Information security company ESET has discovered a new cyberattack that appears to target Ukraine and aims to overwrite critical Windows operating system files.
ESET said in a tweet: “On January 25, #ESETResearch discovered a new cyberattack in Ukraine where attackers used Active Directory Group Policy to deploy a new file wiper tool we are calling #SwiftSlicer. #The SwiftSlicer wiper tool was created in the Go programming language. We attribute this attack to #Sandworm“.
Active Directory Group Policy is an important utility in the Windows Active Directory environment that IT administrators can configure. Active Directory Group Policies define the behavior and permissions of users and computers.
Also:
Sandworm, also known as Unit 74455, is a group of Russian military hackers operating under the General Staff of the Russian Armed Forces. Several other attacks in Ukraine have been attributed to it, such as the 2015 attack on the power grid.
In another tweet, ESET said: “Upon execution, the tool deletes shadow copies and recursively overwrites files in the %CSIDL_SYSTEM%\drivers directory, the %CSIDL_SYSTEM_DRIVE%\Windows\NTDS directory, and other non-system drives, then reboots the computer.
Also:
The Go programming language that forms the basis of the attack is valuable to threat actors due to its versatility, and it is used by many large companies for legitimate purposes, such as: Google, Twitter, and PayPal.
According to Ukraine's Computer Emergency Response Team, Sandworm has carried out a number of other attacks in the country, including: five data-wiping attacks on Ukraine's state news agency Ukrinform;
A series of CaddyWiper, the data wiper tool used in attacks on Ukrainian news agencies, was found in several attacks against Ukraine, indicating the involvement of the Sandstorm group.
Also:
And with that, my friend, we have successfully completed the mission