Olympic Destroyer is a destructive malware operation associated with the 2018 Winter Olympics in Pyeongchang. It targeted organizations connected to the Olympic Games, including companies involved in event operations and Olympic facilities. The operation is notable for combining disruptive effects with deliberate attribution deception, embedding false-flag artifacts intended to mislead investigators toward other known threat actors. The malware exhibited post-compromise and destructive tradecraft consistent with a wiper-style intrusion. Documented behavior includes remote system discovery within victim networks using Windows Management Instrumentation to enumerate systems, indicating internal reconnaissance in support of broader impact. It also inhibited recovery by using native Windows administrative utilities to delete shadow copies, remove backup catalogs, and disable operating system recovery features, reducing victims’ ability to restore affected systems. Olympic Destroyer is widely discussed as a prominent example of malware engineered not only for operational disruption but also for defense evasion through deceptive attribution. High-confidence reporting in this context supports its use against Olympic-related entities and its reliance on native Windows tooling for reconnaissance and recovery inhibition, but does not by itself establish a definitive country of origin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Olympic Destroyer is known for targeting organizations related to the Pyeongchang Olympic Games, using supply chain attacks and planting false flags to complicate attribution.
Uses WMI to enumerate systems across victim networks.
Referenced as an example of using false-flag indicators in malware development to mislead attribution.
Destructive malware that disables Windows recovery features using built-in utilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.