SwiftSlicer
SwiftSlicer (canonical ESET naming per January 27, 2023 disclosure.
ESET detection signature WinGo/ KillFiles.C) is a Go (Golang) programming language wiper deployed January 25, 2023 by Sandworm against an unnamed Ukrainian target via Active Directory Group Policy, the 6th Sandworm wiper strain targeting Ukraine since February 2022 invasion per Cybernews count.
Russian state-sponsored APT attribution to Sandworm (Russian GRU Unit 74455, also Mandiant APT44 / Microsoft Seashell Blizzard / CERT-UA UAC-0082 / Dragos ELECTRUM, curated separately as sandworm_team parent operator) via ESET canonical January 27, 2023 disclosure (Robert Lipovsky senior malware researcher ESET, per ESET Research Twitter thread: "On January 25th ESETResearch discovered a new cyberattack in Ukraine. Attackers deployed a new wiper we named SwiftSlicer using Active Directory Group Policy. The SwiftSlicer wiper is written in Go programming language. We attribute this attack to Sandworm") + CERT-UA UAC-0082 tracking.
standalone malware platform cluster paralleling prestige_ransomware + ransomboggs in 2023+ Sandworm destructive cyberweapon evolution cell.
cluster- defining destruction mechanism per ESET technical analysis: "Once executed it deletes shadow copies, recursively overwrites files located in %CSIDL_SYSTEM%\drivers, %CSIDL_SYSTEM_DRIVE%\Windows\ NTDS and other non-system drives and then reboots computer. For overwriting it uses 4096 bytes length block filled with randomly generated bytes"; cluster-defining Windows domain destruction intent via NTDS folder targeting, per Bleeping Computer: "the malware targets the %CSIDL_SYSTEM_DRIVE%\Windows\ NTDS folder, showing that SwiftSlicer tries to destroy files and bring down the entire Windows domain".
cluster-defining Active Directory Group Policy deployment via Domain Policy Modification (Group Policy Modification), same deployment tradecraft as HermeticWiper + CaddyWiper indicating domain controller compromise prerequisite per ESET: "deployed through Group Policy, which suggests that the attackers had taken control of the victim's Active Directory environment. Some of the wipers spotted by ESET in Ukraine early into Russia's invasion - HermeticWiper and CaddyWiper - were in some instances also planted in the same fashion" (cluster-cell coherence with v0.1.130 hermeticwiper.yaml + v0.1.130 caddywiper.yaml AD GPO deployment pattern)
cluster-defining Go (Golang) programming language wiper development per ESET + Bleeping Computer + Help Net Security, "Sandworm developed SwiftSlicer in Golang programming language, which has been adopted by multiple threat actors for its versatility, and it can be compiled for all platforms and hardware" (signature Sandworm tradecraft evolution toward cross-platform multi-OS destructive capability, distinct Go codebase from Prestige C++ + RansomBoggs .NET demonstrating Sandworm multi-language destructive capability); concurrent CERT-UA-disclosed Ukrinform Ukrainian National News Agency attack January 17-25, 2023 attributed to UAC-0082 (suspected Sandworm) deploying 5 different wipers (CaddyWiper + ZeroWipe + SDelete + AwfulShred + BidSwipe) targeting Windows + Linux + FreeBSD systems per CERT-UA Twitter "UAC-0082 (suspected Sandworm) to target Ukrinform using 5 variants of destructive software" (signature operational tempo + multi-OS multi-wiper signature late-January 2023)
VirusTotal submission January 26, 2023 (one day after detection) with ~half AV engines detecting at publication per Bleeping Computer (relatively rapid industry response); SentinelOne January 2024 "The Nightmare Of Destructive Malware | From Wiper To SwiftSlicer" by Natacha Bakir (Senthorus/Cefcys) consolidates SwiftSlicer as canonical illustration of wiper malware evolution from MeteorExpress to AcidRain to HermeticWiper to SwiftSlicer pattern.
Cybernews canonical 6th Sandworm wiper strain classification (HermeticWiper February 2022 + IsaacWiper February 2022 + HermeticRansom February 2022 + CaddyWiper March 2022 + DoubleZero March 2022 - SwiftSlicer January 2023 with Industroyer2 April 2022 + Prestige October 2022 + RansomBoggs November 2022 between)
ESET DynoWiper January 30, 2026 retrospective catalogs SwiftSlicer in chronological Sandworm destructive malware family (HermeticWiper + HermeticRansom + CaddyWiper + DoubleZero + ARGUEPATCH + ORCSHRED + SOLOSHRED + AWFULSHRED + Prestige ransomware + RansomBoggs ransomware + SDelete-based wipers + BidSwipe + ROARBAT + SwiftSlicer + NikoWiper + SharpNikoWiper + ZEROLOT + Sting wiper + ZOV wiper)
cluster fills Go-language wiper position in 2023+ Sandworm destructive cyberweapon evolution cell.
canonical illustration of Windows domain destruction via NTDS folder targeting + cross-platform Go-language wiper evolution + signature 4096-byte block overwrite tradecraft cited in essentially all subsequent Sandworm + Ukraine war + Go-language wiper + AD GPO wiper deployment industry analyses through 2023- 2026 period.