A Chinese language state-linked hacking group compromised government laptops at an agricultural trade convention on Hainan Island this spring — not by means of phishing or a community breach, however by breaking into resort rooms and booting the machines from a USB stick whereas the executives have been at dinner.
CrowdStrike, which tracks the group as OVERCAST PANDA, disclosed the marketing campaign in its 2026 Menace Looking Report and detailed the operation’s timeline in an interview with VentureBeat at Fal.Con 2026: an intruder entered one room at round 8 p.m. native time and a second room by 9:57 p.m., writing a backdoor referred to as FlowCloud instantly to every laptop computer’s storage earlier than rebooting the machines and leaving. There was no community intrusion, no phishing e mail, and no credential stolen by means of a login web page.
The report dates the intrusions to between March and Might 2026, and the timestamps come from Adam Meyers, CrowdStrike’s senior vp of counter adversary operations, who cleared them for publication within the VentureBeat interview. CrowdStrike’s OverWatch group disrupted the intrusions and assessed that OVERCAST PANDA will virtually definitely proceed. FlowCloud itself predates this marketing campaign by years: Proofpoint documented it in 2020, delivered by phishing to U.S. utilities, and NTT Safety’s SOC has tracked USB-delivered infections at abroad branches of Japanese organizations since early 2022.
Safety researchers have referred to as physical-access tampering with an unattended laptop computer an “evil maid assault,” since Joanna Rutkowska demonstrated one with a bootable USB stick in 2009. Bodily-access operations are uncommon throughout the 290 named adversaries CrowdStrike tracks, in accordance with Meyers, and MUSTANG PANDA’s model is determined by a dropped USB stick the sufferer plugs in. What Meyers recognized as novel is the mix of hotel-room entry by a state intelligence service with malware deployment, booting the goal machine from the USB quite than counting on a person to execute a file from it.
When the executives powered on the following morning, the set off fired and FlowCloud loaded. Keylogging, display seize, file assortment, and credential harvesting started.
“We now have the visibility as soon as the machine boots up,” Meyers informed VentureBeat. A registry key or comparable set off begins FlowCloud someday after the working system masses, and that is when Falcon’s sensor picks it up. The hole is the window between the USB write and the following boot — the hours the laptop computer sits compromised and undetected earlier than the manager logs again in.
CrowdStrike revealed that hole a month earlier than it introduced its AI safety product slate — Falcon Guardian, SafeMind, the Agentic Identification Supplier, and AI Gateway — at Fal.Con 2026 this week.
Why present safety instruments missed it
EDR wants the working system loaded and the agent working. MFA waits for a login try, phishing coaching for an e mail, AI agent safety for an agent to safe.
OVERCAST PANDA bypassed all of them on the level of entry. The preliminary compromise accomplished beneath the working OS, beneath the EDR agent, beneath the authentication stack. Falcon caught FlowCloud as soon as its course of began after boot, however by then the implant and its set off have been already on disk.
“Lodge entry is a quite common factor,” Meyers stated. “Speak to any company bodily safety individual. They’re typically conscious of resort entry, however I feel what is exclusive is the mix of resort entry with deployment of malware.”
Meyers stated he thinks China’s Ministry of State Safety sits behind OVERCAST PANDA. The individuals getting into the rooms are both officers or brokers of the MSS or the Ministry of Public Safety, or resort housekeeping workers the companies have bribed or compelled, Meyers informed VentureBeat. A separate mid-2026 intrusion focused a U.S.-based media skilled utilizing the identical tradecraft, in accordance with the report. Concentrating on an agricultural convention aligns with assortment priorities Meyers tied to China’s five-year plans.
What CrowdStrike introduced at Fal.Con and the place runtime safety begins
Nvidia CEO Jensen Huang joined George Kurtz on the Fal.Con stage to unveil SafeMind, an agentic cybersecurity system constructed on Nvidia Nemotron open fashions and CrowdStrike’s menace knowledge. Meyers informed the Fal.Con viewers that 7,400 CVEs have been registered in June 2026, a 96% improve over June 2025, and that CrowdStrike submitted 2,400 of them through accountable disclosure, roughly 30% of all CVEs registered that month.
Falcon Guardian, the corporate’s runtime safety layer for AI brokers on the endpoint, went stay the minute Kurtz put the slide up, CrowdStrike President Mike Sentonas informed the Day 2 viewers, and AI Gateway, listed as a Guardian functionality, ships in September as a hosted service with a hybrid model to observe. AJ Shipley, CrowdStrike’s chief product officer, informed VentureBeat that CrowdStrike will embed a SafeMind mannequin into Guardian for malicious-prompt detection throughout the subsequent couple of weeks.
The threats these merchandise handle are actual, and the report quantifies them. AI agent-triggered detection leads grew at 2.5 instances the speed of human-triggered leads, by OverWatch’s depend. Cloud-conscious eCrime exercise surged 171% over the reporting interval. Vishing intrusions doubled within the first half of 2026 in comparison with the second half of 2025, with the eCrime group SNARKY SPIDER transferring from account takeover to knowledge exfiltration in below 5 minutes after compromising SSO-integrated SaaS purposes.
Each a kind of threats is network-based. All of them assume a working OS, an lively person session, or a stay cloud workload.
The controls that cease this are firmware and coverage
“It is a solvable downside,” Meyers stated. “It is simply an inconvenient answer, which signifies that lots of people do not do it.”
CrowdStrike itself has shipped firmware assault detection and BIOS settings auditing by means of the Falcon sensor since Might 2019, together with a Dell SafeBIOS integration that surfaces BIOS verification telemetry within the Falcon console. The flexibility to audit security-related BIOS settings on the laptops executives carry has sat contained in the platform for seven years. Pointing it at journey units is a choice, not a product hole.
The controls that will have blunted the OVERCAST PANDA marketing campaign are previous and low-cost, and every does a distinct job. Disabling exterior boot in UEFI removes the vector. A BIOS administrator password retains it disabled. Pre-boot authentication lets a international boot atmosphere load and nonetheless retains the encrypted quantity unreadable till a human provides the PIN or key. Firmware monitoring detects tampering after the very fact.
“Do not carry something with you that you just’re not comfy with handing over to a international intelligence service,” Meyers suggested. He used short-term laptops and e mail accounts on abroad journeys whereas at CrowdStrike, wiping the gadget when he returned. The publicity begins at customs. Officers can seize a tool and compel a login, he added.
“They’ve grasp keys to that stuff,” was his verdict on resort safes.
Why scale wins the precedence battle
Intrusions tracked by CrowdStrike OverWatch grew about 4% over the reporting interval, after a 27% rise the yr earlier than, a plateau CrowdStrike attributed to a shift towards extra advanced, resource-intensive campaigns. The OVERCAST PANDA resort room operation is the instance.
The community menace worries Meyers extra. Requested to weigh OVERCAST PANDA’s resort room marketing campaign in opposition to the REVENANT SPIDER case he had proven on the Fal.Con stage, an eCrime group utilizing AI to compromise 17 victims with customized net shells in 48 minutes, he picked REVENANT SPIDER.
“You’ll be able to’t intrude on resort rooms at scale,” he stated. “You’ll be able to’t intrude on bodily units at scale. And even then, it is only one gadget.” The individual within the room is the goal, and the intrusion not often pivots additional, he added. “REVENANT SPIDER, they’re transferring at that pace and so they’re utilizing AI throughout the board, and that is an entire different menace, and I feel that is extra regarding for the common enterprise.”
Community-speed, AI-powered intrusions scale. Bodily-access tradecraft doesn’t. Safety budgets observe the menace that hits essentially the most machines. The menace that’s hardest to detect on one machine will get what’s left.
However the executives who attended an agricultural convention in China this spring have been the precise targets of a state intelligence service, one which selected the gradual, unscalable methodology exactly as a result of it really works the place network-based assaults fail.
The convention itself is the menace mannequin
Executives at conferences are the marketing campaign’s targets, and runtime safety begins solely as soon as the machine boots. The distributors filling the Las Vegas present ground this week have been promoting that very same runtime safety to attendees whose personal laptops carry the an identical hole.
Organizational fracture is the actual downside. Falcon Guardian ships to 1 group, and BIOS configuration on journey laptops belongs to a different. The Agentic IdP rolls out below id governance whereas the choice about whether or not executives carry production-access machines to worldwide conferences sits with a distinct group. And the funds line that funds cloud-threat protection has nothing to do with travel-device insurance policies.
Meyers has lived either side. “I’ve talked to corporations the place they’re like, we’re having a board assembly in Shanghai, and I am like, why would you do this?”
What safety leaders have to do earlier than the following journey
Audit each government laptop computer for USB boot standing. If the gadget will be booted from USB proper now, it has the identical hole OVERCAST PANDA exploited this spring. The steps beneath cowl Home windows laptops, the platform FlowCloud targets.
Implement full-disk encryption with pre-boot authentication. BitLocker in a TPM-only configuration is a documented weak level in opposition to bodily entry. SCRT researchers pulled the quantity grasp key off the LPC bus with a $49 FPGA module in 2021, and Dolos Group did the identical over SPI that yr. OVERCAST PANDA wrote a backdoor and its post-boot set off to the Home windows quantity, so the operators had write entry to it. That factors to machines that have been both unencrypted or protected by a configuration the operators defeated. Pre-boot authentication with a PIN or USB key forces a human step earlier than storage turns into readable.
Confirm Safe Boot is enabled and the revocation record is present. Safe Boot validates signatures on boot parts and blocks most unauthorized bootloaders, but it surely leaves exterior media bootable and signed shims can nonetheless carry a bypass. ESET revealed findings on 11 legacy Microsoft-signed UEFI shims in July 2026 that allow untrusted code run at boot on any machine trusting Microsoft’s third-party certificates. Microsoft revoked them in its June 9, 2026 DBX replace, so a laptop computer that skipped that replace nonetheless trusts them. Lock the boot order on the UEFI stage, disable one-time boot menus, and set a BIOS administrator password that covers each the setup utility and any boot-override key. Meyers’ learn is that a whole lot of these settings go unchecked as a result of the repair is inconvenient.
Situation travel-only units for worldwide conferences with no entry to manufacturing methods, no saved credentials for inner instruments, and no persistent VPN configuration.
“If they’ll get their palms on it, they’ll personal it,” Meyers put it, citing an previous DEF CON adage. Falcon catches FlowCloud solely after boot — the publicity is the hours between the USB write and the following login, whereas the laptop computer sits closed and compromised.
“It is low-cost to purchase a few laptops and a few telephones,” Meyers stated. The controls that shut that window are a handful of firmware settings and a spare laptop computer. The query is whether or not anybody has deployed them.