Venturebeat iconVenturebeatSep 3, 2026 ~1 min source read

China-linked hackers backdoored executives' laptops via USB, exploiting a fix companies had but weren't using

local time and a second room by 9:57 p.m., writing a backdoor called FlowCloud directly to each laptop's storage before rebooting the machines and leaving. There was no network intrusion, no phishing email, and no credential stolen through a login page.

China-linked hackers backdoored executives' laptops via USB, exploiting a fix companies had but weren't using

Share this story

Send the public story page.

Useful takeaways from this story.

local time and a second room by 9:57 p.m., writing a backdoor called FlowCloud directly to each laptop's storage before rebooting the machines and leaving.

There was no network intrusion, no phishing email, and no credential stolen through a login page.

CrowdStrike's OverWatch team disrupted the intrusions and assessed that OVERCAST PANDA will almost certainly continue.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

local time and a second room by 9:57 p.m., writing a backdoor called FlowCloud directly to each laptop's storage before rebooting the machines and leaving. There was no network intrusion, no phishing email, and no credential stolen through a login page. CrowdStrike's OverWatch team disrupted the intrusions and assessed that OVERCAST PANDA will almost certainly continue.

How it works

  • Security researchers have called physical-access tampering with an unattended laptop an "evil maid attack," since Joanna Rutkowska...
  • utilities, and NTT Security's SOC has tracked USB-delivered infections at overseas branches of Japanese organizations since early 2022.

Details worth keeping

CrowdStrike, which tracks the group as OVERCAST PANDA, disclosed the campaign in its 2026 Threat Hunting Report and detailed the operation's timeline in an interview with VentureBeat at Fal.Con 2026: an intruder entered one room at around 8 p.m. Proofpoint documented it in 2020, delivered by phishing to U.S.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app