logo

Swarmer Tool Abuses Windows Registry to Evade Detection and Persist on Systems

ID: fab318a3-27d7-53ed-b92c-80fdfa5e93d1

STIX ID: report--fab318a3-27d7-53ed-b92c-80fdfa5e93d1

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-01-29

Date Updated: 2026-04-22

Author: Divya

...
...

Swarmer is a technique/tool that abuses Windows mandatory user profiles and the Offline Registry Library (Offreg.dll) to build and deploy malicious NTUSER.MAN hives that override HKCU at user login, enabling stealthy persistence and evasion of EDRs and standard registry monitoring; defenders should watch for unexpected NTUSER.MAN creation, Offreg.dll usage by uncommon processes, and restrict profile directory controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.