Cybersecuritynews
Swarmer Tool Enables Stealthy Registry Persistence on Windows
First seen 29 Jan 2026, 22:54 UTC
•
•89% similarity
•18.3
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Praetorian Inc. has released Swarmer, a tool that allows low-privilege attackers to achieve stealthy persistence in the Windows registry while evading Endpoint Detection and Response (EDR) systems. The tool exploits mandatory user profiles and the Offline Registry API to modify the NTUSER hive without triggering standard hooks, posing a risk to systems since its operational deployment in February 2025.
ThreatCluster AI