China-linked hackers exploit USB backdoors to compromise executive laptops
Louis Columbus
10:33 am, PT, September 3, 2026
A Chinese state-linked hacking group, known as OVERCAST PANDA by CrowdStrike, infiltrated executive laptops at an agricultural industry conference on Hainan Island this spring through a novel method: USB backdoors. Instead of traditional phishing or network breaches, the attackers targeted hotel rooms, booting machines from USB sticks while executives dined.
CrowdStrike disclosed this campaign in its 2026 Threat Hunting Report, detailing the operation's timeline at Fal.Con 2026. The report reveals intrusions occurring between March and May 2026, with timestamps verified by Adam Meyers, CrowdStrike's senior vice president of counter adversary operations.
This attack, named an "evil maid attack" by security researchers, involves physically accessing an unattended laptop and installing malware via a USB stick. While not uncommon, the unique aspect here is the combination of hotel room entry and malware deployment triggered by USB booting.
FlowCloud, the malware used, predates this campaign, having been documented by Proofpoint in 2020 and tracked by NTT Security's SOC since early 2022. CrowdStrike's OverWatch team disrupted the intrusions, confirming OVERCAST PANDA's continued activity.
"Hotel entry is a very common thing," Meyers remarked. "But what is unique is the combination of hotel entry with deployment of malware."
Existing security measures, including EDR (Endpoint Detection and Response), MFA (Multi-Factor Authentication), and AI-driven agents, were bypassed by this attack, as it occurred below the operating system and agent layers. Falcon caught FlowCloud after boot, but by then, the implant and its trigger were already on disk.
CrowdStrike's AI security product slate, unveiled at Fal.Con 2026, aims to address these gaps, including Falcon Guardian, SafeMind, the Agentic Identity Provider, and AI Gateway.