New Settra Ransomware Hits Retail and Manufacturing Firms
Security researchers at Huntress have identified a new ransomware variant called Settra, first seen in June and used in attacks against a retail and consumer services company in July and a manufacturing firm in September. In both cases, the attackers used legitimate remote monitoring and management (RMM) tools to maintain persistent access to victim systems before deploying the ransomware.
In the retail incident, the attackers installed the MeshAgent RMM tool, which connected to infrastructure linked to the attackers' command-and-control servers. The following day, the ransomware was launched, encrypting files and appending them with a '.locked' extension before dropping a ransom note. Immediately afterwards, the attackers took steps to hinder recovery, including clearing Windows Event Logs, disabling the Windows Recovery Environment, flushing the DNS cache, and removing a recovery partition using native Windows tools.
The attackers also used the built-in Windows 'cipher' utility to overwrite free disk space, making deleted data harder to recover. Huntress noted that Settra has previously been linked to double-extortion tactics, where attackers threaten to leak stolen data as well as encrypt systems, though there is not yet enough evidence to confirm it operates as a ransomware-as-a-service model. The method of initial access in both incidents remains unconfirmed.