A new ransomware variant, named Settra, has been used in attacks against retail and manufacturing organisations, according to Huntress. The researchers first observed the malware in June and identified post-compromise activity in a consumer services and retail organisation in July, followed by a manufacturing firm in September. Huntress could not confirm how the attackers initially gained access, and said there was insufficient evidence to classify Settra as a ransomware-as-a-service operation.
Earlier research indicated that Settra operators used double extortion, encrypting systems while threatening to publish stolen corporate data.
In the retail incident, attackers installed the MeshAgent remote monitoring and management tool for persistent access before launching ransomware from `C:\Perflogs`. Files were encrypted and given the `.locked` extension. The attackers then cleared Windows Event Logs, disabled the Windows Recovery Environment, flushed the DNS cache and removed a recovery partition using `diskpart`. They also used Windows’ `cipher` utility to overwrite free space, making deleted data harder to recover.
The manufacturing incident followed a similar pattern but additionally involved bring-your-own-vulnerable-driver (BYOVD) activity, which can affect security tools and antivirus-related services. Huntress said one attempted log-clearing command contained a misspelling and therefore failed.
The workstation name `WIN-LIVFRVQFMKO` was linked to the September incident and had appeared in other incidents dating back to December 2024. In both cases, the ransomware executable was named after the victim organisation’s domain with `_win64.exe` appended. Huntress advised defenders to track emerging variants and their post-compromise techniques, while maintaining core security controls.