Olympic Destroyer is a destructive Windows malware family used by the Russian GRU-linked Sandworm threat actor, also tracked as Unit 74455 or APT44, in the cyberattack that disrupted the opening ceremony of the 2018 PyeongChang Winter Olympics. The operation affected Olympic IT infrastructure including Wi-Fi, ticketing, the official application, the event website, and other supporting systems, and has been publicly attributed by multiple governments to Sandworm.
The malware combines wiper functionality with credential theft, discovery, lateral movement, and defense-evasion features. It attempts to obtain credentials from web browsers and from LSASS memory, then uses stolen credentials to move laterally with PsExec and Windows Management Instrumentation. It enumerates remote systems, mapped network shares, and ARP information to identify additional targets and propagate across the environment. For destructive impact, it overwrites files on local systems and remote shares, disables services, clears Windows event logs, and uses native Windows recovery-management utilities to delete or disable backup and recovery mechanisms before shutting down affected systems.
Olympic Destroyer is notable both for its operational timing and for deliberate false-flag elements intended to complicate attribution. Its design and deployment reflect Sandworm’s broader pattern of using destructive malware to create disruptive effects against high-visibility civilian and critical targets. In the Olympic incident, the malware was used to impair event operations rather than for financial gain, making it a prominent example of state-directed disruptive cyber sabotage against a major international sporting event.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The US Department of Justice attributed KillDisk, Industroyer, NotPetya, and Olympic Destroyer operations to GRU officers associated with the unit.
DOJ tied Unit 74455 officers to BlackEnergy, Industroyer, KillDisk, NotPetya, and Olympic Destroyer.
Pyeongchang Winter Olympics 2018 Olympic Destroyer wiper; attributed to Razing Ursa (aka GRU Unit 74455, Sandworm) ... Wi-Fi at opening ceremony, Olympics website, ticketing, broadcast drones disabled. 300+ systems compromised.
The GRU’s malign cyber activities include deployment of the NotPetya and Olympic Destroyer malware; intrusions targeting the Organization for the Prohibition of Chemical Weapons and the World Anti-Doping Agency; cyber attacks on government systems and critical infrastructure in Ukraine and the state of Georgia; and hack-and-leak operations targeting elections in the United States and France.
"...false flags were planted in the case of the Olympic Destroyer malware that was employed by the Russian-attributed Sandworm Advanced Persistent Threat (APT) group against the 2018 Winter Olympics in Pyeongchang, South Korea..."
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Multiple actors and tools are described as using Mimikatz/Windows Credential Editor/LaZagne/ProcDump to “dump credentials,” often by targeting LSASS memory (e.g., “used Mimikatz to capture and use legitimate credentials,” “dumped the LSASS process memory using the MiniDump function,” “injecting itself into lsass.exe”).
Olympic Destroyer contains a module that tries to obtain credentials from LSASS, similar to Mimikatz. These credentials are used with PsExec and Windows Management Instrumentation to help the malware propagate itself across a network.
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
Olympic Destroyer uses PsExec to interact with the ADMIN$ network share to execute commands on remote systems.
On March 11, 2026, the MOIS-affiliated Handala Hack Team (also tracked as Void Manticore) executed a destructive wiper attack against U.S. medical technology company Stryker, abusing the company’s own Microsoft Intune MDM platform to push the payload.
Olympic Destroyer uses the API call ChangeServiceConfigW to disable all services on the affected system.
Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.
The Olympic Destroyer malware caused issues during the Opening Ceremony, including taking down Wi-Fi networks, ticketing systems, and contributing to flickering broadcast infrastructure.
The Olympic Destroyer malware caused issues during the Opening Ceremony, including taking down Wi-Fi networks, ticketing systems, and contributing to flickering broadcast infrastructure.
57 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive malware used in disruptive operations attributed to GRU Unit 74455, including the 2018 Winter Olympics attack.
Destructive malware/tooling family tied by DOJ to GRU Unit 74455.
Destructive wiper malware used to disrupt event operations, including Wi-Fi, ticketing systems, official apps, and websites during the PyeongChang 2018 Winter Olympics.
Destructive wiper malware used during the 2018 Pyeongchang Winter Olympics to disrupt Wi-Fi, ticketing, websites, and other event systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.