On 25 January 2023 ESET reported detecting a new wiper written in Go, which it named SwiftSlicer, deployed against Ukrainian targets. It attributed the activity to Sandworm.
The reported deployment mechanism was Active Directory Group Policy. Once run, the wiper deletes shadow copies and recursively overwrites files in system directories and on non-system drives with randomly generated bytes, then reboots the machine.
Group Policy Is A Deployment System
Group Policy exists so an administrator can push configuration and software to every machine in a domain at once. Using it to distribute a wiper is not an exploit; it is the feature.
The corpus records the same pattern of legitimate mechanisms turned around at 23-0524, where Volt Typhoon used built-in Windows utilities, and at 23-0329, where a vendor’s own signed update carried malware. The distribution channel an organisation trusts most is the one that reaches everything.
Reaching Group Policy Means It Was Already Over
Deployment through Group Policy implies control of the directory that governs authentication and authorisation for the whole estate. By the time the wiper ran, the intrusion had already succeeded completely.
That makes the destruction an outcome rather than an attack, in the same way the corpus reads the Kyivstar file at 23-1212, where Ukraine’s security service reported seven months of access before the environment was destroyed.
Destruction Has No Victim Count
This file carries no figure for affected organisations or machines. Wiper campaigns in a war do not produce breach notifications, and the reporting that exists is research telemetry rather than disclosure.
The corpus notes throughout that it can only measure what somebody was required to publish. Ukraine in 2023 is the clearest case of a set of incidents that are real, documented by researchers, and permanently uncountable.
Built on ESET’s published research on SwiftSlicer and its broader account of wiper activity against Ukrainian targets. The 25 January detection, the Go implementation, the Group Policy deployment, the overwrite behaviour and the attribution to Sandworm are ESET’s findings, recorded as the researchers’ assessment and not as a finding of this desk. No victim organisations are named and no count of affected systems is asserted; none was published. No indicators are reproduced. Graded high on the research as published. Corrections: corrections@forensicpost.com.