Researchers identified a Windows wiper malware campaign using Tokyo Olympics-themed lures, including an executable disguised as an urgent cyberattack damage report. The malware, a UPX-packed x86 console application written in C/C++, selectively deletes files from the user profile rather than wiping the full disk, targeting Office documents, PDFs, text and log files, executables, CSVs, and Japanese Ichitaro formats such as .jtd and .jtt, indicating likely interest in Japanese systems. Analysts reported at least two related samples uploaded in July 2021, including one destructive variant and another without wiper functionality.
The malware includes multiple anti-analysis features, checking for debuggers, sandbox or virtual-machine artifacts, malware analysis tools, and modified functions associated with hooks or breakpoints; if such conditions are detected, it exits and can delete itself. After wiping files, the sample also launches a curl request to an adult website, a behavior researchers said may have been intended to mislead investigators into attributing the infection to adult-site browsing. Fortinet said the malware showed no worming or propagation capability, and available reporting found no confirmed victims, delivery mechanism, or evidence tying it to Olympic Destroyer or a nation-state actor.

Get the actors, campaigns, and ATT&CK mapping behind it.
8 events from the most recent confirmed update back to the earliest known activity.
Researchers reported that the destructive Tokyo Olympics-themed malware sample was uploaded on July 20, 2021, including to VirusTotal/public repositories. The sample masqueraded as a PDF-themed urgent damage report and selectively deleted files from users' Windows profiles.
Cyble's analysis said the wiper malware sample was compiled as a C/C++ x86 console application on July 20, 2021. The sample was packed with UPX and disguised as an urgent Tokyo Olympics cyberattack damage report executable.
FortiGuard Labs reported that a related Tokyo Olympics-themed file using a PDF icon was uploaded to a public file repository. This July 17 sample shared similar functionality with the later malware but lacked destructive file-deletion capability.
Cyble Research Labs published a detailed analysis of the Tokyo Olympics-themed wiper, including anti-analysis behavior, file-targeting logic, SHA-256 indicators, and a YARA rule named win32_tokyoolympicdeleter. Cyble assessed the malware's primary purpose as deleting user files and then deleting itself.
FortiGuard Labs published analysis covering both Tokyo Olympics-themed samples, including the July 20 wiper and the July 17 related file. The report said the malware was not code-similar to Olympic Destroyer and that there was insufficient evidence of nation-state involvement.
A second sample of the Olympics-themed malware was discovered after the initial article was published. FortiGuard later described this broader set as including both the July 17 related sample and the July 20 wiper sample.
The Record reported on the newly discovered Olympics-themed wiper targeting Japanese PCs two days before the Tokyo Olympics opening ceremony. At that time, only one sample had been found, and the report highlighted its focus on Japanese file types such as Ichitaro documents.
Mitsui Bussan Secure Directions discovered and analyzed the Windows wiper shortly before the Tokyo Olympics opening ceremony. MBSD found anti-analysis and anti-VM checks, self-deletion behavior, and access to an adult site intended to mislead investigators.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
blog.cyble.com
Open sourcefortinet.com
Open sourcetherecord.media
Open sourcembsd.jp
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.