logo

Swarmer Tool Evading EDR With a Stealthy Modification on Windows Registry for Persistence

ID: 41f25fb5-0707-5df2-8552-7a5f4e45fab9

STIX ID: report--41f25fb5-0707-5df2-8552-7a5f4e45fab9

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-01-29

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Praetorian disclosed Swarmer, a Windows persistence tool that lets low-privilege users convert a reg export into an NTUSER.MAN hive and use Microsoft’s Offline Registry (Offreg.dll) APIs to modify HKCU without invoking standard Reg* APIs, enabling stealthy login-time persistence that bypasses many EDR hooks; the report covers usage patterns, commands, implementation notes, limitations (HKCU-only, one-shot, login activation), and detection opportunities such as unexpected NTUSER.MAN files and Offreg.dll loads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.