logo

Olymp Loader: A new Malware-as-a-Service written in Assembly

ID: e4193475-0b1b-57ce-8492-d809e3536b93

STIX ID: report--e4193475-0b1b-57ce-8492-d809e3536b93

Feed Name: Outpost24 Blog

Threat Score
72/100

Date Published: 2025-09-26

Date Updated: 2026-04-28

Author: mpeintner

...
...

Olymp Loader is a commercially offered Malware-as-a-Service promoted by the actor "OLYMPO" since June 2025; marketed as an assembly-written, FUD loader/crypter with built-in stealer modules (browser, Telegram, crypto wallets), Defender-evasion features (exclusions, Defender removal), code signing, deep XOR obfuscation, and support for multiple payload types. The report documents distribution vectors (including abused GitHub releases and socially engineered installers), observed post‑infection payloads (LummaC2, WebRAT/SalatStealer, QasarRAT, Raccoon), technical behaviors, TTP mappings, and a set of IOCs (download URLs and file hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.