China-Linked Hackers Snuck Into Hotel Rooms to Hack Executives’ Laptops With an Old-School USB Trick

CrowdStrike reveals how OVERCAST PANDA compromised executive laptops using USB-based attacks

AI Hacker
China-linked hackers used USB drives to plant backdoors on executive laptops Photo by Antoni Shkraba: Pexels

A China-linked hacking group compromised corporate executives' laptops during an agricultural industry conference on Hainan Island by allegedly entering their hotel rooms and booting the unattended machines from USB media, according to CrowdStrike. The incidents reportedly occurred between March and May 2026.

The attackers exploited a physical-security and device-configuration gap for which longstanding mitigations already existed, including disabling external boot and requiring pre-boot authentication. CrowdStrike said such protections are often left unenforced because they can be inconvenient to deploy.

The intrusion revives an attack method that many corporate security teams had largely stopped planning for. The USB-based compromise predates most modern enterprise security architecture. Its reappearance in a state-sponsored operation against business executives at a physical event highlights a stubborn gap between security controls that organisations have available and those actually enforced on high-value devices.

How OVERCAST PANDA Planted FlowCloud on Executive Laptops

CrowdStrike attributes the activity to OVERCAST PANDA, a China-linked threat actor with an established history of corporate espionage. According to the findings, OVERCAST PANDA installed a backdoor program called FlowCloud directly onto the storage of targeted laptops during the Hainan Island conference events.

FlowCloud is a remote-access implant. Once installed, it enables keylogging, screen capture, file collection and credential harvesting long after the victim has gone home. The delivery method is notable for its simplicity.

Rather than fighting through firewalls, running phishing campaigns, or hunting for zero-day browser exploits, the attackers needed only physical proximity to a target's device. USB attacks of this type bypassed many protections that depend on a running operating system, active endpoint agent or network connection.

A device that has never touched a malicious server and carries no suspicious browsing history can still be compromised if an attacker obtains sufficient physical access.

What makes the operation notable is that the fundamental mitigations were neither new nor expensive. CrowdStrike said disabling external boot, setting a BIOS administrator password and enforcing pre-boot authentication could have significantly reduced the attack surface.

The failure was less about an exotic vulnerability than about enforcing basic controls on high-value travel devices. Security teams can disable external boot, enforce BIOS passwords and require pre-boot authentication, but those settings may conflict with convenience and support requirements for employees who travel frequently.

Why USB Attacks Remain Effective Against High-Value Targets

Most enterprise security investment concentrates on network perimeter defence: firewalls, intrusion detection systems, endpoint software that monitors for suspicious traffic. These tools are built to catch threats arriving over data connections. They are far less effective when the threat arrives on a piece of hardware that an employee plugs in directly.

Unlike conventional USB attacks that rely on a victim plugging in an unknown device, the Hainan operation reportedly required no such interaction. The attackers gained physical access to unattended laptops and booted them directly from external media while their owners were away.


Frequently Asked Questions

  • What is a USB-based cyber attack?
    A USB-based cyber attack involves compromising a device by using a USB drive to bypass security measures and install malicious software.
  • How can organizations protect against USB-based attacks?
    Organizations can protect against USB-based attacks by disabling external boot, setting BIOS passwords, and enforcing pre-boot authentication.
  • Why are USB attacks still effective?
    USB attacks remain effective because they can bypass network-based security measures and exploit physical access to devices.