Desk live·
ForensicPost
Nation-state/Infrastructure/File 23-0125

Sandworm Pushed a Wiper to Ukrainian Targets Through Active Directory Itself

The malware was new and the delivery mechanism was not. Researchers reported SwiftSlicer being distributed via Group Policy — the administrative system for pushing software to every machine in a domain, used exactly as designed to destroy them.

Constructed geometry · not a chart of case data
JurisdictionUkrainethe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUkrainian organisations
ActorSandworm
D. Kennedy10 min readConfidence: high2 sources reviewed

On 25 January 2023 ESET reported detecting a new wiper written in Go, which it named SwiftSlicer, deployed against Ukrainian targets. It attributed the activity to Sandworm.

The reported deployment mechanism was Active Directory Group Policy. Once run, the wiper deletes shadow copies and recursively overwrites files in system directories and on non-system drives with randomly generated bytes, then reboots the machine.

Group Policy Is A Deployment System

Group Policy exists so an administrator can push configuration and software to every machine in a domain at once. Using it to distribute a wiper is not an exploit; it is the feature.

The corpus records the same pattern of legitimate mechanisms turned around at 23-0524, where Volt Typhoon used built-in Windows utilities, and at 23-0329, where a vendor’s own signed update carried malware. The distribution channel an organisation trusts most is the one that reaches everything.

Reaching Group Policy Means It Was Already Over

Deployment through Group Policy implies control of the directory that governs authentication and authorisation for the whole estate. By the time the wiper ran, the intrusion had already succeeded completely.

That makes the destruction an outcome rather than an attack, in the same way the corpus reads the Kyivstar file at 23-1212, where Ukraine’s security service reported seven months of access before the environment was destroyed.

Destruction Has No Victim Count

This file carries no figure for affected organisations or machines. Wiper campaigns in a war do not produce breach notifications, and the reporting that exists is research telemetry rather than disclosure.

The corpus notes throughout that it can only measure what somebody was required to publish. Ukraine in 2023 is the clearest case of a set of incidents that are real, documented by researchers, and permanently uncountable.

How we reported this

Built on ESET’s published research on SwiftSlicer and its broader account of wiper activity against Ukrainian targets. The 25 January detection, the Go implementation, the Group Policy deployment, the overwrite behaviour and the attribution to Sandworm are ESET’s findings, recorded as the researchers’ assessment and not as a finding of this desk. No victim organisations are named and no count of affected systems is asserted; none was published. No indicators are reproduced. Graded high on the research as published. Corrections: corrections@forensicpost.com.

Sources
  1. SwiftSlicer: New destructive wiper malware strikes UkraineESET
  2. A year of wiper attacks in UkraineESET
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary