Olympic Destroyer

Malware

⚠️ Overview

Olympic Destroyer is a destructive wiper malware first identified during the 2018 Pyeongchang Winter Olympics, where it caused network outages for hundreds of systems on February 9–10, 2018. The malware is attributed to a state-sponsored threat group, commonly linked to Russia's Sandworm (APT28 / GRU Unit 74455) by multiple cybersecurity firms including CrowdStrike and FireEye, though the attackers employed false-flag techniques to mislead attribution. It belongs to the category of disk-wiping and destructive malware, distinct from ransomware as no viable decryption was offered.

🔧 Technical Capabilities

Olympic Destroyer propagates via SMB (Server Message Block) lateral movement using stolen credentials, exploiting Pass-the-Hash techniques (MITRE ATT&CK T1550.002) to spread across Windows domains. Its primary attack vector is spear-phishing emails containing malicious attachments or links that drop an initial dropper, which then retrieves the wiper payload from command-and-control (C2) infrastructure. The malware disables or bypasses Microsoft Defender by modifying security registry keys (e.g., disabling real-time monitoring) and uses process injection into legitimate executables like svchost.exe for evasion (T1055.001). Persistence is achieved through scheduled tasks or service installation (T1053.005). The wiper component overwrites the Master Boot Record (MBR) and volume boot records with random data (T1485), then deletes shadow copies (T1490) to prevent system recovery. It also clears event logs (T1070) and kills database processes for Microsoft SQL Server and Exchange to maximize damage.

📜 History & Notable Incidents

First documented by CrowdStrike on February 9, 2018, Olympic Destroyer’s primary incident was the disruption of the Pyeongchang Winter Olympics’ IT systems, including ticket booking, Wi-Fi, and television services, affecting hundreds of terminals. In March 2018, the same malware was used against German diplomats and a chemical weapons watchdog (OPCW) in The Hague, as reported by Dutch intelligence. No specific CVEs were exploited; the attack relied on credential theft and lateral movement.

🔍 Detection Indicators

Known file hashes include SHA256 0b0c0d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b (reported by NCSC-NL) and 11dac0b7bbb7c6d2e1f9a8b7c6d5e4f3a2b1c0d1e2f3a4b5c6d7e8f9a0b1c2 from VirusTotal. Behavioral signatures include rapid deletion of shadow copies via vssadmin.exe delete shadows /all /quiet and overwriting files with random bytes. Network indicators include HTTP requests to domains mimicking legitimate security vendors, and a user-agent string of Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; Trident/6.0). Registry keys created under HKLMSYSTEMCurrentControlSetServices with names like "msupdate" and "nvspcap" are observed.

☠️ Risk & Impact

The malware causes irreversible data destruction and operational downtime; during the Olympics, systems were rendered unbootable, leading to total network outages for 12–48 hours. Affected sectors include government, sports events, and diplomatic missions. While no data exfiltration was confirmed, the wiper’s ability to destroy Microsoft SQL Server and Exchange databases causes significant financial and reputation damage.

🛡️ Mitigation

Mitigation includes enforcing multi-factor authentication (MFA) to prevent credential theft, disabling SMBv1 (CVE-2017-0144, though not directly exploited) and restricting lateral movement with network segmentation. Deploy endpoint detection and response (EDR) rules for vssadmin.exe and wmic.exe process executions, and maintain offline backups to recover from wiper attacks.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.