Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
New SETTRA Ransomware Leverages MeshAgent RMM and BYOVD to Encrypt Windows Systems
September 18, 2026
Four Critical Linux Kernel Privilege Escalation Flaws Let Attackers Gain Root Access
September 18, 2026
AI Agents Automate End-to-End Ransomware Attacks
September 18, 2026
Home/Threats/New SETTRA Ransomware Leverages MeshAgent RMM and BYOVD to Encrypt Windows Systems
Threats

New SETTRA Ransomware Leverages MeshAgent RMM and BYOVD to Encrypt Windows Systems

Key Takeaways Settra ransomware is actively targeting Windows networks, leveraging remote management tools and vulnerable drivers. Initial access is often gained via compromised VPNs or stolen...

Marcus Rodriguez
Marcus Rodriguez
September 18, 2026 5 Min Read
3 0

Key Takeaways

  • Settra ransomware is actively targeting Windows networks, leveraging remote management tools and vulnerable drivers.
  • Initial access is often gained via compromised VPNs or stolen credentials, highlighting the importance of strong access controls.
  • The ransomware employs sophisticated tactics to hinder recovery and forensic analysis, including clearing event logs and disabling recovery environments.
  • Two distinct incidents in July and September involving consumer services/retail and manufacturing sectors, respectively, demonstrate the group’s evolving techniques.
  • Organizations should prioritize robust access security, monitor RMM tool usage, and maintain secure, tested backups to mitigate risk.

A new ransomware strain, dubbed Settra, is actively targeting Windows environments, exhibiting advanced tactics that combine legitimate remote management software with techniques designed to impede recovery and forensic efforts. Cybersecurity researchers have linked Settra to at least two recent intrusions, underscoring its emerging threat profile.

Table Of Content

  • Key Takeaways
  • Analysis of Settra Operations
  • MeshAgent RMM and BYOVD Exploitation
  • Recovery Disruption Tactics
  • What You Should Do

The ransomware encrypts critical files, delivers ransom notes to victims, and then takes steps to complicate both incident response and data restoration. Investigations suggest that the Settra operators initially compromise networks through vulnerable virtual private networks (VPNs) or by exploiting previously stolen credentials. This indicates that inadequate remote access security and weak account management remain significant points of vulnerability for organizations.

Furthermore, the attackers’ use of legitimate administrative software, specifically remote monitoring and management (RMM) tools, reflects a broader trend of threat actors co-opting trusted applications to maintain persistence and execute malicious operations post-breach.

Analysis of Settra Operations

Analysts at Huntress have documented two specific incidents involving Settra ransomware. The first occurred in July, impacting an organization in the consumer services and retail sector. The second, in September, targeted a manufacturing company. While the initial breach vectors for both incidents could not be definitively confirmed, Huntress observed strikingly similar post-compromise behaviors in each case, as detailed in a report shared with Cyber Security News (CSN).

According to Huntress, the significance of these attacks lies in the combination of rapid data encryption with deliberate actions to obstruct recovery and eliminate forensic evidence. A notable characteristic observed was the ransomware executable’s naming convention; it adopted a name based on the victim organization’s domain, likely an attempt to blend in and appear less suspicious on the compromised system.

MeshAgent RMM and BYOVD Exploitation

In both documented Settra intrusions, the attackers deployed MeshAgent, an open-source remote monitoring and management tool, after gaining initial access. RMM tools like MeshAgent are highly valuable to attackers because they provide a persistent and versatile channel for maintaining control, executing commands, and advancing their objectives without relying exclusively on custom malware. This strategy echoes other recent incidents, such as a FortiGate intrusion that also leveraged MeshAgent for post-breach activities.

In the July incident, the MeshAgent program was renamed to mvtcs.exe and established communication with an attacker-controlled command-and-control (C2) server at 45.13.122[.]7. The following day, researchers witnessed the ransomware being executed from a Windows performance-log directory, encrypting files with a .locked extension, and creating a ransom note named RESTORE_FILES.txt.

The September incident revealed an even more sophisticated tactic: the use of Bring Your Own Vulnerable Driver (BYOVD). This technique involves exploiting a legitimate but flawed kernel-mode driver, in this case, gdrv.sys, to interfere with security software. By leveraging such a driver, attackers can potentially disable endpoint security solutions before initiating encryption, significantly increasing their chances of success. This highlights why BYOVD has become a recurring concern in modern ransomware investigations, as documented in recent reports on trusted Windows drivers.

During the September attack, the MeshAgent program was not renamed and connected to a different C2 server at 193.5.65[.]114. The ransomware launched from the compromised user’s Documents folder, encrypting files with a .locked_wip extension and depositing ransom notes in multiple directories. Researchers also linked this malicious activity to a specific workstation name, WIN-LIVFRVQFMKO, which had been previously associated with the C2 server.

Recovery Disruption Tactics

A hallmark of Settra ransomware is its aggressive approach to disrupting recovery efforts and erasing forensic trails. After initiating encryption, the attackers systematically cleared several Windows Event Logs and disabled the Windows Recovery Environment. They also utilized DiskPart in both incidents, seemingly to remove recovery partitions, and in the July case, flushed the DNS cache.

These actions are designed to prolong recovery times and reduce the amount of actionable evidence available to incident responders. In the July incident, Settra also executed the Windows Cipher utility to overwrite free space on a data drive, further complicating the retrieval of deleted information. Although the September operators attempted to remove Defender logging, a misspelling of the log channel name inadvertently left the Windows Defender Event Log intact. This underscores the importance of centralizing Windows event logs, which can preserve critical evidence even when attackers attempt to erase local records.

The two Settra cases demonstrate that the ransomware group does not necessarily require an entirely novel toolkit to inflict significant damage. By skillfully combining familiar tools, exploiting vulnerable drivers, and leveraging built-in Windows utilities, they can rapidly put defenders under immense pressure. Effective safeguards hinge on quick detection of abnormal RMM activity, robust protection of logs, and regularly rehearsed recovery procedures.

What You Should Do

  • Strengthen Remote Access Security: Implement multi-factor authentication (MFA) for all VPNs and remote access services. Regularly audit and restrict access based on the principle of least privilege.
  • Monitor RMM Tool Usage: Actively monitor the installation and usage of remote monitoring and management tools like MeshAgent. Investigate any unexpected deployments or connections to unknown external C2 servers.
  • Implement Endpoint Detection and Response (EDR): Utilize EDR solutions to detect suspicious process execution, unusual driver installations, and commands launched from atypical directories (e.g., user folders, performance-log directories).
  • Protect and Centralize Logs: Ensure that Windows Event Logs, especially security and Defender logs, are centrally collected and protected from tampering. This preserves forensic evidence even if local logs are cleared.
  • Maintain Robust Backup and Recovery Plans: Regularly create and test offline or immutable backups of critical data. Verify that Windows Recovery Environment and other recovery features remain enabled and functional.
  • Practice Incident Response: Conduct regular tabletop exercises and simulated encryption events to test your organization’s incident response playbooks. Include scenarios where endpoint visibility is compromised to prepare for real-world challenges.
  • Patch and Update: Keep all operating systems, applications, and drivers up to date to mitigate known vulnerabilities.
  • Educate Users: Train employees on identifying phishing attempts and the importance of strong, unique credentials to prevent initial access via stolen credentials.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachMalwareransomwareSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Four Critical Linux Kernel Privilege Escalation Flaws Let Attackers Gain Root Access

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Chrome 153 Update Patches 16 Vulnerabilities, Including Critical Dawn and WebGL Flaws
September 18, 2026
Android Apps Can Verify Missing Critical Security Patches
September 18, 2026
T-Mobile Phishing Scam Uses Fake Reward Expiry Texts
September 18, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us