Olympic Destroyer is a destructive Windows malware family used in the cyberattack that disrupted the opening of the 2018 Winter Olympics in PyeongChang, South Korea. It is best characterized as a wiper with worm-like lateral movement features. Its primary objective was operational disruption rather than espionage: it disabled recovery mechanisms and services, corrupted files on local and mapped network resources, cleared event logs, and forced system shutdowns, leaving affected systems difficult to recover and impairing organizers’ internal operations.
The malware operates as a multi-component package. Observed samples dropped embedded modules that harvested Windows and browser-stored credentials, a legitimate remote execution utility used for propagation, and a destructive payload. Browser credential theft targeted major Windows browsers including Internet Explorer, Firefox, and Chrome, while a separate credential-dumping component attempted to obtain operating system credentials from memory using techniques similar to Mimikatz-derived tooling. Stolen credentials were then incorporated into propagated copies of the malware to support authenticated lateral movement.
For discovery and spread, Olympic Destroyer enumerated local network information including the ARP table and identified additional systems through WMI and directory-related queries. It propagated laterally using WMI and PsExec-style remote execution, copying itself to remote hosts and launching there with harvested credentials. It also enumerated mapped network shares and writable shared resources, which were subsequently targeted for destructive actions.
Its destructive behavior included deleting volume shadow copies and backup catalogs, disabling startup recovery and boot-failure handling, disabling Windows services, deleting key Windows event logs, and wiping files on accessible shares by overwriting all or part of their contents. The malware also included self-deletion and anti-forensic behavior, including overwriting its own contents and removing itself after execution. Analyses consistently found no meaningful command-and-control backdoor capability and no evidence that stolen credentials were exfiltrated for long-term intelligence collection; credential theft primarily supported propagation and impact.
Olympic Destroyer has been widely associated in public reporting with Sandworm, but attribution remains contested because the malware contained deliberate false-flag elements and overlapping tradecraft that could implicate multiple actors. The case is frequently cited as a prominent example of deceptive malware attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On 12 February, Talos published a blog post detailing the functionality of the malware that we had identified with high confidence as having been used in the attack. We named the malware Olympic Destroyer.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sandworm Team has developed malware for its operations, including malicious mobile applications and destructive malware such as NotPetya and Olympic Destroyer.
On 12 February, Talos published a blog post detailing the functionality of the malware that we had identified with high confidence as having been used in the attack. We named the malware Olympic Destroyer.
On 12 February, Talos published a blog post detailing the functionality of the malware that we had identified with high confidence as having been used in the attack. We named the malware Olympic Destroyer.
On 12 February, Talos published a blog post detailing the functionality of the malware that we had identified with high confidence as having been used in the attack. We named the malware Olympic Destroyer.
On 12 February, Talos published a blog post detailing the functionality of the malware that we had identified with high confidence as having been used in the attack. We named the malware Olympic Destroyer.
DOJ tied Unit 74455 officers to BlackEnergy, Industroyer, KillDisk, NotPetya, and Olympic Destroyer.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware isn’t the only aspect you need to look into—you need to look at the infrastructure, domain registrations, telemetry, the stuff you might find on control servers.
Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of payloads, droppers, post-compromise tools, backdoors (including backdoored images), packers, C2 protocols, and the creation of infected removable media.
WMI(”SELECT ds_cn FROM ds_computer”クエリ)を利用して得られた端末一覧情報を取得
This code is responsible for leveraging cmd.exe to copy the initial stage to a remote system in %ProgramData%\%COMPUTERNAME%.exe and executing it via a VBScript.
This code is responsible for leveraging cmd.exe to copy the initial stage to a remote system in %ProgramData%\%COMPUTERNAME%.exe and executing it via a VBScript.
正規プログラムである「notepad.exe」を隠し状態で起動しWriteProcessMemoryによりコードインジェクションを実施、CreateRemoteThreadで「notepad.exe」内に書き込まれたコードを実行します。
ボリュームシャドーコピー(システムの復元)の削除 / システムバックアップの削除(wbadminによる) / イベントログ(SYSTEMおよびSECURITY)の削除
C:\Windows\system32\cmd.exe /c wevtutil.exe cl System C:\Windows\system32\cmd.exe /c wevtutil.exe cl Security
まず(1)と(2)のEXEファイルを実行することで、OSのログイン情報および、ブラウザの保存情報などの各種ログイン情報・パスワード情報を取得します。
The system stealer attempts to obtain credentials from LSASS with a technique similar to that used by Mimikatz.
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
それらの宛先に対し、自身が上記でドロップしたPsExecを利用することでリモート先への自身のコピー及びリモート実行を行う事で横展開(ワーム活動)を行います。
47 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
77 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive malware used in disruptive operations attributed to GRU Unit 74455, including the 2018 Winter Olympics attack.
Destructive malware/tooling family tied by DOJ to GRU Unit 74455.
Destructive wiper malware used to disrupt event operations, including Wi-Fi, ticketing systems, official apps, and websites during the PyeongChang 2018 Winter Olympics.
Destructive wiper malware used during the 2018 Pyeongchang Winter Olympics to disrupt Wi-Fi, ticketing, websites, and other event systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.