Praetorian publicly released Swarmer, a Windows persistence tool that enables low-privilege attackers to establish startup execution while evading EDR visibility by avoiding standard registry-write APIs. The technique abuses mandatory user profiles by creating a NTUSER.MAN hive (derived from NTUSER.DAT) that overrides the normal per-user registry hive at next logon; because the modified hive is not loaded until the user signs in again, EDR products that rely on monitoring live registry modifications (e.g., hooks on RegSetValue* and related telemetry) may not observe the persistence being set.
Swarmer achieves this by using Microsoft’s Offline Registry Library (offreg.dll) to build and modify registry hives “offline” (e.g., via functions such as OROpenHive, ORCreateKey, ORSetValue, and ORSaveHive) rather than calling the typical Reg* APIs that many EDRs instrument. Reported operator workflow includes exporting HKCU, adding a startup entry (commonly under HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run), generating a modified NTUSER.MAN, and placing it in %USERPROFILE% so the persistence activates on the next login; the Reddit post links to the same research/tool release and reiterates the core evasion premise (no observable registry writes at the time persistence is staged).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Praetorian publicly released Swarmer and described how it uses mandatory user profiles (NTUSER.MAN) and Microsoft's Offline Registry API in Offreg.dll to modify a copied user registry hive without relying on standard Reg* APIs commonly monitored by EDR tools. The disclosure also outlined limitations and possible detection opportunities, including monitoring for unexpected NTUSER.MAN creation and unusual Offreg.dll usage.
Praetorian said its Windows persistence tool and technique, dubbed Swarmer, had been used operationally since February 2025. The method abuses mandatory user profiles and offline registry hive editing to establish HKCU Run-key persistence that activates at the next user logon.
A blog post published a proof of concept, RegREeper.exe, showing how to establish HKCU Run-key persistence by saving a registry hive, modifying it offline, and restoring it with RegRestoreKeyW after enabling SeRestorePrivilege. The research also reported that Sysmon did not log the save-and-restore workflow and attributed this to gaps in the REG_NOTIFY_CLASS operations it monitors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcereddit.com
Open sourcetccontre.blogspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.