Olympic Destroyer is a destructive Windows wiper with self-propagating worm capabilities, used to disrupt the February 2018 Winter Olympics in Pyeongchang, South Korea. The operation affected Olympic organizers, suppliers, and partners, interrupting website availability, ticket printing, and media connectivity during the opening ceremony. The malware is associated with Sandworm Team; the attack activity has also been tracked as Hades.
Olympic Destroyer extracts credentials from LSASS using a Mimikatz-like module and harvests saved passwords from Internet Explorer, Firefox, and Chrome. It discovers additional systems through Windows Management Instrumentation and the local ARP table, enumerates mapped network shares, and uses stolen credentials with PsExec and WMI to copy and execute itself on remote Windows hosts. During propagation, it embeds harvested credentials into its own binary, allowing subsequent copies to reuse accumulated credentials.
Its destructive functionality deletes volume shadow copies and the Windows backup catalog, disables startup recovery and Windows services, clears System and Security event logs, and corrupts writable files on mapped shares by overwriting their contents or headers. It then forcibly shuts down compromised hosts, leaving systems unusable and hindering recovery. For anti-forensic self-deletion, it injects code into a legitimate text-editor process and overwrites its own executable before removing it. Its credential theft supports internal propagation rather than demonstrated command-and-control exfiltration.
Olympic Destroyer contains deliberate false-flag artifacts, including a forged Rich Header intended to suggest a connection to Lazarus Group. Copied code and similarities to other malware complicated early attribution; these technical overlaps alone do not establish common authorship.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On 12 February, Talos published a blog post detailing the functionality of the malware that we had identified with high confidence as having been used in the attack. We named the malware Olympic Destroyer.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sandworm Team has developed malware for its operations, including malicious mobile applications and destructive malware such as NotPetya and Olympic Destroyer.
Olympic Destroyer was a cyber-sabotage attack based on the spread of a destructive network worm.
On 12 February, Talos published a blog post detailing the functionality of the malware that we had identified with high confidence as having been used in the attack. We named the malware Olympic Destroyer.
On 12 February, Talos published a blog post detailing the functionality of the malware that we had identified with high confidence as having been used in the attack. We named the malware Olympic Destroyer.
On 12 February, Talos published a blog post detailing the functionality of the malware that we had identified with high confidence as having been used in the attack. We named the malware Olympic Destroyer.
On 12 February, Talos published a blog post detailing the functionality of the malware that we had identified with high confidence as having been used in the attack. We named the malware Olympic Destroyer.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
まず(1)と(2)のEXEファイルを実行することで、OSのログイン情報および、ブラウザの保存情報などの各種ログイン情報・パスワード情報を取得します。
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
67 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
83 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive malware used in disruptive operations attributed to GRU Unit 74455, including the 2018 Winter Olympics attack.
Destructive malware/tooling family tied by DOJ to GRU Unit 74455.
Destructive wiper malware used to disrupt event operations, including Wi-Fi, ticketing systems, official apps, and websites during the PyeongChang 2018 Winter Olympics.
Destructive wiper malware used during the 2018 Pyeongchang Winter Olympics to disrupt Wi-Fi, ticketing, websites, and other event systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.