Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-06 01:02:56 UTC Home > List all groups > List all tools > List all groups using tool SwiftSlicer Tool: SwiftSlicer Names SwiftSlicer JaguarBlade Category Malware Type Wiper Description (ESET) SwiftSlicer is detected by ESET products as WinGo/KillFiles.C. The malware was written in Go, a highly versatile, cross-platform programming language. When it comes to SwiftSlicer’s method of destruction, ESET researchers had this to say: “Once executed it deletes shadow copies, recursively overwrites files located in %CSIDL_SYSTEM%\drivers, %CSIDL_SYSTEM_DRIVE%\Windows\NTDS and other non-system drives and then reboots computer. For overwriting it uses 4096 bytes length block filled with randomly generated byte”. Information Malpedia Last change to this tool card: 22 June 2023 Download this tool card in JSON format All groups using tool SwiftSlicer Changed Name Country Observed APT groups Sandworm Team, Iron Viking, Voodoo Bear 2009-Dec 2024 1 group listed (1 APT, 0 other, 0 unknown) https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=769d41bc-33d6-4026-9456-2047d30e0a83 Page 1 of 2 Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=769d41bc-33d6-4026-9456-2047d30e0a83 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=769d41bc-33d6-4026-9456-2047d30e0a83 Page 2 of 2 APT groups Sandworm Team, Iron Viking, Voodoo Bear 2009-Dec 2024 1 group listed (1 APT, 0 other, 0 unknown) Page 1 of 2