/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Researchers: cyberattack caused disruption to Pyeongchang2018.com and local internet, which grounded drones and more during Winter Olympics' opening ceremony

UPDATED USA Today : Olympic officials: Winter Games hit with cyber attack during opening ceremony Motherboard : Researchers: We Found the Olympic-Disrupting Malware Alfred Ng / CNET : Winter Olympics cyberattack designed to cause chaos Tweets: Darien Huss / @darienhuss : Olympic Destroyer, published on by @SecurityBeard and @r00tbsd , uses AES-CBC mode 32-byte key of md5sum('123')*2 with 16-byte null IV to protect resources 101-105. Script to decrypt resources: http://pastebin.com/... Blog: http://blog.talosintelligence.com/ ... Sample: http://www.virustotal.com/... http://twitter.com/... Kevin Beaumont / @gossithedog : There's a lot to digest in this report from @SecurityBeard et all about malware used in Olympic attack - but key headlines - they had 44 employee AD credentials, used psexec and WMI for lateral movement (ala Petya) and do interesting destruction things http://blog.talosintelligence.com/ ... http://twitter.com/... Nicole Perlroth / @nicoleperlroth : A short thread on Olympic cyberattack. 1. Pyeongchang organizers confirmed that Friday's #OpeningCeremony wifi outages (which took out wifi, grounded drones, made it impossible for people to print their reservations, and led to empty seats) was the result of a cyberattack. Nicole Perlroth / @nicoleperlroth : 4. Here's the weird part. Even though attackers' code clearly demonstrated the ability to “brick” Olympic computers i.e. outright destroy them, the attackers stopped short of pulling their final punch. They erased back-up Windows files and boot up configuration, but stopped short Nicole Perlroth / @nicoleperlroth : 2. Forensics show the attackers were out to disrupt the games since at least December 27, when timestamps show they created a destructive payload, at 11:39 AM UTC, which converts to 6:39 AM ET, 2:39 PM in Moscow and 8:39 PM in South Korea. Nicole Perlroth / @nicoleperlroth : 5. Why? Some at Cisco Talos tell me this was presumably to send a political message that the damage could have been a lot worse. They could have bricked their machines, but instead left open the possibility that organizers could still recover... (insert Jaws music) THIS TIME. Nicole Perlroth / @nicoleperlroth : 3. From the outset, attackers made clear who they were out to disrupt. The word http://Pyeongchang2018.com was hardcoded into their payload, as were multiple sets of stolen credentials for Pyeongchang organizers, which enabled attackers to spread their payload across Olympic network

New York Times Nicole Perlroth

Context & Ripple Effects

The disruption at the opening ceremony was not an accident of scale but a planned strike: forensic work shows a destructive payload built on December 27, 2017, weeks before the Games, which researchers named Olympic Destroyer. It hardcoded Pyeongchang2018.com, moved laterally using 44 stolen Active Directory credentials via psexec and WMI, wiped Windows backups and boot configuration, then stopped short of fully bricking machines — sabotage calibrated to disrupt, not destroy.

Attribution is the contested layer: US officials later said Russian hackers breached several hundred machines while making it look like a North Korean operation, and Wired's behind-the-scenes reporting tied the operation to a specific GRU unit. Cisco Talos's rapid publication of the malware sample and decryption script turned a mystery outage into one of the best-documented state attacks on a civilian event.

First-order effects

  • Pyeongchang organizers confirmed the ceremony's wifi outages, grounded drones, and ticketing failures were cyberattack-caused — spectators and broadcasters lost connectivity at the moment of maximum visibility.
  • Cisco Talos researchers published the sample and a decryption script within days, giving defenders the exact AES-CBC parameters and letting affected systems recover encrypted resources.

Second-order effects

  • The false-flag design forced investigators to spend months untangling attribution before US officials and Wired's GRU reporting settled it — raising the cost of every future response decision made on initial indicators.
  • Operators of comparable public-facing networks took note: Russian group Energetic Bear's breach of San Francisco airport Wi-Fi showed the same appetite for visible civilian infrastructure, pushing venue and transit operators toward credential-hardening over perimeter defense.

Third-order effects

  • If the pattern holds, destructive malware paired with harvested credentials becomes the standard playbook for state actors seeking disruption with deniability — shifting defender investment from malware signatures to identity and lateral-movement controls.
  • Attacks on globally televised events blur the line between espionage and coercion, pressuring governments to treat critical-event networks as critical infrastructure even when no lives are directly at stake.

The trend: State-sponsored hacking is shifting from quiet intelligence gathering toward disruptive strikes on high-visibility civilian events, with deliberate misattribution as a core feature rather than an afterthought.

Discussion

  • @nicoleperlroth Nicole Perlroth on x
    A short thread on Olympic cyberattack. 1. Pyeongchang organizers confirmed that Friday's #OpeningCeremony wifi outages (which took out wifi, grounded drones, made it impossible for people to print their reservations, and led to empty seats) was the result of a cyberattack.
  • @darienhuss Darien Huss on x
    Olympic Destroyer, published on by @SecurityBeard and @r00tbsd , uses AES-CBC mode 32-byte key of md5sum('123')*2 with 16-byte null IV to protect resources 101-105. Script to decrypt resources: http://pastebin.com/... Blog: http://blog.talosintelligence.com/ ... Sample: http://ww…
  • @gossithedog Kevin Beaumont on x
    There's a lot to digest in this report from @SecurityBeard et all about malware used in Olympic attack - but key headlines - they had 44 employee AD credentials, used psexec and WMI for lateral movement (ala Petya) and do interesting destruction things http://blog.talosintelligen…
  • @nicoleperlroth Nicole Perlroth on x
    4. Here's the weird part. Even though attackers' code clearly demonstrated the ability to “brick” Olympic computers i.e. outright destroy them, the attackers stopped short of pulling their final punch. They erased back-up Windows files and boot up configuration, but stopped short
  • @nicoleperlroth Nicole Perlroth on x
    2. Forensics show the attackers were out to disrupt the games since at least December 27, when timestamps show they created a destructive payload, at 11:39 AM UTC, which converts to 6:39 AM ET, 2:39 PM in Moscow and 8:39 PM in South Korea.
  • @nicoleperlroth Nicole Perlroth on x
    5. Why? Some at Cisco Talos tell me this was presumably to send a political message that the damage could have been a lot worse. They could have bricked their machines, but instead left open the possibility that organizers could still recover... (insert Jaws music) THIS TIME.
  • @nicoleperlroth Nicole Perlroth on x
    3. From the outset, attackers made clear who they were out to disrupt. The word http://Pyeongchang2018.com was hardcoded into their payload, as were multiple sets of stolen credentials for Pyeongchang organizers, which enabled attackers to spread their payload across Olympic netw…