← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

China-linked hackers used USBs to backdoor executive laptops at agricultural conference

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • OVERCAST PANDA compromised laptops at an agricultural conference.
  • Attackers physically accessed hotel rooms to install malware via USB.
  • The malware, FlowCloud, enabled keylogging and data exfiltration.
  • This method bypassed network and phishing defenses.

Physical Compromise at Conference

A Chinese state-linked hacking group, tracked as OVERCAST PANDA by CrowdStrike, compromised executive laptops during an agricultural industry conference on Hainan Island. The intrusions occurred between March and May 2026, with attackers entering hotel rooms and booting machines from USB sticks while executives were absent.

Bypassing Standard Defenses

This attack method bypassed common cybersecurity defenses such as network intrusion detection and phishing prevention. The hackers directly wrote a backdoor called FlowCloud to each laptop's storage, then rebooted the machines. CrowdStrike's OverWatch team disrupted these intrusions.

FlowCloud Malware Capabilities

Once the executives powered on their laptops, FlowCloud activated, initiating keylogging, screen capture, file collection, and credential harvesting. The malware has been documented since 2020, previously delivered via phishing and USB in other campaigns.

Novel Attack Vector

CrowdStrike noted the novelty of combining hotel-room entry by a state intelligence service with malware deployment via USB boot, rather than relying on user interaction. This type of physical-access tampering, known as an "evil maid attack," is rare among the adversaries CrowdStrike tracks.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~23 min · 21 stories · Sep 03

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A Chinese state-linked hacking group, OVERCAST PANDA, compromised executive laptops at an agricultural conference by physically accessing hotel rooms and installing malware via USB drives. This method bypassed typical network and phishing defenses, highlighting a vulnerability in physical security protocols that many organizations have fixes for but do not implement.