Settra ransomware hits retail and manufacturing sectors

A new variant of the emerging Settra ransomware family has been deployed in two recent intrusions against organizations in the retail and manufacturing sectors, giving defenders fresh insight into the group’s post-compromise playbook.[1][2][8]

In an analysis published this week, researchers at Huntress described investigations into two Settra incidents: a July attack on an organization in the consumer services and retail space and a September intrusion at a manufacturing company.[1][6][8] In both cases, the endpoint was already compromised by the time Huntress tooling was deployed, leaving analysts to reconstruct the attack chain from forensic traces rather than live response.[1][6] The initial access vector remains unconfirmed for both victims, but the subsequent activity showed a highly consistent pattern in how the attackers moved, persisted and ultimately launched encryption.[1][4]

Huntress reports that in each intrusion the threat actors installed MeshAgent, a legitimate remote monitoring and management (RMM) tool, to gain persistent access and hands-on control of victim systems before triggering encryption.[1][2][6] The ransomware executables were named after the victim organization’s domain, and once launched they encrypted files and dropped a ransom note titled RESTORE_FILES.txt across affected systems.[1][4] In at least one of the incidents, the attackers deployed a “bring your own vulnerable driver” (BYOVD) technique in an apparent attempt to tamper with security defenses at the kernel level, although a typo in a command prevented them from fully clearing the Windows Defender event log.[1][4][12]

The Settra operation itself is relatively new but already firmly embedded in the double-extortion ecosystem, combining file encryption with the threat of public data leaks to pressure victims into paying.[2][7][11] Multiple tracking efforts place the group’s emergence around June 2026, when its Tor-based leak site and initial cluster of victim disclosures first appeared.[3][9][10][15] Depending on the data source, Settra has now claimed roughly between several dozen and more than 90 organizations worldwide, with third-party trackers and intelligence firms reporting victim counts ranging from the mid-60s to the 90-victim mark.[2][9][10][13] Sector analyses indicate a concentration in manufacturing and technology, alongside targets in retail, professional services and other industries.[2][11][13]

Geographically, Settra appears opportunistic rather than strictly region-bound, with observed or claimed victims in countries including the United States, Germany, the United Kingdom, Canada and Australia.[4][5][15] External threat-intelligence reporting and victim-leak monitoring suggest that manufacturing accounts for a significant share of named victims, while retail remains a smaller but noteworthy slice of the group’s target mix.[2][13] Public reporting so far has not identified a clear nation-state link, and Settra is currently characterized as a financially motivated criminal operation rather than a ransomware-as-a-service franchise, with no firm evidence that it is leasing its tooling to affiliates.[2][10][11]

The Huntress cases underscore several detection opportunities for defenders facing Settra or similar human-operated ransomware crews, particularly around the use of MeshAgent and other RMM tooling on endpoints where such software is not standard.[1][2] Security teams are urged to monitor for unexpected RMM installations, aggressive log clearing, Volume Shadow Copy deletions and changes to Windows recovery and boot configuration settings, all of which featured in the Settra intrusions.[1][4] Given the group’s reliance on double extortion and a public leak site, organizations in exposed sectors such as manufacturing and retail are being advised to review incident-response runbooks, ensure immutable backups and practice strict access control around remote-management tooling to limit the blast radius of similar compromises.[2][7][10]

References

  1. New Settra Ransomware Variant Deploys MeshAgent RMM – Huntress
  2. Settra ransomware group uses MeshAgent RMM in recent attacks
  3. Threat Analysis Blog Posts
  4. ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM …
  5. Post
  6. New Settra Ransomware Strain Deploys MeshAgent RMM for Persistence
  7. Settra ransomware group: victims, status, activity | Ransomnews
  8. Infosecurity Magazine – Information Security & IT Security News and Resources
  9. Settra
  10. SETTRA Ransomware: Emerging Double-Extortion Threat
  11. Settra — Threat Actor Profile
  12. Huntress (@HuntressLabs) / X
  13. SETTRA
  14. settra · Darkfield

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply