The malware dubbed Olympic Destroyer disrupted systems tied to the Pyeongchang Winter Olympics, knocking the Olympic website offline and degrading services including on-site Wi‑Fi for reporters during the opening ceremony. Researchers described it as a destructive, worm-like Windows malware built to maximize operational impact rather than steal data: it harvested browser and OS credentials, moved laterally with WMI and a legitimate signed PsExec binary, and spread through the environment using stolen administrative access.
Once deployed, the malware deleted shadow copies, backup catalogs, and event logs, disabled services and recovery features, wiped writable files on mapped shares, and shut down infected systems; analysts also found self-deletion behavior intended to hinder forensics, including code injection into notepad.exe. Multiple reports noted similarities to tools and tradecraft associated with Lazarus, APT3, APT10, NotPetya, and BadRabbit, but concluded those overlaps were inconclusive and may have been planted as false flags, leaving attribution unresolved without intelligence beyond malware artifacts.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
Talos published a follow-up attribution analysis concluding that available technical evidence did not support unambiguous attribution of Olympic Destroyer to a specific threat actor. The report argued the attacker likely planted false flags and that overlaps with Lazarus, APT3, APT10, and NotPetya were inconclusive.
MBSD released a detailed technical analysis of Olympic Destroyer, documenting its dropped components, self-deletion via notepad.exe injection, and the embedding of stolen credentials into propagated binaries. The report also noted similarities to NotPetya and BadRabbit while cautioning that these were not conclusive for attribution.
Talos published technical analysis of malware believed to have been used in the Olympic attack and identified it as Olympic Destroyer with moderate confidence. The report described credential theft, PsExec and WMI-based lateral movement, and destructive actions including wiping files, deleting backups, and shutting down systems.
The PyeongChang Olympic organizing committee publicly announced that the disruptions were caused by a cyberattack. This was the first explicit confirmation from organizers about the nature of the incident.
Internal system troubles at the PyeongChang Olympic organizing committee began around February 9, preceding public confirmation of the incident. The disruptions were later tied to the Olympic Destroyer attack.
During the 2018 Winter Olympics in Pyeongchang, a cyberattack knocked the Olympic website offline, prevented some ticket printing, and degraded on-site WiFi for reporters during the opening ceremony. Officials later confirmed the incident was caused by malware now known as Olympic Destroyer.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
blog.talosintelligence.com
Open sourcembsd.jp
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.