Categories
Audio Sources - Full Text Articles

Sandworm APT targets Ukraine with new SwiftSlicer wiper

Listen to this article

Russia-linked Sandworm APT group is behind a new Golang-based wiper, tracked as SwiftSlicer, that hit Ukraine, ESET reports.

Researchers from ESET discovered a new Golang-based wiper, dubbed SwiftSlicer, that was used in attacks aimed at Ukraine. The experts believe that the Russia-linked APT group Sandwork (akaĀ BlackEnergyĀ andĀ TeleBots) is behind the wiper attacks.

#BREAKING On January 25th #ESETResearch discovered a new cyberattack in šŸ‡ŗšŸ‡¦ Ukraine. Attackers deployed a new wiper we named #SwiftSlicer using Active Directory Group Policy. The #SwiftSlicer wiper is written in Go programing language. We attribute this attack to #Sandworm. 1/3 pic.twitter.com/pMij9lpU5J

— ESET Research (@ESETresearch) January 27, 2023

The SandwormĀ group has been active since 2000, it operates under the control ofĀ Unit 74455Ā ofĀ the Russian GRU’s Main Center for Special Technologies (GTsST).

The group is also the author of theĀ NotPetya ransomwareĀ that hit hundreds of companies worldwide in June 2017.

Once executed, the wiper deletes shadow copies, recursively overwrites files. The wiper targets files located in %CSIDL_SYSTEM%drivers, %CSIDL_SYSTEM_DRIVE%WindowsNTDS and other non-system drives before rebooting the infected system. The SwiftSlicer wiper overwriting files with 4096 bytes length blocks with randomly generated byte.

In 2022, the Russian APT used multiple wipers in attacks aimed at Ukraine, including AwfulShred, CaddyWiper, HermeticWiper, Industroyer2, IsaacWiper, WhisperGate,Ā Prestige, RansomBoggs, and ZeroWipe.Ā 

On September 2022, theĀ SandwormĀ group was observed impersonating telecommunication providers to target Ukrainian entities with malware.

Security firms warn that the Sandworm APT continues to target Ukraine with multiple means, including custom malware and botnet.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

PierluigiĀ Paganini

(SecurityAffairs – hacking, Moshen Dragon)

The post Sandworm APT targets Ukraine with new SwiftSlicer wiper appeared first on Security Affairs.