SwiftSlicer is a destructive Windows wiper written in Go and publicly documented by ESET in January 2023. ESET attributed its use to the Russian GRU-linked Sandworm threat group (also tracked as APT44, Seashell Blizzard, and Voodoo Bear) in attacks against Ukraine. It was detected on January 25, 2023 on the network of a targeted Ukrainian organization, including reporting that it was deployed against Ukrainian local government entities. The malware was deployed through Active Directory Group Policy, indicating the attackers likely had control of the victim’s AD environment. Once executed, SwiftSlicer deletes shadow copies, recursively overwrites files in %CSIDL_SYSTEM%\drivers, %CSIDL_SYSTEM_DRIVE%\Windows\NTDS, and on other non-system drives, using 4096-byte blocks filled with randomly generated bytes, and then reboots the infected machine. ESET detects it as WinGo/KillFiles.C. Supporting telemetry also shows an example of C:\Temp\swiftslicer.exe deleting C:\Python311\vcruntime140_1.dll on a Windows host. The malware is referenced in broader Sandworm destructive campaigns against Ukrainian infrastructure during 2022-2024.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dubbed SwiftSlicer, the destructive malware was spotted on the network of a targeted organization on January 25th. It was deployed through Group Policy, which suggests that the attackers had taken control of the victim’s Active Directory environment.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Once executed it deletes shadow copies, recursively overwrites files located in %CSIDL_SYSTEM%\drivers, %CSIDL_SYSTEM_DRIVE%\Windows\NTDS and other non-system drives and then reboots computer.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Wiper malware used against Ukrainian infrastructure in Sandworm-linked campaigns.
Destructive wiper malware referenced in open-source Sandworm/APT44 campaign reporting.
A destructive wiper malware indicated by the executable name 'swiftslicer.exe' appearing in a Sysmon file deletion event.
Destructive wiper malware written in Go. Once executed, it deletes shadow copies, recursively overwrites files in key system and non-system locations using randomly generated data blocks, and then reboots the computer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.