An emerging threat called Settra ransomware was observed in two recent attacks by Huntress analysts, revealing the use of the MeshAgent RMM and potential Bring Your Own Vulnerable Driver (BYOVD) tactics by the threat actor, Huntress reported Thursday.The Settra ransomware group, which has been active since June 2026, has so far claimed a total of 93 victims, according to information from SOCRadar. The group uses double extortion tactics, with at least four of the claimed victims having their data leaked by Settra, however, there is no evidence it operates under a ransomware-as-a-service model, according to MOXFIVE.For initial access, Settra typically leverages compromised credentials, including VPN credentials, and exploits unpatched software, as previously reported by MOXFIVE and SOCRadar. In the attacks reported by Huntress, which occurred in July and September, the initial access methods could not be determined, but the use of the MeshAgent RMM and encryption of files was observed.In the first incident, the MeshAgent RMM was deployed under the name mvtcs.exe. MeshAgent is an open-source remote device management tool for Windows, Linux, macOS and FreeBSD that is available on GitHub, with devices being managed through a MeshCentral server.
Related reading:
“We’ve seen MeshAgent across many attacks, but it’s not one of the most common RMMs Huntress sees being abused. In previous attacks, we’ve seen threat actors installing renamed malicious MeshAgent instances and using MeshAgent instances to install further RMMs (like ScreenConnect) for persistence,” Lindsey O’Donnell-Welch, principal technical community engagement writer at Huntress, told SC Media.MeshAgent was also installed in the September attack, though it was not renamed, and connected to a separate IP address. In this later attack, Huntress found evidence of possible BYOVD tactics, specifically installation of the vulnerable Gigabyte gdrv.sys kernel driver. BYOVD is typically used to disrupt security tools at the kernel level.Evasion and anti-recovery tactics were observed in both incidents, with the ransomware clearing multiple Windows Events Logs, disabling the Windows Recovery Environment via “reagentc /disable,” flushing the DNS cache with “ipconfig /flushdns” and using a script to run diskpart and remove the recovery partition in the first incident. It also used the Windows “cipher” utility to overwrite previously deleted free space in order to make it more difficult to recover deleted data.In the second incident, in which the Huntress agent was installed mid-incident, the ransomware executable also disabled the Windows Recovery Environment, removed the recovery partition and cleared several Windows Event Logs. However, Huntress noted that an incorrect spelling of the “Microsoft-Windows-Windows-Defender/Operational” event log in the attacker’s code prevented its deletion in this case.Both ransomware executables included the name of the victim organization’s domain appended with “_win64.exe” and in both cases a ransom note titled “RESTORE_FILES.txt” was created. In the first incident, the executable was launched from C:\Perflogs and encrypted files were given the “.locked” extension, while in the second incident, the executable was launched from the Documents folder and the encrypted files were appended with “.locked_wip”.“The best opportunity for defenders to detect the attack and prevent encryption is during the threat actor’s initial attempts to gain access. Defenders should also prioritize alerts for unauthorized MeshAgent instances or suspicious driver deployment, especially when followed by event-log clearing or recovery tampering, since these early post-compromise behaviors offer the best chance to stop Settra before encryption begins,” O’Donnell-Welch told SC Media.Settra typically communicates with victims for negotiations over Tox chat. The group appears to opportunistically target organizations with unpatched systems and exposed credentials rather than targeting a specific industry, with claimed victims including retail and hospitality, manufacturing and production, professional services, construction and engineering, and food and beverage companies, according to MOXFIVE.Huntress’ investigation connected the workstation name and C2 IP address from the September incident to previous malicious activity dating back to Dec. 24, 2024. A VirusTotal search for the IP address reveals 11 out of 89 security vendors flag this IP as malicious, with one community comment reporting its use in an attack deploying the AdaptixC2 framework.
Ransomware
Settra ransomware group uses MeshAgent RMM in recent attacks
An In-Depth Guide to Ransomware
Get essential knowledge and practical strategies to protect your organization from ransomware attacks.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds