OlympicDestroyer is destructive Windows malware with self-propagating network-worm capabilities, associated with Sandworm, a Russian GRU threat group. It disrupted infrastructure supporting the 2018 Winter Olympics in Pyeongchang, South Korea, around the opening ceremony, affecting wireless connectivity, display systems, ticketing, and other operational services. Affected organizations included Olympic partners, IT service providers, ski resort hotels, and a ski resort automation vendor.
Its modular architecture combines credential stealers, the legitimate PsExec utility, and a wiper. It retrieves passwords from browsers and Windows credential storage, incorporates collected credentials into newly generated copies of itself, and spreads to accessible network computers using stolen credentials and existing user privileges. The destructive component targets files on remote network shares rather than local user files. It also deletes shadow copies, disables recovery options and services, clears Windows event logs, and reboots affected systems, impairing their usability and recovery. It does not establish persistence and includes measures to prevent repeated reinfection.
The associated intrusion campaign used Olympic-themed spearphishing documents that induced recipients to enable Office macros, leading to PowerShell-based backdoor deployment. Operators conducted manual lateral movement before releasing the destructive worm. OlympicDestroyer is also notable for deliberate attribution deception, including a forged executable Rich header designed to resemble Lazarus-linked malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The main malware module is a network worm that consists of multiple components, including a legitimate PsExec tool from SysInternals’ suite, a few credential stealer modules and a wiper.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sandworm’s disruption of the 2018 Pyeongchang Winter Olympics with the OlympicDestroyer malware.
The main malware module is a network worm that consists of multiple components, including a legitimate PsExec tool from SysInternals’ suite, a few credential stealer modules and a wiper.
The main malware module is a network worm that consists of multiple components, including a legitimate PsExec tool from SysInternals’ suite, a few credential stealer modules and a wiper.
The main malware module is a network worm that consists of multiple components, including a legitimate PsExec tool from SysInternals’ suite, a few credential stealer modules and a wiper.
In the past, we have seen sophisticated attacks such as OlympicDestroyer confusing the industry and complicating attribution.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Since December 2017 security researchers have been seeing samples of MS Office documents in spearphishing emails related to the Winter Olympics uploaded to VirusTotal. The documents contained nothing but slightly formatted gibberish ... encouraging the user to press a button to “Enable Content”.
When the victim “enables content”, the document starts a cmd.exe with a command line to execute a PowerShell scriptlet that, in turn, downloads and executes a second stage PowerShell scriptlet and, eventually, backdoors the system.
They seemed to be moving through the network via Psexec and stolen credentials, opening a default meterpreter port (TCP 4444) and downloading and running a backdoor (meterpreter).
Sandworm directly deployed the OLYMPICDESTROYER wiper at the 2018 Pyeongchang Winter Olympics, disabling Wi-Fi at the opening ceremony, taking down the official ticketing system, disrupting broadcast drone operations, and compromising over 300 systems, requiring 12 hours to restore.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Wiper malware used in disruptive attacks against the 2018 Pyeongchang Winter Olympics, impacting ticketing, Wi-Fi, connectivity, and operational services.
Referenced as an example of a wiper malware seen during the PyeongChang Olympics.
Destructive self-propagating malware used in the Pyeongchang Winter Olympics attack. It steals credentials from browsers and Windows storage, propagates laterally using PsExec and stolen credentials, delivers a wiper payload to remote systems and shares, deletes backups and shadow copies, clears event logs, disables services, and reboots systems into an unbootable state.
Mentioned for comparison as a prior wiper with worming capabilities similar to the spreading technique observed.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.