Settra is a ransomware and extortion threat group that emerged publicly in 2026 and has been observed in incidents and victim claims across multiple countries. The group has been associated with data-theft and ransomware operations, including public victim shaming and leak-style exposure of stolen information. Settra has appeared in ransomware activity tracking as a newer entrant and has been linked to attacks against organizations in construction, business services, industrial-related enterprises, and at least one e-commerce-related target in Taiwan. Settra has been referenced in incident-response investigations involving a separate actor using the name Ransom Busters, which researchers assessed with moderate confidence to be a ransomware affiliate operating across multiple ransomware-as-a-service ecosystems, including Settra, DragonForce, and Anubis. In those linked intrusions, overlapping tradecraft included internal reconnaissance with network scanning, exfiltration to cloud storage, deployment of remote-management tooling, and creation of local backdoor accounts, indicating that affiliates associated with Settra-linked cases have used common post-compromise tooling and secondary extortion tactics. Victim reporting and public claims tie Settra to ransomware attacks in the United States, Germany, Great Britain, and Taiwan. Reported victims include organizations in construction and business services, as well as a diamond mining company and a company supporting chemical and defense production. Settra also claimed compromise of Pi Mobile Technology, a subsidiary of PChome Online in Taiwan, alleging theft of internal documents and user data. Public reporting indicates that some Settra-attributed incidents involved both ransomware and data-breach elements, consistent with contemporary extortion operations that combine system compromise with theft of sensitive information. Settra’s observed behavior supports assessment of a financially motivated cybercriminal actor engaged in extortion-oriented intrusions. High-confidence reporting supports capabilities including initial access, reconnaissance, exfiltration, persistence through backdoor account creation, and post-exploitation activity. Publicly available information does not establish a confirmed national-state sponsor or a verified country of origin for Settra.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware operation linked to incidents in which the 'Ransom Busters' outfit contacted victims and allegedly attempted to divert ransom payments.
Named as one of the ransomware groups whose attacks were linked to incidents in which Ransom Busters contacted victims.
Named RaaS operation linked to incidents where the same affiliate behavior attributed to Ransom Busters was observed.
Named as one of the ransomware-as-a-service operations whose stolen-data servers Ransom Busters claimed it could access and delete data from.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.