/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

A behind-the-scenes account of a cyberattack that disrupted the opening ceremony of the 2018 Winter Olympics, which was tied to a specific unit of Russia's GRU

How digital detectives unraveled the mystery of Olympic Destroyer—and why the next big attack will be even harder to crack. Tweets: @a_greenberg , @securitybeard , @matonis , @a_greenberg , @nxthompson , and @a_greenberg Tweets: Andy Greenberg / @a_greenberg : Wired has published another excerpt of my book SANDWORM, out 11/5. This piece tells the blow-by-blow story of how the most deceptive malware in history nearly crippled the 2018 Olympics—and how investigators ultimately tracked down the culprits behind it. https://www.wired.com/... Warren Mercer / @securitybeard : Check the write up from @r00tbsd and I when we first discovered Olympic Destroyer https://blog.talosintelligence.com/ ... and our attribution nightmare follow up https://blog.talosintelligence.com/ ... https://twitter.com/... Michael / @matonis : A pleasure to read about the various exploits and joyful trolls of security researchers. RICH Header research out of @kaspersky continues to be an unparalleled gem. https://twitter.com/... Andy Greenberg / @a_greenberg : This excerpt is told as an unfolding mystery, but I'm going to spoil the ending. So SPOILER ALERT: The cyberattack on the Olympics was directly tied via a command-and-control domain to the Russians who hacked two US states' boards of election in 2016: Unit 74455 of the GRU. Nicholas Thompson / @nxthompson : An amazing story that starts w one of the most confounding and brazen cyberattacks in history—and ends with @a_greenberg following breadcrumbs back to Russian hackers he's been tracking for 3 years. https://www.wired.com/... Andy Greenberg / @a_greenberg : Come for the inside story of the 12-hour race to rebuild the IT network of last year's Olympics after it was destroyed by hackers. Stay for the part where I went to Moscow to visit the building where those hackers were based. https://www.wired.com/... For your weekend reading!

Wired Andy Greenberg

Context & Ripple Effects

When Pyeongchang's opening ceremony went dark in February 2018, researchers could only describe the damage — Pyeongchang2018.com and local internet disruptions that grounded drones — while the attacker stayed hidden behind deliberately planted false clues. Andy Greenberg's SANDWORM excerpt, published ahead of the book's November release, now supplies the missing half: how digital detectives followed a command-and-control domain to tie Olympic Destroyer to GRU Unit 74455, the same unit that had hacked two US state election boards in 2016.

The piece matters because Olympic Destroyer was engineered to mislead its own investigators, and cracking it became a template for unmasking Moscow's covert units. The through-line runs forward too: the US and allies later exposed Cadet Blizzard as part of GRU Unit 29155, extending the same name-and-shame playbook to another GRU cell.

First-order effects

  • Attribution of Olympic Destroyer to GRU Unit 74455 collapses the malware's false-flag design and formally connects the Olympics sabotage to the unit behind the 2016 US state election board hacks.

Second-order effects

  • The investigative method Greenberg documents — following infrastructure rather than code signatures — feeds directly into the kind of US tech-company, NATO-intel, and Ukrainian-hacker cooperation that later helped blunt Russia's offensive cyber operations in Ukraine.

Third-order effects

  • Public, unit-level attribution is hardening into a standing countermeasure: once GRU cells can be named, as with Unit 29155's exposure via Cadet Blizzard, each new operation carries diplomatic cost, which is why the article's warning that the next big attack will be even harder to crack points toward an escalating forensics-versus-deception arms race.

The trend: State-sponsored cyber operations are shifting from deniable disruption to named-unit accountability, as forensic investigators and allied governments turn attribution itself into a deterrent against the GRU.

Discussion

  • @a_greenberg Andy Greenberg on x
    Wired has published another excerpt of my book SANDWORM, out 11/5. This piece tells the blow-by-blow story of how the most deceptive malware in history nearly crippled the 2018 Olympics—and how investigators ultimately tracked down the culprits behind it. https://www.wired.com/..…
  • @securitybeard Warren Mercer on x
    Check the write up from @r00tbsd and I when we first discovered Olympic Destroyer https://blog.talosintelligence.com/ ... and our attribution nightmare follow up https://blog.talosintelligence.com/ ... https://twitter.com/...
  • @matonis Michael on x
    A pleasure to read about the various exploits and joyful trolls of security researchers. RICH Header research out of @kaspersky continues to be an unparalleled gem. https://twitter.com/...
  • @a_greenberg Andy Greenberg on x
    This excerpt is told as an unfolding mystery, but I'm going to spoil the ending. So SPOILER ALERT: The cyberattack on the Olympics was directly tied via a command-and-control domain to the Russians who hacked two US states' boards of election in 2016: Unit 74455 of the GRU.
  • @nxthompson Nicholas Thompson on x
    An amazing story that starts w one of the most confounding and brazen cyberattacks in history—and ends with @a_greenberg following breadcrumbs back to Russian hackers he's been tracking for 3 years. https://www.wired.com/...
  • @a_greenberg Andy Greenberg on x
    Come for the inside story of the 12-hour race to rebuild the IT network of last year's Olympics after it was destroyed by hackers. Stay for the part where I went to Moscow to visit the building where those hackers were based. https://www.wired.com/... For your weekend reading!