Wiper

Olympic Destroyer

First seen: 2018-02 • Status: inactive

Currently Inactive

Olympic Destroyer attacked the Winter Olympics in South Korea. Russia tried to make it look like North Korea or China did it.

Overview

Olympic Destroyer disrupted the 2018 PyeongChang Winter Olympics. It contained false flags to blame multiple countries. Attributed to Russia.

Also Known As

OlympicDestroyer

How It Spreads

  • Spear-phishing
  • Supply chain compromise

What It Does

  • Destroys backups
  • Wipes systems
  • Contains false flag code

Is your business exposed?

Target Platforms

Windows

Detection Tips

  • Watch for false flag indicators
  • Monitor Olympics infrastructure

MITRE ATT&CK Techniques

T1561, T1490

If You're Infected

  1. 1.

    Historical threat - used for analysis and attribution studies

Related Malware

Notpetya

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required