OLYMPO is the alias of a cybercriminal operator or small team behind Olymp Loader, a Malware-as-a-Service and Loader-as-a-Service offering that emerged in June 2025. The operation marketed Olymp Loader as a fully undetectable assembly-language loader and crypter, and promoted it across multiple underground forums and Telegram channels. The project appears to have evolved rapidly from an earlier "Olymp Botnet" concept with centralized botnet functionality into a modular loader-focused service after that functionality was removed. Olymp Loader has been advertised with support for loading 32-bit, 64-bit, .NET, Java, and native payloads, and with features aimed at persistence, privilege escalation, and defense evasion. Reported capabilities include auto-run persistence, aggressive UAC-flood elevation, payload encryption and obfuscation, code signing, and extensive interaction with Microsoft Defender through exclusions and, in some variants, attempts to disable or remove protections. The service also emphasized anti-analysis and anti-detection updates as a core selling point. Observed use of Olymp Loader in the wild indicates it has been used to deliver commodity stealers and remote access tools, including LummaC2, WebRAT or SalatStealer, QasarRAT, and Raccoon. The broader Olymp ecosystem also included modular stealer components targeting browser data, Telegram data, and cryptocurrency wallets, with exfiltration routed through client-controlled proxy infrastructure. Delivery has included masquerading as legitimate software installers and use as a second-stage payload behind other malware, indicating flexibility in initial access and post-compromise deployment models. OLYMPO’s activity is consistent with financially motivated cybercrime enablement. The operation lowered the barrier to entry for other criminals by selling a maintained loader platform with frequent feature updates, evasive packaging, and support for common infostealer and RAT payloads.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
OLYMPO is the threat actor behind Olymp Loader, a Malware-as-a-Service offering that acts as a loader, crypter, and stealer for browsers, Telegram, and cryptocurrency wallets. The actor markets the malware as fully undetectable (FUD) and written in assembly for evasion and anti-analysis. Olymp Loader is distributed via social engineering, disguised downloads, and is used to deliver credential stealers and RATs.
Crimeware developer/seller operating a Malware-as-a-Service/Loader-as-a-Service offering (“Olymp Loader”, previously marketed as “Olymp Botnet” and later emphasizing crypter functionality). Sells stubs/unique builds, provides built-in stealer modules (browser/Telegram/crypto wallet), and focuses on AV evasion (Defender exclusions/removal, obfuscation, code signing) to enable customers to deliver commodity stealers/RATs at scale.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.