ZeroHour
Product

MeshAgent

3 mentions in 7 days · 3 in 30 days · 3 total · first seen · last

Timeline

New SETTRA Ransomware Uses MeshAgent RMM and BYOVD to Encrypt Windows Systems

Huntress reports new Settra ransomware hit retail and manufacturing firms, using MeshAgent RMM, BYOVD, and Windows utilities to encrypt systems and block recovery.

Huntress investigated two Settra intrusions: a consumer services and retail organization in July 2026 and a manufacturing firm in September 2026, showing nearly identical post-compromise behavior. Operators installed the MeshAgent RMM, ran ransomware executables named after the victim domain (_win64.exe), encrypted files with .locked or .locked_wip extensions, and dropped RESTORE_FILES.txt ransom notes. In both cases attackers cleared Windows Event Logs, disabled the Windows Recovery Environment, and used DiskPart to remove the recovery partition; the July case also ran Cipher to overwrite free space and flushed DNS cache. The September incident added BYOVD using gdrv.sys, and initial access was suspected via VPNs or previously stolen credentials, though unconfirmed.

Cyber Security News · 2h agoRansomware in the wild 3 sources

New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing

Huntress details a new Settra ransomware variant deployed against retail and manufacturing victims since June, using MeshAgent RMM, recovery sabotage, and BYOVD techniques.

Huntress reported a new Settra ransomware variant, first observed in June, used in a July attack on a consumer services and retail organization and a September attack on a manufacturing firm. In the retail attack, MeshAgent RMM connected to attacker C2, the ransomware ran from C:\Perflogs, encrypted files with the .locked extension, and created a ransom note; the executable was named after the victim's domain in both incidents. Attackers cleared Windows Event Logs, disabled the Windows Recovery Environment, flushed DNS cache, used DiskPart to remove the recovery partition, and ran Cipher to overwrite free space. The September attack added BYOVD; prior research links Settra to double extortion, and initial access remains unconfirmed.

Infosecurity Magazineupdated · 2h agofirst · 2h agoRansomware in the wild 3 sources

New SETTRA Ransomware Uses MeshAgent RMM and BYOVD to Encrypt Windows Systems

New SETTRA ransomware operation abuses MeshAgent RMM for persistence, BYOVD via gdrv.sys, log clearing, and Windows recovery sabotage to encrypt systems.

Huntress investigated two SETTRA ransomware incidents in July and September 2026 at a consumer services/retail organization and a manufacturer, finding victim-specific binaries, MeshAgent RMM persistence, and BYOVD use of the gdrv.sys driver. The operator disabled Windows Recovery Environment, cleared event logs, overwrote free space with cipher, and encrypted files with .locked and .locked_wip extensions. Earlier reporting linked the group to compromised VPN credentials and tools including NetExec, PAExec, ProcDump, Mimikatz, and edr_blind.

GBHackersupdated · 2h agofirst · 3h agoRansomware in the wild 3 sources

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.