Settra is a Windows ransomware and data-extortion operation first observed in June 2026. It has affected organizations in consumer services, retail, and manufacturing, and appears to conduct opportunistic targeting rather than focus on a single sector. Settra encrypts files, appends distinct encrypted-file extensions observed across incidents, and leaves ransom notes directing victims to negotiate; reporting also associates the operation with double extortion, in which data disclosure is threatened alongside encryption.
Observed intrusions deployed MeshAgent remote monitoring and management software to maintain access and execute commands after compromise. Settra operators have attempted to impede investigation and recovery by clearing Windows Event Logs, disabling the Windows Recovery Environment, removing recovery partitions, flushing DNS caches, and overwriting free disk space to hinder recovery of deleted material. One incident showed evidence consistent with use of a bring-your-own-vulnerable-driver technique to interfere with endpoint security tooling. Initial access was not confirmed in the investigated incidents, though other reporting has associated Settra activity with compromised VPN access, stolen credentials, and exploitation of unpatched software. There is insufficient public evidence to classify Settra as a ransomware-as-a-service operation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
An emerging threat called Settra ransomware was observed in two recent attacks... The group uses double extortion tactics... In both cases a ransom note titled "RESTORE_FILES.txt" was created.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
In the July incident, MeshAgent was renamed to mvtcs.exe. In both cases, the ransomware executable was named after the victim's own domain, with '_win64.exe' appended.
« Effacement des journaux d’événements Windows » ; une faute de frappe a empêché l’effacement du journal Windows Defender dans un incident.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware that gains initial access through compromised VPNs or credentials, deploys RMM tools for persistence, encrypts victim files, drops RESTORE_FILES.txt ransom notes, clears Windows event logs, and disables Windows recovery options. One observed incident showed indicators of BYOVD use.
Windows-targeting ransomware that encrypts files and creates RESTORE_FILES.txt ransom notes. In the reported intrusions, operators deployed MeshAgent for remote access, used BYOVD in one case to interfere with defensive software, cleared Windows Event Logs, disabled the Windows Recovery Environment, used DiskPart to remove recovery partitions, and in one incident used Cipher to overwrite free space.
Windows ransomware that encrypts files, appends victim-specific extensions, and creates RESTORE_FILES.txt ransom notes. Operators used MeshAgent for remote control and performed recovery- and evidence-disruption actions, including clearing Windows Event Logs, disabling the Windows Recovery Environment, using DiskPart to remove recovery partitions, flushing DNS, and using Cipher to overwrite free space. One intrusion showed BYOVD activity using gdrv.sys, potentially to disable security services before encryption.
Settra is a ransomware variant used in targeted post-compromise attacks. It encrypts files and renames them with a .locked extension, creates a ransom note, and has been associated with double-extortion tactics involving threats to release sensitive corporate data. Operators used MeshAgent for persistent access and conducted recovery-inhibition activity, including disabling Windows Recovery Environment, removing recovery partitions, clearing logs, and overwriting free disk space. In one incident, they also used a bring-your-own-vulnerable-driver technique intended to affect security tooling or antivirus-related services.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.