New SETTRA Ransomware Leverages MeshAgent RMM and BYOVD to Encrypt Windows Systems
Key Takeaways Settra ransomware is actively targeting Windows networks, leveraging remote management tools and vulnerable drivers. Initial access is often gained via compromised VPNs or stolen...
Key Takeaways
- Settra ransomware is actively targeting Windows networks, leveraging remote management tools and vulnerable drivers.
- Initial access is often gained via compromised VPNs or stolen credentials, highlighting the importance of strong access controls.
- The ransomware employs sophisticated tactics to hinder recovery and forensic analysis, including clearing event logs and disabling recovery environments.
- Two distinct incidents in July and September involving consumer services/retail and manufacturing sectors, respectively, demonstrate the group’s evolving techniques.
- Organizations should prioritize robust access security, monitor RMM tool usage, and maintain secure, tested backups to mitigate risk.
A new ransomware strain, dubbed Settra, is actively targeting Windows environments, exhibiting advanced tactics that combine legitimate remote management software with techniques designed to impede recovery and forensic efforts. Cybersecurity researchers have linked Settra to at least two recent intrusions, underscoring its emerging threat profile.
Table Of Content
The ransomware encrypts critical files, delivers ransom notes to victims, and then takes steps to complicate both incident response and data restoration. Investigations suggest that the Settra operators initially compromise networks through vulnerable virtual private networks (VPNs) or by exploiting previously stolen credentials. This indicates that inadequate remote access security and weak account management remain significant points of vulnerability for organizations.
Furthermore, the attackers’ use of legitimate administrative software, specifically remote monitoring and management (RMM) tools, reflects a broader trend of threat actors co-opting trusted applications to maintain persistence and execute malicious operations post-breach.
Analysis of Settra Operations
Analysts at Huntress have documented two specific incidents involving Settra ransomware. The first occurred in July, impacting an organization in the consumer services and retail sector. The second, in September, targeted a manufacturing company. While the initial breach vectors for both incidents could not be definitively confirmed, Huntress observed strikingly similar post-compromise behaviors in each case, as detailed in a report shared with Cyber Security News (CSN).
According to Huntress, the significance of these attacks lies in the combination of rapid data encryption with deliberate actions to obstruct recovery and eliminate forensic evidence. A notable characteristic observed was the ransomware executable’s naming convention; it adopted a name based on the victim organization’s domain, likely an attempt to blend in and appear less suspicious on the compromised system.
MeshAgent RMM and BYOVD Exploitation
In both documented Settra intrusions, the attackers deployed MeshAgent, an open-source remote monitoring and management tool, after gaining initial access. RMM tools like MeshAgent are highly valuable to attackers because they provide a persistent and versatile channel for maintaining control, executing commands, and advancing their objectives without relying exclusively on custom malware. This strategy echoes other recent incidents, such as a FortiGate intrusion that also leveraged MeshAgent for post-breach activities.
In the July incident, the MeshAgent program was renamed to mvtcs.exe and established communication with an attacker-controlled command-and-control (C2) server at 45.13.122[.]7. The following day, researchers witnessed the ransomware being executed from a Windows performance-log directory, encrypting files with a .locked extension, and creating a ransom note named RESTORE_FILES.txt.
The September incident revealed an even more sophisticated tactic: the use of Bring Your Own Vulnerable Driver (BYOVD). This technique involves exploiting a legitimate but flawed kernel-mode driver, in this case, gdrv.sys, to interfere with security software. By leveraging such a driver, attackers can potentially disable endpoint security solutions before initiating encryption, significantly increasing their chances of success. This highlights why BYOVD has become a recurring concern in modern ransomware investigations, as documented in recent reports on trusted Windows drivers.
During the September attack, the MeshAgent program was not renamed and connected to a different C2 server at 193.5.65[.]114. The ransomware launched from the compromised user’s Documents folder, encrypting files with a .locked_wip extension and depositing ransom notes in multiple directories. Researchers also linked this malicious activity to a specific workstation name, WIN-LIVFRVQFMKO, which had been previously associated with the C2 server.
Recovery Disruption Tactics
A hallmark of Settra ransomware is its aggressive approach to disrupting recovery efforts and erasing forensic trails. After initiating encryption, the attackers systematically cleared several Windows Event Logs and disabled the Windows Recovery Environment. They also utilized DiskPart in both incidents, seemingly to remove recovery partitions, and in the July case, flushed the DNS cache.
These actions are designed to prolong recovery times and reduce the amount of actionable evidence available to incident responders. In the July incident, Settra also executed the Windows Cipher utility to overwrite free space on a data drive, further complicating the retrieval of deleted information. Although the September operators attempted to remove Defender logging, a misspelling of the log channel name inadvertently left the Windows Defender Event Log intact. This underscores the importance of centralizing Windows event logs, which can preserve critical evidence even when attackers attempt to erase local records.
The two Settra cases demonstrate that the ransomware group does not necessarily require an entirely novel toolkit to inflict significant damage. By skillfully combining familiar tools, exploiting vulnerable drivers, and leveraging built-in Windows utilities, they can rapidly put defenders under immense pressure. Effective safeguards hinge on quick detection of abnormal RMM activity, robust protection of logs, and regularly rehearsed recovery procedures.
What You Should Do
- Strengthen Remote Access Security: Implement multi-factor authentication (MFA) for all VPNs and remote access services. Regularly audit and restrict access based on the principle of least privilege.
- Monitor RMM Tool Usage: Actively monitor the installation and usage of remote monitoring and management tools like MeshAgent. Investigate any unexpected deployments or connections to unknown external C2 servers.
- Implement Endpoint Detection and Response (EDR): Utilize EDR solutions to detect suspicious process execution, unusual driver installations, and commands launched from atypical directories (e.g., user folders, performance-log directories).
- Protect and Centralize Logs: Ensure that Windows Event Logs, especially security and Defender logs, are centrally collected and protected from tampering. This preserves forensic evidence even if local logs are cleared.
- Maintain Robust Backup and Recovery Plans: Regularly create and test offline or immutable backups of critical data. Verify that Windows Recovery Environment and other recovery features remain enabled and functional.
- Practice Incident Response: Conduct regular tabletop exercises and simulated encryption events to test your organization’s incident response playbooks. Include scenarios where endpoint visibility is compromised to prepare for real-world challenges.
- Patch and Update: Keep all operating systems, applications, and drivers up to date to mitigate known vulnerabilities.
- Educate Users: Train employees on identifying phishing attempts and the importance of strong, unique credentials to prevent initial access via stolen credentials.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.