Researchers identify new data-wiping malware in cyberattack against Ukraine

TechSpot is about to celebrate its 25th anniversary. TechSpot means tech analysis and advice you can trust.

In a nutshell: Security researchers from ESET have identified a specific type of malware called SwiftSlicer deployed in recent attacks against Ukrainian targets. SwiftSlicer targets critical Windows operating system files and Active Directory (AD) databases. Based on the team’s findings, the malware can destroy operating system resources and cripple entire Windows domains.

The researchers identified the SwiftSlicer malware deployed during a cyberattack targeting Ukrainian technology outlets. The malware ware was written using a cross-platform language called Golang, better known as Go, and uses an Active Directory (AD) Group Policy attack vector.

#BREAKING On January 25th #ESETResearch discovered a new cyberattack in ???????? Ukraine. Attackers deployed a new wiper we named #SwiftSlicer using Active Directory Group Policy. The #SwiftSlicer wiper is written in Go programing language. We attribute this attack to #Sandworm. 1/3 pic.twitter.com/pMij9lpU5J

— ESET Research (@ESETresearch) January 27, 2023

The announcement notes that the malware identified as WinGo/Killfiles.C. On execution, SwiftSlicer deletes shadow copies and recursively overwrites files, then reboots the computer. It overwrites the data using 4,096 byte-length blocks comprised of randomly generated bytes. Overwritten files are typically located in the %CSIDL_SYSTEM%drivers, %CSIDL_SYSTEM_DRIVE%WindowsNTDS, and several other non-system drives.

Analysts attributed the wiper-style malware to the Sandworm hacking group, which serves Russia’s General Staff Main Intelligence Directorate (GRU) and Main Center for Special Technologies (GTsST). The latest attack is reminiscent of the recent HermeticWiper and CaddyWiper outbreaks deployed during Russia’s invasion.

Researchers noted that hackers infected the targets in all three wiper attacks via the same AD-based vector. The similarities in deployment methods lead ESET to believe that the Sandworm actors may have taken control of their target’s Active Directory environments prior to initiating the attack.

To say Sandworm has been busy since the Ukraine conflict would be an understatement. The Ukrainian Computer Emergency Response Team (CERT-UA) recently discovered another combination of several data-wiping malware packages deployed to the Ukrinform news agency’s networks. The malware scripts targeted Windows, Linux, and FreeBSD systems and infected them with multiple malware payloads, including CaddyWiper, ZeroWipe, SDelete, AwfulShred, and BidSwipe.

UPDATE: UAC-0082 (suspected #Sandworm) to target Ukrinform using 5 variants of destructive software: CaddyWiper, ZeroWipe, SDelete, AwfulShred, BidSwipe.

Details: https://t.co/vFIiRvXm0u (UA only)

— CERT-UA (@_CERT_UA) January 27, 2023

According to CERT-UA, the attacks were only partially successful. One of Sandworm’s listed malware packages, CaddyWiper, was also discovered in a failed attack that targeted one of Ukraine’s largest energy providers in April of 2022. Researchers at ESET helped during that attack by working with CERT-UA to remediate and protect the network.

Read More
Alejandro Fetzer

Latest

Eyewitness Recalls ‘Tragic’ Hit-and-Run That Killed Ex-Penn State Player’s Fiancee & Left Him on Life Support

What began as a routine walk through a quiet Colorado neighborhood turned into an unimaginable tragedy for former Penn State football player Kyle Vasey and his fiancée, Corinne More. On June 3, a pickup truck veered onto a sidewalk and struck the couple, leaving More dead and Vasey fighting for his life. One bystander who

Texas Southern Football Releases Multi-Venue 2026 Home Schedule

HOUSTON — A clearer picture is emerging of where Texas Southern University will play its home football games in 2026. A school representative contacted HBCU Legends and said the schedule has not been finalized and remains subject to change. As Texas Southern marks its centennial next year, the football program is framing this season's multi-venue

Will Bettridge, Ted Lasso and the embodiment of a Virginia football player

Will Bettridge is about to become Virginia’s all-time leading scorer.  He is like a goldfish, according to former Virginia kicker Matt Ganyard. “I think about what makes a great kicker,” Ganyard said in an interview with UVA On SI. “And then looking at Will, he absolutely embodies it. Thinking back to the Ted Lasso quote

The NFL’s Changing Landscape: Why Talent Evaluation Matters More Than Ever

The NFL’s Changing Landscape: Why Talent Evaluation Matters More Than Ever The National Football League remains the most popular sports competition in the United States, attracting millions of viewers every season and generating enormous interest among fans, analysts, scouts, and bettors alike. While star quarterbacks and championship contenders often dominate headlines, the foundation of every

Newsletter

Don't miss

Eyewitness Recalls ‘Tragic’ Hit-and-Run That Killed Ex-Penn State Player’s Fiancee & Left Him on Life Support

What began as a routine walk through a quiet Colorado neighborhood turned into an unimaginable tragedy for former Penn State football player Kyle Vasey and his fiancée, Corinne More. On June 3, a pickup truck veered onto a sidewalk and struck the couple, leaving More dead and Vasey fighting for his life. One bystander who

Texas Southern Football Releases Multi-Venue 2026 Home Schedule

HOUSTON — A clearer picture is emerging of where Texas Southern University will play its home football games in 2026. A school representative contacted HBCU Legends and said the schedule has not been finalized and remains subject to change. As Texas Southern marks its centennial next year, the football program is framing this season's multi-venue

Will Bettridge, Ted Lasso and the embodiment of a Virginia football player

Will Bettridge is about to become Virginia’s all-time leading scorer.  He is like a goldfish, according to former Virginia kicker Matt Ganyard. “I think about what makes a great kicker,” Ganyard said in an interview with UVA On SI. “And then looking at Will, he absolutely embodies it. Thinking back to the Ted Lasso quote

The NFL’s Changing Landscape: Why Talent Evaluation Matters More Than Ever

The NFL’s Changing Landscape: Why Talent Evaluation Matters More Than Ever The National Football League remains the most popular sports competition in the United States, attracting millions of viewers every season and generating enormous interest among fans, analysts, scouts, and bettors alike. While star quarterbacks and championship contenders often dominate headlines, the foundation of every

The Importance of Chris Barnes’ First Watch List Mention at Oklahoma State

Three schools in three years was probably not how Chris Barnes wanted to start his college football career. Now at Oklahoma State, he hopes this decision sticks. Barnes began his college football career at Washington State in 2024 as a redshirt and he followed that by transferring to Wake Forest in 2025. Why does a

Business delegation visits Kazakhstan to strengthen economic and trade cooperation

Astana, Kazakhstan, Jun 2, 2026 - (ACN Newswire) - A business delegation led by the Chief Executive of the Hong Kong Special Administrative Region (HKSAR), John Lee, and organised by the Hong Kong Trade Development Council (HKTDC), began its visit to Astana, the capital of Kazakhstan, on 1 June. During the visit, a total of 43

13 Real Business Trip Stories That Prove Work Travel Collects More Stories Than Miles

Real business trips almost never go the way the itinerary promised. They start with a confidently-packed suitcase and an eight-page agenda, and somewhere between the airport gate and the hotel breakfast they quietly turn into something nobody could have invented — equal parts comedy, chaos, and unscheduled adventure. These 13 real business trip moments are exactly that kind of work-trip plot

Your business texts could look like scam messages from July 1 if you don’t act now

From July 1, any branded SMS your business sends without a registered sender ID will be labelled “Unverified” and grouped with scam messages.  What’s happening: From 1 July 2026, any business or organisation that sends SMS using a branded name, such as “MyShop” or “AcmeServices”, instead of a phone number, must have that sender ID