SwiftSlicer is a destructive Windows wiper written in Go and publicly linked to Sandworm, the Russian GRU-associated threat actor also tracked as APT44 and Seashell Blizzard. It was identified in January 2023 during attacks against organizations in Ukraine, including local government entities. The malware has been associated with Sandworm’s broader pattern of disruptive and destructive operations against Ukrainian targets, particularly in campaigns that combine domain compromise, centralized deployment, and rapid system destruction.
SwiftSlicer is designed to render systems unusable by deleting shadow copies, overwriting files with randomly generated data, and forcing a reboot after completing its destructive actions. Reported behavior includes recursive overwriting of files in key Windows system areas, Active Directory database-related locations, and on non-system drives. Its overwrite routine uses fixed-size blocks filled with random bytes, indicating an intent to corrupt both operating system components and organizational data rather than to support extortion or recovery.
Observed deployment via Active Directory Group Policy indicates operation after compromise of the victim’s domain environment and suggests the attackers had obtained high-privilege control over enterprise administration infrastructure. This deployment pattern aligns with Sandworm tradecraft seen in multiple wiper incidents in Ukraine, where destructive payloads are pushed centrally across Windows estates once administrative control has been established.
SwiftSlicer fits Sandworm’s long-running sabotage-focused malware portfolio, which has included other wipers and disruptive tooling used against Ukrainian government, energy, media, and other critical or public-sector organizations. Its role is post-compromise destruction rather than covert persistence or espionage collection, and its operational context strongly indicates use in state-aligned disruptive campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dubbed SwiftSlicer, the destructive malware was spotted on the network of a targeted organization on January 25th. It was deployed through Group Policy, which suggests that the attackers had taken control of the victim’s Active Directory environment.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
In two recent major geopolitical conflicts, in Ukraine and in Israel, wipers - malware used to destroy access to files and commonly used to halt telecom operations - were used to destroy digital infrastructure.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in a list of wipers observed after AcidRain.
Wiper malware used against Ukrainian infrastructure in Sandworm-linked campaigns.
Destructive wiper malware referenced in open-source Sandworm/APT44 campaign reporting.
A destructive wiper malware indicated by the executable name 'swiftslicer.exe' appearing in a Sysmon file deletion event.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.