📣 Send us your press release
Site updates every 15 minutes
Technology

China-linked hackers compromised executives' laptops via hotel room USB attacks

A state-linked Chinese hacking group compromised executive laptops at an agricultural conference by physically accessing hotel rooms and installing malware via USB drives.

3 September 2026
China-linked hackers compromised executives' laptops via hotel room USB attacks

A hacking group with ties to the Chinese state compromised executive laptops at an agricultural industry conference on Hainan Island this spring. The attackers bypassed traditional methods like phishing and network breaches by entering hotel rooms and installing malware via a USB stick while executives were dining.

CrowdStrike, which tracks the group as OVERCAST PANDA, disclosed the campaign in its 2026 Threat Hunting Report. The intrusions, dated between March and May 2026, involved intruders entering hotel rooms to write a backdoor named FlowCloud directly to each laptop's storage before rebooting the machines.

Security researchers refer to this tactic as an "evil maid attack," where an attacker exploits physical access to an unattended device. CrowdStrike noted the novelty in this operation was the combination of physical hotel room entry by a state intelligence service with direct malware deployment via USB, rather than relying on user interaction.

Once the executives powered on their laptops the next morning, the FlowCloud backdoor activated, enabling keylogging, screen capture, and credential harvesting. CrowdStrike's systems detected the malware after the operating system booted and the implant began its process, but the initial compromise occurred below the level of standard endpoint security software.

Original source: venturebeat.com