ignore wireless, because no sensible security plan involves a WiFi network attached to their private network. You segregate wireless in the DMZ, then allow WiFi users to connect to a VPN endpoint using strong encryption.
Any business concerned about securing their networks has implemented policies like shutting interfaces that aren't in use, and authenticating access at the Ethernet level using 802.1X. Neither of these are foolproof, but depending upon how secure you want to be, you build up security at every layer: physical, Ethernet, VPN, application.