LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0365: Olympic Destroyer

Olympic Destroyer is malware that was used by Sandworm Team against the 2018 Winter Olympics, held in Pyeongchang, South Korea. The main purpose of the malware was to render infected computer systems inoperable. The malware leverages various native Windows utilities and API calls to carry out its destructive tasks. Olympic Destroyer has worm-like features to spread itself across a computer network in order to maximize its destructive impact.[1][2]

EnterpriseS0365MalwareObject v2.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Olympic Destroyer matters because it represents destructive Windows malware designed to make infected systems inoperable and spread across a network to maximize disruption. For leaders, the key decision is not just whether a signature exists, but whether the organization can detect credential theft, lateral movement over Windows administration channels, service disruption, recovery inhibition, log clearing, and rapid destructive activity before business operations are affected.

Executive priority

Treat this as an operational resilience and incident-readiness scenario. The supplied ATT&CK relationships connect Olympic Destroyer to credential access, discovery, SMB/admin share movement, WMI and service execution, lateral file transfer, data destruction, service stopping, recovery inhibition, reboot/shutdown, and Windows event log clearing. Executives should ask whether critical Windows environments have segmented administration paths, protected credentials, recoverable backups, and SOC playbooks for destructive malware. This is also useful evidence for audit and compliance discussions around backup integrity, privileged access control, logging retention, and incident response readiness.

Technical view

For SOC, detection engineering, and IR teams, validate coverage across the full behavior chain rather than relying on one malware indicator. On Windows, prioritize telemetry for LSASS access, browser credential store access, network and share discovery, SMB/admin share usage, WMI execution, service-control execution, internal file transfer, service termination, recovery-feature tampering, shutdown/reboot activity, and Windows event log clearing. Because MITRE provides no official detection text for this software object, detections should be derived from the linked ATT&CK techniques and tested against local administrative baselines to separate legitimate operations from destructive or worm-like propagation patterns.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry for native utilities and administrative tools
  • EDR or OS telemetry showing suspicious access to LSASS process memory
  • File and registry activity related to browser credential stores where collected
  • SMB and Windows admin share access logs, including remote file copy behavior
  • WMI operational logs and remote execution evidence

Detection direction

  • Correlate credential-access signals with subsequent SMB, WMI, service execution, or admin share activity; single events may be legitimate, but chained activity increases concern.
  • Baseline legitimate Windows administration, software deployment, backup, and helpdesk behavior to reduce false positives around WMI, service control, and SMB file copy.
  • Monitor for destructive-impact precursors: service stopping, recovery inhibition, log clearing, and coordinated shutdown/reboot activity, especially across multiple systems.
  • Validate whether logs remain available when Windows Event Logs are cleared; forward critical telemetry off-host where feasible.
  • Test visibility for lateral movement over Windows admin shares and internal tool transfer, since these can blend into normal administration.

Mitigation priorities

  • Prioritize resilient backups and recovery processes that are protected from routine administrative compromise and periodically tested for restoration.
  • Harden privileged access to Windows systems, especially credentials that can access LSASS-protected material, admin shares, WMI, and service control functions.
  • Segment critical Windows networks and restrict lateral movement paths such as SMB/admin shares and remote management interfaces to approved administrative sources.
  • Reduce credential exposure in browsers and on endpoints where feasible, and enforce least privilege for users and administrators.
  • Centralize and protect logs so event clearing on a host does not eliminate investigation evidence.
Additional notes and limits

The strongest defensive value is in mapping Olympic Destroyer to a destructive intrusion pattern: credential collection, discovery, lateral movement, execution through Windows administration mechanisms, and impact actions that impair systems and recovery. The object is associated through ATT&CK with Sandworm Team and was used against the 2018 Winter Olympics, but local investigations still require independent evidence before making attribution claims.

The official malware object lists Windows as the platform but does not provide official detection guidance, aliases, labels, or object-level tactics. Some related techniques list broader platforms in ATT&CK; this take only treats Olympic Destroyer as supported on Windows per the supplied malware platform field. Control and detection recommendations require validation against local logging, endpoint coverage, administrative practices, and recovery architecture.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Olympic Destroyer

Olympic Destroyer is malware that was used by Sandworm Team against the 2018 Winter Olympics, held in Pyeongchang, South Korea. The main purpose of the malware was to render infected computer systems inoperable. The malware leverages various native Windows utilities and API calls to carry out its destructive tasks. Olympic Destroyer has worm-like features to spread itself across a computer network in order to maximize its destructive impact.[1][2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

14 rows
DomainIDNameRelationship / procedure
EnterpriseT1016System Network Configuration Discovery

Olympic Destroyer uses API calls to enumerate the infected system's ARP table.[1]

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

Olympic Destroyer contains a module that tries to obtain stored credentials from web browsers.[1]

EnterpriseT1489Service Stop

Olympic Destroyer uses the API call ChangeServiceConfigW to disable all services on the affected system.[1]

EnterpriseT1529System Shutdown/Reboot

Olympic Destroyer will shut down the compromised system after it is done modifying system configuration settings.[1][2]

EnterpriseT1685.005Clear Windows Event LogsSub-technique

Olympic Destroyer will attempt to clear the System and Security event logs using wevtutil.[1]

EnterpriseT1485Data Destruction

Olympic Destroyer overwrites files locally and on remote shares.[1][2]

EnterpriseT1570Lateral Tool Transfer

Olympic Destroyer attempts to copy itself to remote machines on the network.[1]

EnterpriseT1047Windows Management Instrumentation

Olympic Destroyer uses WMI to help propagate itself across a network.[1]

EnterpriseT1018Remote System Discovery

Olympic Destroyer uses Windows Management Instrumentation to enumerate all systems in the network.[1]

EnterpriseT1135Network Share Discovery

Olympic Destroyer will attempt to enumerate mapped network shares to later attempt to wipe all files on those shares.[1]

EnterpriseT1569.002Service ExecutionSub-technique

Olympic Destroyer utilizes PsExec to help propagate itself across a network.[1]

EnterpriseT1021.002SMB/Windows Admin SharesSub-technique

Olympic Destroyer uses PsExec to interact with the ADMIN$ network share to execute commands on remote systems.[1][3]

EnterpriseT1490Inhibit System Recovery

Olympic Destroyer uses the native Windows utilities vssadmin, wbadmin, and bcdedit to delete and disable operating system recovery features such as the Windows backup catalog and Windows Automatic Repair.[1]

EnterpriseT1003.001LSASS MemorySub-technique

Olympic Destroyer contains a module that tries to obtain credentials from LSASS, similar to Mimikatz. These credentials are used with PsExec and Windows Management Instrumentation to help the malware propagate itself across a network.[1]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0034: Sandworm Team

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.[1][2] This group has been active since at least 2009.[3][4][5][6]

In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.[1][2] Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.[7]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.0
Created
Modified
Raw hash
cefd0038d3ff74ed...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.0Current bundlecefd0038d3ff…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  2. [2]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  3. [3]
    PsExec Russinovich

    Russinovich, M. (2004, June 28). PsExec. Retrieved December 17, 2015.

  4. [4]
    CrowdStrike GTR 2019

    CrowdStrike. (2019, January). 2019 Global Threat Report. Retrieved June 10, 2020.

    Open source URL
  5. [5]
    Secureworks IRON VIKING

    Secureworks. (2020, May 1). IRON VIKING Threat Profile. Retrieved June 10, 2020.

    Open source URL
  6. [6]
    UK NCSC Olympic Attacks October 2020

    UK NCSC. (2020, October 19). UK exposes series of Russian cyber attacks against Olympic and Paralympic Games . Retrieved November 30, 2020.

    Open source URL
  7. [7]
    Trend Micro Cyclops Blink March 2022

    Haquebord, F. et al. (2022, March 17). Cyclops Blink Sets Sights on Asus Routers. Retrieved March 17, 2022.

    Open source URL
  8. [8]
    mandiant_apt44_unearthing_sandworm

    Roncone, G. et al. (n.d.). APT44: Unearthing Sandworm. Retrieved July 11, 2024.

    Open source URL
  9. [9]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  10. [10]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  11. [11]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  12. [12]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  13. [13]
    mitre-attackS0365
    Open source URL
  14. [14]
    mitre-attackS0365
    Open source URL
  15. [15]
    mitre-attackS0365
    Open source URL
  16. [16]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  17. [17]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  18. [18]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  19. [19]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  20. [20]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  21. [21]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  22. [22]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  23. [23]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  24. [24]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  25. [25]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  26. [26]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  27. [27]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  28. [28]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  29. [29]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  30. [30]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  31. [31]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  32. [32]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  33. [33]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  34. [34]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  35. [35]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  36. [36]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  37. [37]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  38. [38]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  39. [39]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  40. [40]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  41. [41]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  42. [42]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  43. [43]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  44. [44]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  45. [45]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.