Huntress disclosed a new ransomware and data-extortion variant called Settra, first observed in June 2026, after investigating two incidents: a July attack on a consumer services and retail organization and a September attack on a manufacturing firm. In both cases the attackers deployed MeshAgent, a remote monitoring and management tool, for persistence, pointing to two different command-and-control addresses across the two incidents. The September intrusion also showed signs of a vulnerable driver, gdrv.sys, being staged, a bring-your-own-vulnerable-driver technique attackers use to blind or disable security tools. Both attacks ended with files encrypted under .locked or .locked_wip extensions, a RESTORE_FILES.txt ransom note, cleared Windows Event Logs, and use of the cipher utility to overwrite deleted data, and in both cases the ransomware executable was named after the victim’s own domain.

Separately, researchers at MoxFive reported that Settra has used compromised VPN credentials for initial access and is publishing victims to a shaming site, with the group claiming to specifically target organizations with exploitable weaknesses such as unpatched systems or weak access controls.

For security leaders, Settra’s tooling is not novel, RMM abuse and log clearing are established tradecraft, which is itself the point: capable rather than sophisticated operators can still run a functioning double-extortion business on commodity technique alone. The original wrinkle here is a verification gap: Huntress says it could not confirm how the two incidents it directly investigated began, even though public reporting points to VPN credentials, meaning what a ransomware group claims about its own access method and what incident responders can independently verify are not always the same thing. That gap matters when defenders decide which control failed and what to fix first. CyberTech has covered a similar initial-access pattern in a Node.js-based ransomware access broker and in a ransomware crew sharing an exploited Cisco bug with a nation-state actor.

Source: Huntress