New Malware-as-a-Service Olymp Loader Promises Defender-Bypass With Automatic Certificate Signing
The cybersecurity sector has recently identified a new Malware-as-a-Service (MaaS) platform called Olymp Loader . Developed entirely in Assembly language, this platform has gained attention due to its advanced features and capabilities.
The cybersecurity sector has recently identified a new Malware-as-a-Service (MaaS) platform called Olymp Loader . Developed entirely in Assembly language, this platform has gained attention due to its advanced features and capabilities.
Olymp Loader, advertised initially in June 2025, has developed from a basic botnet concept into an advanced loader and crypter suite. Its architecture supports integration of credential stealers, crypters, and privilege escalation mechanisms. The platform is claimed to be Fully UnDetectable (FUD), designed to bypass modern antivirus engines and evade machine-learning–based heuristics.
Deep XOR encryption for payload modules UAC-Flood privilege escalation Automatic Windows Defender exclusions
As of August 5, 2025, Olymp Loader offers various pricing tiers starting from USD 50 for a basic stub to USD 200 for a fully customized injection service. All packages include features such as a Defender bypass, Defender-removal module, and automatic certificate signing.
The cybersecurity sector has recently identified a new Malware-as-a-Service (MaaS) platform called Olymp Loader .
Analysis by Outpost24 indicates multiple instances where Olymp Loader has been found masquerading as legitimate software. Examples include binaries distributed under the guise of NodeJs[.]exe on GitHub and fake installers for applications like OpenSSL, Zoom, PuTTY, and CapCut.
Upon execution, Olymp Loader follows a multi-stage process for persistence and defense evasion. Initially, it uses a batch script to copy itself to the AppData directory. By early August, enhancements included a Defender Remover module available on GitHub.
Creation of StartUp folder entry via PowerShell Execution of PowerRun[.]exe and RemoveSecHealthApp[.]ps1 scripts Addition of exclusion paths using Add-MpPreference Shellcode component utilizes LoadPE for code-cave injection
The combination of these methods, including script-based persistence, injection techniques, and automatic certificate signing, represents a significant advancement in MaaS offerings, increasing the potential for widespread cybercriminal activity.
Based on reporting by Cyber Security News.
