New SETTRA Ransomware Uses MeshAgent RMM and BYOVD to Encrypt Windows Systems
New SETTRA ransomware operation abuses MeshAgent RMM for persistence, BYOVD via gdrv.sys, log clearing, and Windows recovery sabotage to encrypt systems.
Huntress investigated two SETTRA ransomware incidents in July and September 2026 at a consumer services/retail organization and a manufacturer, finding victim-specific binaries, MeshAgent RMM persistence, and BYOVD use of the gdrv.sys driver. The operator disabled Windows Recovery Environment, cleared event logs, overwrote free space with cipher, and encrypted files with .locked and .locked_wip extensions. Earlier reporting linked the group to compromised VPN credentials and tools including NetExec, PAExec, ProcDump, Mimikatz, and edr_blind.