ZeroHour
Story · 3 sources · 3 articlesfirst updated ()

New SETTRA Ransomware Hits Retail and Manufacturing Firms, Pairing MeshAgent RMM Persistence with BYOVD via gdrv.sys

highRansomwareexploited in the wildimportance 65
What's new: First merged dashboard summary for this story (no previous summary). Key development within the story: the September manufacturing intrusion added BYOVD via gdrv.sys, an escalation from the July retail attack, while core tradecraft (MeshAgent RMM persistence, event log clearing, Windows RE disabling, DiskPart recovery partition removal) was consistent across both incidents.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Huntress investigated two SETTRA ransomware intrusions in 2026 — a consumer services/retail organization in July and a manufacturer in September — where operators installed MeshAgent RMM for persistence, sabotaged Windows recovery, cleared event logs, and…

Huntress investigated two SETTRA (also written Settra) ransomware intrusions showing nearly identical post-compromise behavior: a July 2026 attack on a consumer services and retail organization and a September 2026 attack on a manufacturing firm. The variant was first observed in June 2026, and prior research links the group to double-extortion tactics. In both incidents, operators installed the MeshAgent RMM connecting to attacker-controlled C2 servers — observed at 45.13.122[.]7 and 193.5.65[.]114 — and ran ransomware executables named after each victim's domain with a _win64.exe suffix (per Cyber Security News); in the retail attack the ransomware ran from C:\Perflogs. Files were encrypted with .locked and .locked_wip extensions and a RESTORE_FILES.txt ransom note was dropped (Infosecurity Magazine reports only the .locked extension for the retail incident). Recovery sabotage included clearing Windows Event Logs, disabling the Windows Recovery Environment, using DiskPart to remove the recovery partition, running Cipher to overwrite free space, and flushing the DNS cache. The September intrusion added BYOVD using the gdrv.sys driver to impair security tooling before encryption. In both incidents, operators misspelled the Defender event log channel, leaving critical telemetry intact. Initial access remains unconfirmed by Huntress, which suspects compromised VPNs or previously stolen credentials, though earlier reporting (GBHackers) links the group to compromised VPN credentials; the associated toolset includes NetExec, PAExec, ProcDump, Mimikatz, and edr_blind.

  • Huntress investigated two SETTRA intrusions with nearly identical post-compromise behavior: a consumer services/retail organization in July 2026 and a manufacturing firm in September 2026.
  • Settra was first observed in June 2026; prior research links it to double-extortion tactics.
  • MeshAgent RMM was installed for persistence, connecting to attacker-controlled C2 servers in both incidents; observed C2 IPs are 45.13.122[.]7 and 193.5.65[.]114.
  • Ransomware binaries were named after the victim's domain (with a _win64.exe suffix per Cyber Security News); in the retail attack the ransomware ran from C:\Perflogs.
  • Files were encrypted with .locked and .locked_wip extensions and a RESTORE_FILES.txt ransom note was dropped; Infosecurity Magazine reports only .locked for the retail incident.
  • Recovery sabotage: Windows Event Logs cleared, Windows Recovery Environment disabled, DiskPart used to remove the recovery partition, Cipher used to overwrite free space, and DNS cache flushed.
  • The September manufacturing attack added BYOVD using the vulnerable gdrv.sys driver to impair security tooling before encryption; the July retail attack did not include BYOVD.
  • Operators misspelled the Defender event log channel, leaving critical telemetry intact.

Coverage timeline

  1. · 2h ago
    GBHackers· 52
    New SETTRA Ransomware Uses MeshAgent RMM and BYOVD to Encrypt Windows Systems

    New SETTRA ransomware operation abuses MeshAgent RMM for persistence, BYOVD via gdrv.sys, log clearing, and Windows recovery sabotage to encrypt systems.

  2. · 1h ago
    Infosecurity Magazine· 62
    New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing

    Huntress details a new Settra ransomware variant deployed against retail and manufacturing victims since June, using MeshAgent RMM, recovery sabotage, and BYOVD techniques.

  3. · 1h ago
    Cyber Security News· 65
    New SETTRA Ransomware Uses MeshAgent RMM and BYOVD to Encrypt Windows Systems

    Huntress reports new Settra ransomware hit retail and manufacturing firms, using MeshAgent RMM, BYOVD, and Windows utilities to encrypt systems and block recovery.