New Insights into Settra Ransomware Incidents
In a revealing analysis, researchers at Huntress have detailed two distinct incidents involving a relatively new strain of ransomware known as Settra. First observed in June, this particular variant has raised alarms among cybersecurity experts, leading to discussions about its post-compromise tactics. The insights provided by Huntress could serve as a guide for organizations aiming to identify and mitigate this emerging threat before encryption takes hold.
In a blog post released this week, Huntress researchers, Harlan Carvey and Lindsey O’Donnell-Welch, highlighted their investigations into two Settra attacks that occurred since July. The first incident targeted a consumer services and retail organization, while the second occurred in September, affecting a manufacturing firm. Notably, in the latter case, the Huntress agent was deployed only after the attackers had compromised the environment, suggesting that the threat actors might still have been active within the network during their investigation.
Huntress reported that it had not confirmed the exact method by which the attackers gained initial access in either incident. However, earlier analyses, including a report by incident response firm MoxFive published in July, suggested that compromised Virtual Private Networks (VPNs) and stolen credentials are potential routes of entry for Settra activity. This understanding raises concerns about the security precautions that many organizations may overlook.
A Disturbing Pattern of Intrusion
Despite the attacks being approximately two months apart and involving unrelated organizations, the patterns of the two intrusions were strikingly similar. In both cases, the ransomware executable was cleverly named after the victim’s domain, appended with “_win64.exe.” Additionally, the attackers demonstrated their technical prowess by utilizing the legitimate MeshAgent remote monitoring and management (RMM) tool to ensure persistent access, a tactic that complicates detection efforts.
In the July incident, the attackers renamed MeshAgent to mvtcs.exe, which then established communication with a command-and-control (C2) address at 45.13.122[.]7. Alarmingly, the ransomware executable was activated a day later from the C:\Perflogs folder, initiating the encryption of files with a “.locked” extension. The attackers left a ransom note titled RESTORE_FILES.txt. They took further destructive actions, such as clearing multiple Windows Event Logs, disabling the Windows Recovery Environment using the reagentc /disable command, and running diskpart to erase a recovery partition. To complicate recovery efforts, they even employed the native Windows cipher utility to overwrite free disk space.
In contrast, during the September incident, the MeshAgent retained its original name and connected to a different C2 address, 193.5.65[.]114. The ransomware was executed from the compromised user’s Documents folder instead of the Perflogs directory. This intrusion also showed evidence of Bring Your Own Vulnerable Driver (BYOVD) activity through a driver named gdrv.sys, a technique typically used to disable or obfuscate endpoint security tools.
Unexpected Clues Amidst Chaos
One particularly telling detail caught the attention of Huntress analysts: during the September attack, the ransomware attempted to purge twelve Windows Event Logs, but one entry was misspelled. It erroneously referred to “Microsoft-Windows-Defender/Operational” instead of the correct “Microsoft-Windows-Windows-Defender/Operational.” This minor oversight proved beneficial, as it allowed investigators to obtain additional forensic evidence from the surviving log.
Huntress further connected the September attack to a workstation identified as WIN-LIVFRVQFMKO, previously associated with unrelated incidents dating back to December 2024. This machine had also been tied to the same C2 address identified as far back as November 2025. Such connections imply a broader network of criminal activity that extends beyond isolated incidents.
A Broader Context of Ransomware Threats
Huntress emphasized that Settra represents the latest addition to a series of emerging ransomware variants tracked by its Security Operations Center (SOC) throughout the year, alongside strains like Crux, KawaLocker, and Cephalus. While the researchers have yet to find public evidence indicating that Settra operates on a ransomware-as-a-service (RaaS) model, they underscore that the techniques observed—such as RMM abuse, BYOVD tactics, and efforts to erase Windows Event Logs—are consistent across many ransomware operations, transcending brand distinctions.
In light of these findings, Huntress encouraged defenders to maintain vigilance towards unexpected RMM installations and to monitor for attempts to disable Windows recovery options or clear event logs. Their advice underscores the importance of focusing not merely on preventing initial attacks but also on enhancing detection capabilities for post-compromise behaviors.
Furthermore, Huntress has published indicators of compromise related to both incidents. These include the two MeshAgent C2 addresses, the name of the malicious workstation, the RESTORE_FILES.txt ransom note, the gdrv.sys driver, and the two file extensions used to indicate encrypted files.
The relevance and urgency of these insights cannot be overstated. As ransomware threats continue to evolve, an informed and proactive approach to cybersecurity remains crucial for organizations of all sizes. This latest research from Huntress stands as a significant reminder that vigilance and adaptability are paramount in the ever-changing landscape of cyber threats.

