Swift Slicer is a destructive Windows wiper used in targeted intrusions to render systems inoperable by overwriting critical files, including Windows drivers and other important system data. The malware has been associated with attacks against organizations in Ukraine and is characterized by impact-focused behavior rather than espionage or monetization through encryption. Its destructive activity is comparable to other modern wipers such as CaddyWiper.
Observed deployment involved delivery through Group Policy Objects, indicating use after the attackers had already compromised the victim Active Directory environment and obtained sufficient administrative control to push the malware across Windows hosts. This makes Swift Slicer primarily a post-compromise destructive payload used late in the intrusion lifecycle. Its operational objective is system disruption and data destruction, with file-overwriting behavior intended to leave affected machines unbootable or otherwise unusable.
Swift Slicer is notable as a targeted enterprise wiper rather than commodity malware. Defensive monitoring has focused on behaviors consistent with destructive file operations on Windows endpoints, including unusual file overwrite or deletion patterns that may precede or accompany broad operational disruption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated Analytic Story ... Crypto Stealer Azorult Swift Slicer AgentTesla Qakbot Remcos ...
Destructive malware/wiper referenced as associated with file deletion activity.
Swift Slicer is referenced as destructive malware in suspicious execution and driver-loading detections.
A named malware sample referenced in a Splunk attack simulation dataset. Based on the name and public usage, Swift Slicer is a destructive wiper malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.