Just before eight in the evening on 9 February 2018, Sang-jin Oh was sitting in a plastic chair a few dozen rows above the floor of Pyeongchang's Olympic Stadium, waiting for the opening ceremony of the Winter Games to begin. He was the official responsible for the Olympics' technology, and he saw almost none of the ceremony, because his phone had filled with messages from staff watching the Games' servers die. The stadium wi-fi failed. Televisions and internet access in the main press centre stopped working. The official Pyeongchang 2018 website went down and stayed down for roughly twelve hours, which meant that spectators who had bought tickets could not print them and could not look up where they were meant to go.

Organisers spent 10 February saying only that they were investigating. On 11 February the spokesman Sung Baik-you confirmed that a cyber attack had taken place during the ceremony, said all issues had been resolved and recovered the previous morning, and added that the organising committee and the International Olympic Committee had decided together not to identify the source. The next day Cisco Talos published an analysis of the malware and gave it the name that stuck: Olympic Destroyer. It was a wiper rather than ransomware, written to delete boot configuration data and shadow copies, switch off services and leave machines unable to restart. It carried hardcoded credentials and used them to spread. Staff rebuilt the affected systems overnight, and the Games ran through to their closing ceremony without further public disruption.

The credentials belonged to Atos, the French company running the Games' IT, and researchers noted that some of the earliest samples uploaded to VirusTotal had come from France, where Atos is headquartered, and from Romania, where part of its security team worked — an indication that the company had been penetrated months before the ceremony. What made the malware historically important, though, was what else researchers found inside it. Some pointed at North Korea's Lazarus group, a reading that felt entirely natural nine months after WannaCry; others found code overlapping with Chinese-speaking actors; others still saw Russian workmanship, which Moscow denied, having already dismissed in advance any talk of "Russian fingerprints" on the Games. Every one of them was reading material the author had planted.

On 8 March 2018 Kaspersky Lab published the analysis that unpicked it. The strongest piece of Lazarus evidence was the malware's Rich header, a compiler fingerprint embedded in Windows executables, which matched a known Lazarus component exactly — and which, Kaspersky argued, had been forged, because it bore no relationship to the contents of the binary it sat inside. Someone had lifted a fingerprint off one file and pressed it onto another in order to frame a group. The answer arrived more than two and a half years later, when a federal grand jury in Pittsburgh returned an indictment on 15 October 2020, announced four days afterwards, charging six officers of Unit 74455 of Russia's GRU with Olympic Destroyer and with NotPetya. None of them has stood trial.

Also that month · 1.35 terabits per second

GitHub was offline for nine minutes

At 17:21 UTC on 28 February 2018, GitHub's monitoring picked up an anomaly and the site went dark; it was fully unavailable until 17:26 and intermittently unavailable until 17:30. Traffic peaked at 1.35 terabits per second and 126.9 million packets per second — the largest denial-of-service attack publicly recorded to that date, and more than twice the size of the Mirai flood that had knocked Krebs on Security offline in 2016. The technique was unfamiliar to most defenders: memcached, a caching service never intended to face the internet at all, answering spoofed UDP requests on port 11211 with replies up to roughly fifty thousand times larger than the query that provoked them. GitHub shifted its traffic to Akamai's Prolexic platform within five minutes of detection and afterwards published a timestamped incident report rather than a statement. Cloudflare, Arbor Networks and Qihoo 360 had all warned about the method in the preceding days. The record did not survive the week: on 5 March, NETSCOUT Arbor confirmed a 1.7 Tbps memcached attack against a customer of a US service provider, which reported no outage.

Also that month · Mining in other people's browsers

The data regulator's own website was mining Monero

At 11:14 GMT on Sunday 11 February 2018, a JavaScript file belonging to Browsealoud — an accessibility plugin from the Northern Irish firm Texthelp that reads web pages aloud for visually impaired users — was altered to inject Coinhive's Monero mining script into every browser that loaded it. The researcher Scott Helme was alerted by a friend who had triggered a malware warning on the website of the UK's Information Commissioner's Office, the country's data protection regulator, and traced the injection to 4,275 sites, among them uscourts.gov, NHS Inform in Scotland and Manchester City Council. Texthelp took the file down the same day pending investigation. Nine days later RedLock described the same appetite elsewhere: a Kubernetes console belonging to Tesla, reachable without a password, which had exposed the company's AWS credentials and was being used to mine, with the pool address hidden behind Cloudflare and processor use kept low to avoid notice. RedLock said it found the activity in late January and told Tesla at once; Tesla said it closed the hole within hours and that its initial investigation found no indication customer privacy or vehicle security had been affected.

India desk · February 2018

Two banks, one messaging system, two different crimes

On 6 February 2018 three payment instructions left City Union Bank's SWIFT terminal that nobody inside the bank had issued. The next day, during routine reconciliation, staff at the Kumbakonam lender found the three outward remittances, worth close to $2 million between them: $500,000 through Standard Chartered in New York to Dubai, €300,000 through Standard Chartered in Frankfurt to Turkey, and $1 million through Bank of America in New York to a bank in China. The first was blocked and recovered, the second blocked, the third collected by someone presenting forged documents. The bank disclosed it on 18 February, when its chief executive, N. Kamakodi, described an international conspiracy and said there was no evidence of internal staff involvement.

Four days earlier, on 14 February, Punjab National Bank had told the stock exchanges it had detected fraudulent transactions worth about ₹11,394 crore — roughly $1.77 billion — at one Mumbai branch. The two were reported together; they are not the same story. Nobody broke into PNB. Its own staff had issued letters of undertaking over SWIFT, guaranteeing overseas credit for firms connected to the jeweller Nirav Modi, without making the corresponding entries in the core banking system, so the liability lived in the messaging network and nowhere in the bank's books; PNB had complained to the CBI on 29 January, before the scale was clear, and the figure climbed to roughly ₹14,357 crore by May. Modi was arrested in London in March 2019; his extradition is still unresolved. One was an intrusion. The other was a reconciliation gap that a messaging terminal was allowed to walk through — which is why the Reserve Bank of India made integration of SWIFT with core banking systems a supervisory requirement rather than advice.

AI Tech desk · February 2018

The warning arrived after the deepfakes

On 20 February 2018, twenty-six researchers from Oxford's Future of Humanity Institute, Cambridge's Centre for the Study of Existential Risk, OpenAI, the Electronic Frontier Foundation and the Center for a New American Security published The Malicious Use of Artificial Intelligence, a survey of how the technology was likely to be turned against people in the digital, physical and political domains. It forecast spear phishing written automatically to fit its target and synthetic audio and video convincing enough to be believed — both now ordinary features of the incident reports this archive covers. The warning was not early by much. Reddit had closed r/deepfakes and r/deepfakeNSFW on 7 February, after Discord, Gfycat, Pornhub and Twitter took similar action; the subreddit was approaching ninety thousand subscribers when it went. Google put its Cloud TPU accelerators into beta on 12 February at $6.50 an hour, and Joy Buolamwini and Timnit Gebru presented Gender Shades at the Conference on Fairness, Accountability and Transparency in New York on 23 and 24 February, measuring commercial gender classifiers that failed most often on darker-skinned women.

Digital Guard desk · February 2018

Two hours to the second machine

CrowdStrike published its Global Threat Report on 26 February 2018 and gave the endpoint industry two numbers it kept. The first was breakout time — the interval between an intruder taking the first machine and moving laterally to a second — which it put at one hour and fifty-eight minutes across 2017, and has published every year since. The second was that thirty-nine per cent of the intrusions it observed involved no malware at all, leaving nothing for signature-based antivirus to find. Microsoft announced on 12 February that Windows Defender Advanced Threat Protection would be extended down to Windows 7 SP1 and Windows 8.1; the preview was promised for spring and general availability did not arrive until February 2019. The same day, Thoma Bravo completed its $1.6 billion all-cash purchase of Barracuda Networks, and Kaspersky Lab sued in Washington over the NDAA provision barring its software from federal agencies, calling it an unconstitutional bill of attainder and saying no evidence of wrongdoing had been produced. Vendor laboratories spent the rest of the month taking Olympic Destroyer apart.

⏳ Time capsule — February 2018

  • SpaceX flew Falcon Heavy for the first time on 6 February, sending a cherry-red Tesla Roadster and a mannequin called Starman into orbit around the Sun; the two side boosters landed simultaneously at Cape Canaveral while the centre core missed its drone ship.
  • North and South Korean athletes walked into the Pyeongchang opening ceremony on 9 February behind a single unification flag, and the two countries fielded a joint women's ice hockey team.
  • Jacob Zuma resigned as president of South Africa in a televised address on the evening of 14 February; Cyril Ramaphosa was sworn in the next day.
  • Black Panther opened in US cinemas on 16 February and took an estimated $202 million across its first three days, a record for a February release.
Where it stands today — 2026

The month the evidence lied

Olympic Destroyer is the reason this archive treats early attribution as a claim rather than a finding. Kaspersky's Rich header work turned a compiler artefact into contested evidence, and the industry's habit of publishing confidence levels instead of verdicts dates from roughly this point. The malware's operators surfaced again in mid-2018, when Kaspersky reported them targeting organisations working on chemical and biological threat prevention in Europe — a target list that made a great deal more sense for a Russian military unit than for Pyongyang. The 2020 indictment set the Games attack beside NotPetya and stated the motive plainly: retaliation for the banning of Russian athletes from competing under their own flag. The same unit walks back into these pages in February 2022, hours before the tanks.

The month's other threads resolved more quietly. Open memcached servers were closed, providers filtered port 11211, and the amplification record moved on within a week and has kept moving since; the shape of it — a service never meant to be reachable, reachable — is the one constant in every volumetric record this archive holds. Browser cryptomining died of economics rather than enforcement, Coinhive shutting down in March 2019 as Monero's value and mining yields fell, though the supply-chain lesson it taught, that one third-party script can rewrite thousands of sites at once, has been relearned every year since. And in India, February 2018 is where bank technology stopped being an internal matter and became something a regulator wrote rules about.