OlympicDestroyer is a destructive Windows malware operation best known for disrupting IT systems associated with the 2018 Winter Olympics in Pyeongchang, South Korea. It functioned as a self-propagating network worm with an integrated wiper component and was used to impair event operations, including ticketing, wireless networking, internet connectivity, display systems, and other supporting services during the opening-ceremony period.
The malware’s main module combined multiple components, including credential-stealing functionality, the legitimate PsExec administration tool for remote execution, and a wiper. It harvested credentials from browsers and Windows credential storage, generated new copies of itself embedding stolen credentials, and propagated laterally across accessible networked systems using current user privileges and recovered passwords. The wiper phase targeted remote network shares, after which the malware cleared Windows event logs, deleted shadow copies and backups, disabled recovery options and services, and forced systems to reboot into an unusable state. Reported behavior indicates it avoided persistence and included safeguards against repeated reinfection.
Associated intrusion activity included spearphishing campaigns themed around the Winter Olympics that targeted organizations connected to the event ecosystem, including partners and service providers across government, transport, media, hospitality, energy, semiconductor, healthcare, advertising, and resort sectors. Malicious documents used social engineering to induce macro execution and launched follow-on PowerShell-based payloads and backdoors. Investigators also observed manual lateral movement and staging activity before the worm was released.
OlympicDestroyer is notable not only for its disruptive impact but also for sophisticated attribution deception. Multiple artifacts appeared to implicate different threat actors, including overlaps suggestive of Lazarus and other clusters, but some of the strongest links were later assessed to have been deliberately forged as false flags. Public reporting has variously linked the operation to Russian state interests, and some research connected it to Sandworm or Sofacy-related activity, while emphasizing the deliberate effort to confuse attribution. The operation remains a prominent case study in destructive malware, worm-enabled disruption, and false-flag tradecraft against high-visibility international events.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The main malware module is a network worm that consists of multiple components, including a legitimate PsExec tool from SysInternals’ suite, a few credential stealer modules and a wiper.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During the opening ceremony, the OlympicDestroyer malware disrupted portions of the Olympic environment, affecting ticketing systems, wireless networks, internet connectivity, and supporting operational services.
The main malware module is a network worm that consists of multiple components, including a legitimate PsExec tool from SysInternals’ suite, a few credential stealer modules and a wiper.
The main malware module is a network worm that consists of multiple components, including a legitimate PsExec tool from SysInternals’ suite, a few credential stealer modules and a wiper.
The main malware module is a network worm that consists of multiple components, including a legitimate PsExec tool from SysInternals’ suite, a few credential stealer modules and a wiper.
In the past, we have seen sophisticated attacks such as OlympicDestroyer confusing the industry and complicating attribution.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Since December 2017 security researchers have been seeing samples of MS Office documents in spearphishing emails related to the Winter Olympics uploaded to VirusTotal. The documents contained nothing but slightly formatted gibberish ... encouraging the user to press a button to “Enable Content”.
When the victim “enables content”, the document starts a cmd.exe with a command line to execute a PowerShell scriptlet that, in turn, downloads and executes a second stage PowerShell scriptlet and, eventually, backdoors the system.
As standalone fileless backdoors, they were built and obfuscated using the same tool.
As standalone fileless backdoors, they were built and obfuscated using the same tool.
They seemed to be moving through the network via Psexec and stolen credentials, opening a default meterpreter port (TCP 4444) and downloading and running a backdoor (meterpreter).
Sandworm directly deployed the OLYMPICDESTROYER wiper at the 2018 Pyeongchang Winter Olympics, disabling Wi-Fi at the opening ceremony, taking down the official ticketing system, disrupting broadcast drone operations, and compromising over 300 systems, requiring 12 hours to restore.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Wiper malware used in disruptive attacks against the 2018 Pyeongchang Winter Olympics, impacting ticketing, Wi-Fi, connectivity, and operational services.
Referenced as an example of a wiper malware seen during the PyeongChang Olympics.
Destructive self-propagating malware used in the Pyeongchang Winter Olympics attack. It steals credentials from browsers and Windows storage, propagates laterally using PsExec and stolen credentials, delivers a wiper payload to remote systems and shares, deletes backups and shadow copies, clears event logs, disables services, and reboots systems into an unbootable state.
Mentioned for comparison as a prior wiper with worming capabilities similar to the spreading technique observed.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.