Security News

New Settra Ransomware Hits Retail and Manufacturing Firms

Infosecurity Magazine · 18 Sept 2026
Key Takeaway Monitor for unauthorised RMM tools and unusual use of native Windows utilities like cipher and diskpart, as these are early warning signs of a ransomware attack in progress.

Security researchers at Huntress have identified a new ransomware variant called Settra, first seen in June and used in attacks against a retail and consumer services company in July and a manufacturing firm in September. In both cases, the attackers used legitimate remote monitoring and management (RMM) tools to maintain persistent access to victim systems before deploying the ransomware.

In the retail incident, the attackers installed the MeshAgent RMM tool, which connected to infrastructure linked to the attackers' command-and-control servers. The following day, the ransomware was launched, encrypting files and appending them with a '.locked' extension before dropping a ransom note. Immediately afterwards, the attackers took steps to hinder recovery, including clearing Windows Event Logs, disabling the Windows Recovery Environment, flushing the DNS cache, and removing a recovery partition using native Windows tools.

The attackers also used the built-in Windows 'cipher' utility to overwrite free disk space, making deleted data harder to recover. Huntress noted that Settra has previously been linked to double-extortion tactics, where attackers threaten to leak stolen data as well as encrypt systems, though there is not yet enough evidence to confirm it operates as a ransomware-as-a-service model. The method of initial access in both incidents remains unconfirmed.

ransomware Settra retail manufacturing Huntress

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.