Swarmer Tool Abuses Windows Registry to Evade Detection and Persist on Systems
ID: fab318a3-27d7-53ed-b92c-80fdfa5e93d1
STIX ID: report--fab318a3-27d7-53ed-b92c-80fdfa5e93d1
Feed Name: GBHackers
Threat Score
Swarmer is a technique/tool that abuses Windows mandatory user profiles and the Offline Registry Library (Offreg.dll) to build and deploy malicious NTUSER.MAN hives that override HKCU at user login, enabling stealthy persistence and evasion of EDRs and standard registry monitoring; defenders should watch for unexpected NTUSER.MAN creation, Offreg.dll usage by uncommon processes, and restrict profile directory controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
