Swarmer Tool Enables Stealthy Registry Persistence on Windows

Swarmer Tool Enables Stealthy Registry Persistence on Windows

First seen 29 Jan 2026, 22:54 UTC CybersecuritynewsGbhackers 89% similarity 18.3

Article Content

Browse articles
ThreatCluster

Praetorian Inc. has released Swarmer, a tool that allows low-privilege attackers to achieve stealthy persistence in the Windows registry while evading Endpoint Detection and Response (EDR) systems. The tool exploits mandatory user profiles and the Offline Registry API to modify the NTUSER hive without triggering standard hooks, posing a risk to systems since its operational deployment in February 2025.

ThreatCluster AI

Community

Browse all →