Olymp Loader has emerged as a new malware-as-a-service (MaaS) platform, rapidly gaining traction among low-tier cybercriminals due to its turnkey nature and advanced technical features. The service, first launched in June 2025 as a botnet tool, quickly pivoted to a loader-as-a-service model by August, enabling users to stealthily deliver additional malware payloads to compromised systems. Olymp Loader is fully written in assembly language, which contributes to its claims of being fully undetectable (FUD) by antivirus solutions, a feature heavily marketed by its operator known as 'OLYMPO.' The loader's undetectability is further supported by low detection rates on VirusTotal, as observed by security researchers from Outpost24. Frequent uploads of Olymp samples to VirusTotal, likely by OLYMPO and their clients, have allowed researchers to track the malware's rapid evolution and feature expansion. Early versions of Olymp Loader incorporated built-in stealer modules, including a Telegram stealer, browser stealer, and crypto stealer, broadening its appeal to threat actors seeking to harvest sensitive information. The browser stealer component is based on the open-source BrowserSnatch project, while the crypto stealer targets a wide range of cryptocurrency wallets such as Exodus, Electrum, Atomic, Guarda, Wasabi, Monero, BitcoinCore, and ZelCore. Olymp Loader supports the delivery of custom payloads across multiple formats, including 32-bit, 64-bit, .NET, Java, and native executables, with LummaC2 and WebRAT being the most commonly observed post-infection payloads. In late June, the service began offering personal builds with custom payloads embedded for an additional fee, and by late August, it introduced a crypter feature, which has become its most popular offering. The operator has announced plans to expand the service further, potentially bundling botnet, loader, crypter, installs service, and file-scanning tools into a comprehensive package. Olymp Loader is primarily advertised on underground forums such as HackForums and Telegram, where its official channel has attracted nearly a hundred subscribers. The pricing model has evolved alongside the feature set, with costs ranging from $40 to $200 per stub depending on customization and included features. The loader's accessibility, technical sophistication, and ongoing development make it a significant threat, particularly for organizations concerned about information theft and malware delivery. Security professionals are advised to monitor for Olymp Loader activity and implement robust endpoint protection measures to mitigate the risk posed by this rapidly evolving MaaS platform. The emergence of Olymp Loader underscores the increasing commoditization of sophisticated malware tools, lowering the barrier to entry for cybercriminals and amplifying the threat landscape.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On September 30, 2025, reporting based on Outpost24 research publicly detailed Olymp Loader's emergence, technical evolution, and growing popularity among low-tier cybercriminals. The disclosure also noted one case where Olymp was delivered as a second-stage payload by Amadey.
As the service evolved in recent months, Outpost24 observed Olymp supporting multiple payload types and commonly delivering LummaC2 and WebRAT. The malware also used evasion methods including code-cave injection, XOR encryption, Defender exclusions, and code signing, and was disguised as legitimate software such as Node.js, PuTTY, OpenSSL, and Zoom.
By late August 2025, the operators had added a crypter feature and offered paid personal builds, reflecting rapid capability growth and commercialization. The service was also being advertised on HackForums and Telegram, with pricing increasing over time.
In August 2025, Olymp shifted into a loader-as-a-service offering designed to stealthily deliver additional malware payloads. Researchers noted it was written entirely in assembly language and marketed as fully undetectable by antivirus tools.
Outpost24 reported that Olymp first appeared in June 2025 as a botnet-focused malware service. Early samples uploaded to VirusTotal showed built-in stealer functions targeting Telegram, browsers, and cryptocurrency wallets.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.