China-Linked Hackers Use Physical USB Attacks on Executives

- Chinese state-linked group OVERCAST PANDA compromised executive laptops via physical hotel room intrusions.
- Attackers used bootable USB sticks to install FlowCloud malware, bypassing EDR and MFA.
- The campaign targeted agricultural industry executives on Hainan Island between March and May 2026.
- Security gaps exist because traditional software defenses only activate after the OS boots.
The traditional narrative of cyber espionage usually involves a sophisticated phishing email, a leaked password, or a vulnerability in a cloud server. However, a recent campaign attributed to a Chinese state-linked hacking group has returned to a more primal method of intrusion: physical access. By literally breaking into hotel rooms, these actors bypassed some of the most advanced digital security stacks available to modern enterprises.
The anatomy of a physical breach
Between March and May 2026, executives attending an agricultural industry conference on Hainan Island became the targets of a highly coordinated operation. According to the 2026 Threat Hunting Report from CrowdStrike, the group known as OVERCAST PANDA did not rely on network intrusions or social engineering. Instead, they waited for their targets to leave their rooms for dinner.
The precision of the timing suggests a high level of intelligence gathering. In one documented instance, an intruder entered a hotel room at approximately 8 p.m. local time. A second room was breached shortly after, at 9:57 p.m. The attackers did not steal the hardware; instead, they used bootable USB sticks to write a backdoor called FlowCloud directly to the laptops' storage. After rebooting the machines to ensure the implant was set, the intruders vanished, leaving no obvious sign of entry.
Why FlowCloud is a persistent threat
The malware used in this campaign, FlowCloud, is not a new creation. Its history shows a long-term evolution in delivery methods. Proofpoint first documented the backdoor in 2020, at that time delivered via phishing campaigns targeting utilities in the United States. By early 2022, NTT Security's SOC had tracked versions of the infection delivered via USB at overseas branches of Japanese organizations.
The transition from phishing to physical installation marks a strategic shift. While phishing requires the user to click a link or open an attachment, the Hainan Island operation removed the human element entirely. The malware was placed on the disk while the machine was off, meaning the executive was compromised before they even touched their keyboard the following morning.
The return of the evil maid attack
In cybersecurity circles, this method is known as an evil maid attack. The term describes a scenario where an attacker gains physical access to an unattended device to install a bootkit or steal data. The concept is not new; researcher Joanna Rutkowska demonstrated the viability of bootable USB tampering as far back as 2009.
Despite its age, the tactic remains devastatingly effective because it operates below the level of the operating system. Adam Meyers, CrowdStrike's senior vice president of counter adversary operations, noted that physical-access operations are rare among the 290 adversaries the firm tracks. While other groups, such as MUSTANG PANDA, use USBs, they typically rely on the victim finding a dropped drive and plugging it in. OVERCAST PANDA's approach is more aggressive: they do not wait for the victim to make a mistake; they create the vulnerability themselves through physical trespassing.
The blind spot in modern EDR
The most alarming aspect of this breach is why standard security tools failed to prevent it. Most enterprises rely on Endpoint Detection and Response (EDR) systems and Multi-Factor Authentication (MFA) to protect their executives. However, these tools have a fundamental limitation: they require the operating system to be running to function.
Because the attackers booted the laptops from an external USB, they operated in a space where the EDR agent was dormant. There was no login attempt for MFA to challenge and no email for phishing filters to catch. The compromise happened in the gap between the machine being powered off and the OS loading. As VentureBeat reports, visibility only returns once the machine boots up and the sensor picks up the trigger.
The initial compromise completed below the running OS, below the EDR agent, below the authentication stack.
Once the executives powered on their machines the next morning, the FlowCloud trigger fired. The malware then initiated a suite of espionage activities, including keylogging, screen capture, file collection, and credential harvesting, effectively turning the executive's own tool into a surveillance device for a foreign intelligence service.
Strategic implications for global travel
The OVERCAST PANDA campaign highlights a critical vulnerability for C-suite executives and government officials traveling to high-risk jurisdictions. The assumption that a laptop is safe as long as it is password-protected or encrypted is no longer sufficient when the adversary has the capability and willingness to enter a private hotel room.
This operation demonstrates that state-linked actors are willing to blend traditional espionage—physical infiltration—with digital payloads. The use of a known backdoor like FlowCloud suggests that the attackers prioritize reliability and proven results over the need to develop entirely new, stealthier code for every mission.
Global business impact and risk mitigation
For companies operating in the USA, UK, and other global markets, this incident serves as a wake-up call regarding the physical security of corporate assets. In the US and UK, where corporate espionage is a constant threat to intellectual property, the reliance on software-only security is a liability.
From a regulatory and compliance perspective, this breach underscores the need for stricter hardware security policies. While the EU AI Act focuses on the deployment of artificial intelligence, the underlying security of the hardware that runs these systems remains a primary concern. Businesses must recognize that physical security is a prerequisite for cybersecurity.
To mitigate these risks, international firms should consider the following hardware-level protections:
- Disabling boot from USB in the BIOS/UEFI and protecting those settings with a strong password.
- Implementing Full Disk Encryption (FDE) with pre-boot authentication.
- Using physical locks or tamper-evident seals on laptop ports during international travel.
- Providing 'burner' laptops for executives traveling to regions with high state-sponsored hacking activity.
The gap identified by CrowdStrike—the window of time where a machine is compromised but not yet booted—is the new frontier for state-sponsored attacks. As companies integrate more AI-driven security tools, the physical layer remains the most overlooked vulnerability in the executive toolkit.
FAQ
What is an evil maid attack?
It is a physical security breach where an attacker gains access to an unattended device, such as a laptop in a hotel room, to install malware or steal data before the owner returns.
How did OVERCAST PANDA bypass MFA and EDR?
They booted the laptops from a USB stick while the machines were off. Since EDR and MFA only function once the operating system is running, the attackers could install the FlowCloud backdoor without triggering any alerts.
What is FlowCloud?
FlowCloud is a backdoor malware used for espionage. It has been tracked since 2020 and is capable of keylogging, screen capturing, and harvesting credentials.
Who were the targets of this specific campaign?
The campaign targeted executives in the agricultural industry who were attending a conference on Hainan Island between March and May 2026.
Sources: Venturebeat, Novalogiq, Aventure ·
Scrivila qui: Susanna, l assistente AI di glacom, ti risponde via email con un approfondimento gratuito.
Nessuna consulenza personalizzata (finanziaria, legale o medica): solo informazione e fonti. Email usata solo per rispondere.
oppure scrivile su: WhatsApp · Telegram · SimpleX · Delta Chat · Email



