OlympicDestroyer is here to trick the industry
2018-03-08 • Kaspersky •
https://securelist.com/olympicdestroyer-is-here-to-trick-the-industry/84295/
Kaspersky analyzed OlympicDestroyer as a destructive worm used against Pyeongchang Winter Olympics infrastructure and related organizations, disrupting Wi-Fi, ticketing, displays, and other IT systems. The malware combined credential theft, PsExec-based propagation, and a wiper that targeted remote network shares, cleared event logs, deleted shadow copies, disabled recovery options, stopped services, and rebooted systems. The investigation connected the incident to earlier spearphishing against Winter Olympics targets that used weaponized Office documents, PowerShell downloaders, RC4-based backdoors, and similar URL and cookie structures. The report explicitly warns against quick attribution because the operation contained false flags and only notes that other researchers observed similarities to BlueNorOff/Lazarus-linked loader code, rather than assigning responsibility to a DPRK actor.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 3c0d740347b0362331c882c2dee96dbf | 2018-03-08 | 2020-03-09 |
| HASH | 221c6db5b60049e3f1cdbb6212be7f41 | 2018-03-08 | 2018-03-08 |
| HASH | 0311cec923c57a435e735e106517797f | 2018-03-08 | 2018-03-08 |
| HASH | 567d379b87a54750914d2f0f6c3b6571 | 2018-03-08 | 2018-03-08 |
| HASH | 5ba7ec869c7157efc1e52f5157705867 | 2018-03-08 | 2018-03-08 |
| HASH | 104ecbc2746702fa6ecd4562a867e7fb | 2018-03-08 | 2018-03-08 |
| HASH | 58dd6099f8df7e5509cee3cb279d74d5 | 2018-03-08 | 2018-03-08 |
| HASH | 4f43f03783f9789f804dcf9b9474fa6d | 2018-03-08 | 2018-03-08 |
| HASH | 19c539ff2c50a0efd52bb5b93d03665a | 2018-03-08 | 2018-03-08 |
| HASH | 6b728d2966194968d12c56f8e3691855 | 2018-03-08 | 2018-03-08 |
| HASH | 12668f8d072e89cf04b9cbcd5a3492e1 | 2018-03-08 | 2018-03-08 |
| HASH | 3514205d697005884b3564197a6e4a34 | 2018-03-08 | 2018-03-08 |
| HASH | 7c3bf9ab05dd803ac218fc7084c75e96 | 2018-03-08 | 2018-03-08 |
| HASH | 583f05b4f1724ed2ebfd06dd29064214 | 2018-03-08 | 2018-03-08 |
| HASH | 86d1a184850859a6a4d1c35982f3c40e | 2018-03-08 | 2018-03-08 |
| HASH | 47e67d1c9382d62370a0d71fecc5368b | 2018-03-08 | 2018-03-08 |
| HASH | 51545abcf4f196095ed102b0d08dea7e | 2018-03-08 | 2018-03-08 |
| HASH | 59c3f3f99f44029de81293b1e7c37ed2 | 2018-03-08 | 2018-03-08 |
| HASH | 64aa21201bfd88d521fe90d44c7b5dba | 2018-03-08 | 2018-03-08 |
| HASH | 83d8d40f435521c097d3f6f4d2358c67 | 2018-03-08 | 2018-03-08 |
| HASH | 4c8fa3731efd2c5097e903d50079a44d | 2018-03-08 | 2018-03-08 |
| HASH | 68970b2cd5430c812bef5b87c1add6ea | 2018-03-08 | 2018-03-08 |
| HASH | 52775f24e230c96ea5697bca79c72c8e | 2018-03-08 | 2018-03-08 |
| HASH | 65c024d60af18ffab051f97ccddfab7f | 2018-03-08 | 2018-03-08 |
| HASH | 5778d8ff5156de1f63361bd530e0404d | 2018-03-08 | 2018-03-08 |
| HASH | 6e0ebeeea1cb00192b074b288a4f9cfe | 2018-03-08 | 2018-03-08 |
| [email protected] | 2018-03-08 | 2018-03-08 | |
| [email protected] | 2018-03-08 | 2018-03-08 | |
| DOMAIN | monovm.mars.orderbox-dns.com | 2018-03-08 | 2018-03-08 |
| DOMAIN | pyeongchang2018.com | 2018-03-08 | 2018-03-08 |
| DOMAIN | alpensiaresort.co.kr | 2018-03-08 | 2018-03-08 |
| DOMAIN | krovy-sk.com | 2018-03-08 | 2018-03-08 |
| DOMAIN | monovm.venus.orderbox-dns.com | 2018-03-08 | 2018-03-08 |
| DOMAIN | kuhlekt.com | 2018-03-08 | 2018-03-08 |
| DOMAIN | wertprojekt.com | 2018-03-08 | 2018-03-08 |
| DOMAIN | samikdisplay.co.kr | 2018-03-08 | 2018-03-08 |
| DOMAIN | sports.or.kr | 2018-03-08 | 2018-03-08 |
| DOMAIN | bcel-kt.com | 2018-03-08 | 2018-03-08 |
| DOMAIN | okc-sk.com | 2018-03-08 | 2018-03-08 |
| DOMAIN | esco-posco.co.kr | 2018-03-08 | 2018-03-08 |
| DOMAIN | atos.net | 2018-03-08 | 2018-03-08 |
| DOMAIN | ppcom.kr | 2018-03-08 | 2018-03-08 |
| DOMAIN | sk.com | 2018-03-08 | 2018-03-08 |
| DOMAIN | gnah.co.kr | 2018-03-08 | 2018-03-08 |
| DOMAIN | tkad.co.kr | 2018-03-08 | 2018-03-08 |
| DOMAIN | kt.com | 2018-03-08 | 2018-03-08 |
| DOMAIN | monovm.mercury.orderbox-dns.com | 2018-03-08 | 2018-03-08 |
| DOMAIN | monovm.earth.orderbox-dns.com | 2018-03-08 | 2018-03-08 |
| DOMAIN | airport.co.kr | 2018-03-08 | 2018-03-08 |
| HASH | 5d0ffbc8389f27b0649696f0ef5b3cfe | 2016-05-27 | 2018-03-08 |