ZeroHour
Malware

SETTRA ransomware

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

New SETTRA Ransomware Uses MeshAgent RMM and BYOVD to Encrypt Windows Systems

New SETTRA ransomware operation abuses MeshAgent RMM for persistence, BYOVD via gdrv.sys, log clearing, and Windows recovery sabotage to encrypt systems.

Huntress investigated two SETTRA ransomware incidents in July and September 2026 at a consumer services/retail organization and a manufacturer, finding victim-specific binaries, MeshAgent RMM persistence, and BYOVD use of the gdrv.sys driver. The operator disabled Windows Recovery Environment, cleared event logs, overwrote free space with cipher, and encrypted files with .locked and .locked_wip extensions. Earlier reporting linked the group to compromised VPN credentials and tools including NetExec, PAExec, ProcDump, Mimikatz, and edr_blind.

GBHackersupdated · 7h agofirst · 8h agoRansomware in the wild 3 sources1

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.