ZeroHour
Cyber Security Newspublished ()ingested Tushar Subhra Dutta
Part of a story covered by 3 sources: “New SETTRA Ransomware Hits Retail and Manufacturing Firms, Pairing MeshAgent RMM Persistence with BYOVD via gdrv.sys” — merged summary and timeline →

New SETTRA Ransomware Uses MeshAgent RMM and BYOVD to Encrypt Windows Systems

highRansomware exploited in the wildimportance 65
AI summary · glm-5.3-flash

Huntress reports new Settra ransomware hit retail and manufacturing firms, using MeshAgent RMM, BYOVD, and Windows utilities to encrypt systems and block recovery.

Huntress investigated two Settra intrusions: a consumer services and retail organization in July 2026 and a manufacturing firm in September 2026, showing nearly identical post-compromise behavior. Operators installed the MeshAgent RMM, ran ransomware executables named after the victim domain (_win64.exe), encrypted files with .locked or .locked_wip extensions, and dropped RESTORE_FILES.txt ransom notes. In both cases attackers cleared Windows Event Logs, disabled the Windows Recovery Environment, and used DiskPart to remove the recovery partition; the July case also ran Cipher to overwrite free space and flushed DNS cache. The September incident added BYOVD using gdrv.sys, and initial access was suspected via VPNs or previously stolen credentials, though unconfirmed.

  • Two intrusions hit consumer services/retail in July and manufacturing in September with nearly identical post-compromise behavior
  • MeshAgent RMM installed for persistence, connecting to attacker-controlled C2 servers in both incidents
  • September attack used BYOVD with gdrv.sys to impair security tooling before encryption
  • Recovery sabotage: event logs cleared, Windows RE disabled, DiskPart removed recovery partition, Cipher overwrote free space
  • Initial access unconfirmed; suspected via VPNs or previously stolen credentials
VendorsMicrosoft
Threat actorsSettra
MalwareSettra
OrganizationsHuntress
CountriesUnited States
Full article867 words · extracted from cybersecuritynews.com · click to collapse

Settra ransomware is emerging as a serious threat to Windows networks after investigators linked it to two recent intrusions involving remote-management software and recovery-blocking actions.

The operation encrypts files, leaves victims with ransom notes, and tries to make both investigation and restoration more difficult. Public reporting indicates that the people behind Settra have gained entry through virtual private networks or previously stolen credentials.

That makes exposed remote access and weak account controls a central concern, while the use of legitimate administration software reflects the wider misuse of remote management tools in intrusions.

Analysts from Huntress identified two incidents, one affecting a consumer services and retail organization in July and another affecting a manufacturing company in September.

They could not confirm how either network was first breached, but found an almost identical post-compromise pattern in both cases.

Huntress said in a report shared with Cyber Security News (CSN) that the activity matters because it combines rapid encryption with actions designed to limit recovery and erase useful evidence.

In each case, the ransomware executable used a name based on the affected organization’s domain, a choice that may help it appear less out of place on a compromised system.

New SETTRA Ransomware

Settra operators installed MeshAgent, a remote monitoring and management tool, after gaining access. Such tools can give attackers a reliable way to maintain control of a machine, execute commands, and advance their operation without relying only on custom malware.

A separate FortiGate intrusion using MeshAgent likewise showed how RMM utilities can be repurposed after a network breach. In the July incident, the MeshAgent program was renamed and reached an attacker-controlled command-and-control server.

The next day, researchers observed the ransomware run from a Windows performance-log directory, encrypt files with a unique extension, and create a ransom note.

Excerpt from the RESTORE_FILES.txt (Source - Huntress)
Excerpt from the RESTORE_FILES.txt (Source – Huntress)

The September incident contained evidence of BYOVD, or Bring Your Own Vulnerable Driver. This approach uses a legitimate but flawed driver to interfere with defensive software, potentially allowing an intruder to disable security services before encryption.

Recent reporting on trusted Windows drivers shows why this technique has become a recurring concern in ransomware investigations.

MeshAgent in the September intrusion was not renamed and connected to a different command-and-control server.

The ransomware launched from the compromised user’s Documents folder, used another file extension, and placed ransom notes in multiple directories. Researchers also connected the malicious activity to a workstation name previously observed alongside that server.

Recovery Disruption Raises Response Pressure

After launching the ransomware, the attackers cleared several Windows Event Logs and disabled the Windows Recovery Environment. They also used DiskPart in both incidents, apparently to remove a recovery partition, and flushed the DNS cache in July.

These steps can delay recovery while reducing the evidence available to responders. In the July case, Settra also ran the Windows Cipher utility to overwrite free space on a data drive.

Signals indicating the attacker's use of BYOVD and the MeshAgent RMM (Source - Huntress)
Signals indicating the attacker’s use of BYOVD and the MeshAgent RMM (Source – Huntress)

That action can make deleted material harder to retrieve. In September, the operators attempted to remove Defender logging but misspelled the log channel name, leaving the Windows Defender Event Log intact. Central collection of Windows event logs can preserve evidence when attackers try to erase local records.

Organizations should focus on basic controls that disrupt this chain early: protect VPN access with strong authentication, restrict and monitor remote-management tools, and investigate unexpected driver installations or suspicious processes launched from user folders and Windows system directories.

Teams should also maintain tested, offline or otherwise protected backups and verify that recovery features remain available. They should also test response playbooks against simulated encryption events, including loss of endpoint visibility.

This reduces the chance an incident becomes a crisis. The two cases show that Settra does not need an entirely new toolkit to create major disruption.

Familiar tools, vulnerable drivers, and built-in Windows utilities can be combined to put defenders under pressure quickly. Fast detection of abnormal RMM activity, protected logs, and rehearsed recovery procedures remain important safeguards.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
IP address45.13.122[.]7MeshAgent command-and-control address in the July incident
IP address193.5.65[.]114MeshAgent command-and-control address in the September incident
File namemvtcs.exeRenamed MeshAgent executable identified in the July incident
File name pattern<victim-domain>_win64.exeRansomware executable naming pattern observed in both incidents
Workstation nameWIN-LIVFRVQFMKOWorkstation associated with September activity and prior incidents
File nameRESTORE_FILES.txtRansom note created in both incidents
Driver filegdrv.sysBYOVD filename observed in the September incident
File extension.locked_wipExtension added to encrypted files in the September incident
File extension.lockedExtension added to encrypted files in the July incident

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/new-settra-ransomware/