ZeroHour
Malware

Settra

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

New SETTRA Ransomware Uses MeshAgent RMM and BYOVD to Encrypt Windows Systems

Huntress reports new Settra ransomware hit retail and manufacturing firms, using MeshAgent RMM, BYOVD, and Windows utilities to encrypt systems and block recovery.

Huntress investigated two Settra intrusions: a consumer services and retail organization in July 2026 and a manufacturing firm in September 2026, showing nearly identical post-compromise behavior. Operators installed the MeshAgent RMM, ran ransomware executables named after the victim domain (_win64.exe), encrypted files with .locked or .locked_wip extensions, and dropped RESTORE_FILES.txt ransom notes. In both cases attackers cleared Windows Event Logs, disabled the Windows Recovery Environment, and used DiskPart to remove the recovery partition; the July case also ran Cipher to overwrite free space and flushed DNS cache. The September incident added BYOVD using gdrv.sys, and initial access was suspected via VPNs or previously stolen credentials, though unconfirmed.

Cyber Security News · 2h agoRansomware in the wild 3 sources

New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing

Huntress details a new Settra ransomware variant deployed against retail and manufacturing victims since June, using MeshAgent RMM, recovery sabotage, and BYOVD techniques.

Huntress reported a new Settra ransomware variant, first observed in June, used in a July attack on a consumer services and retail organization and a September attack on a manufacturing firm. In the retail attack, MeshAgent RMM connected to attacker C2, the ransomware ran from C:\Perflogs, encrypted files with the .locked extension, and created a ransom note; the executable was named after the victim's domain in both incidents. Attackers cleared Windows Event Logs, disabled the Windows Recovery Environment, flushed DNS cache, used DiskPart to remove the recovery partition, and ran Cipher to overwrite free space. The September attack added BYOVD; prior research links Settra to double extortion, and initial access remains unconfirmed.

Infosecurity Magazineupdated · 2h agofirst · 2h agoRansomware in the wild 3 sources

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.