CyberSecurity SEE

New Settra Ransomware Variant Used in Attacks on Retail and Manufacturing

New Settra Ransomware Variant Used in Attacks on Retail and Manufacturing

New Ransomware Variant ‘Settra’ Targets Retail and Manufacturing Sectors

A newly identified ransomware variant named Settra has emerged as a significant threat, particularly targeting the retail and manufacturing sectors, according to a recent report from cybersecurity firm Huntress. The variant was first detected in June and has since shown a troubling capability to inflict specific tactics on organizations, especially those involved in consumer services and manufacturing.

Huntress researchers noted that in July, the Settra variant was deployed in an attack against a retail organization, followed by another incident targeting a manufacturing firm in September. Their analysis revealed several sophisticated post-compromise techniques employed by the threat actors. Notably, these tactics included the utilization of remote monitoring and management (RMM) tools to maintain persistent access to compromised systems, strategies to disable victims’ recovery options, and the installation of "bring your own vulnerable driver" (BYOVD) on affected machines.

The Huntress blog published on September 17 elaborated on the double-extortion tactics employed by attackers using Settra. This method involves not just the encryption of vital systems but also threats to publicly release sensitive corporate data. Such tactics increase pressure on the victim organizations to comply with the attackers’ demands, underscoring the ransomware’s serious implications.

While Huntress has shared valuable insights regarding Settra, researchers cautioned that there is currently insufficient evidence to categorize this variant as a ransomware-as-a-service (RaaS) operation, which has become prevalent in the cybercrime landscape.

Key Post-Compromise Activities

In their investigation, Huntress was unable to determine how the attackers initially gained access to the systems during the two incidents. However, details from the July attack reveal that the threat actors successfully installed the MeshAgent RMM tool within the victim’s environment. This tool then connected to an IP address associated with the command-and-control (C2) infrastructure utilized by the attackers.

Following the installation, the ransomware executable was launched from the C:\Perflogs folder. The execution of this file resulted in the encryption of victim files, which were subsequently renamed with a .locked file extension. A ransom note was then created, demanding payment for file recovery.

The EDR telemetry (Endpoint Detection and Response) provided alarming insights: immediately after the ransomware execution, the threat actors undertook actions aimed at crippling the victim organization’s recovery efforts. These actions included clearing several Windows Event Logs, disabling the Windows Recovery Environment, flushing the DNS cache using the ‘ipconfig /flushdns’ command, and leveraging the diskpart utility to eliminate recovery partitions.

Additionally, the perpetrators executed a command to overwrite free space on various file volumes, thereby complicating any subsequent attempts to recover deleted data.

In the subsequent attack against a manufacturing firm in September, attackers employed similar methodologies, including the deployment of MeshAgent RMM and disabling recovery options after launching the ransomware. However, the September attack did present a new element with the introduction of BYOVD, used to undermine onboard security and disrupt antivirus software.

Interestingly, researchers noted a blunder on the part of the attackers during the September incident; they misspelled a Windows Event Log while attempting to clear it, which compromised their efforts. The activity was tracked back to a workstation named WIN-LIVFRVQFMKO, previously associated with multiple incidents dating as far back as December 2024, as cataloged by Huntress.

In both attacks, the ransomware executable was named after the victim’s domain, with the filename ending in _win64.exe. Researchers pointed out that, despite some variations in execution—such as different naming conventions and C2 IP addresses—the overall structure of the attacks possessed a remarkable similarity.

Recommendations for Defenders

In light of these findings, Huntress researchers emphasized that the rapid evolution of ransomware variants presents continuous challenges for cybersecurity professionals. Each new variant introduces distinct tactics, techniques, and procedures (TTPs) that defenders need to understand.

To counter these threats, security teams are urged to remain vigilant and informed about emerging ransomware variants and the post-compromise techniques that accompany them. The emphasis on foundational aspects of cyber defense remains paramount, as these strategies are crucial for preventing ransomware attacks from taking hold in the first place.

The urgency of these recommendations is underscored by the rapid proliferation of ransomware threats, with new actors emerging at an alarming rate. Cybersecurity professionals are challenged more than ever to safeguard their organizations against this ever-evolving menace.

Source link

Exit mobile version