Huntress investigated July and September intrusions in which the emerging Settra ransomware operation deployed MeshAgent remote-management software for persistence, then ran ransomware binaries named for the victim domains to encrypt systems. The incidents affected consumer services, retail, and manufacturing organizations, while the group appears to opportunistically target organizations with exposed credentials or unpatched systems rather than a single industry. Settra, active since June 2026, uses double extortion and has claimed 93 victims; previous reporting has associated its access methods with compromised VPNs and stolen credentials.
The operators impaired recovery and forensic response by clearing Windows Event Logs, disabling the Windows Recovery Environment, deleting recovery partitions, and overwriting free disk space. In the September intrusion, they also likely used Gigabyte's vulnerable gdrv.sys driver in a Bring Your Own Vulnerable Driver (BYOVD) attempt to weaken endpoint protections. A typo in the log-clearing command left the Windows Defender Operational log intact, aiding investigators, while infrastructure associated with the campaign has been linked to malicious activity dating to December 2024.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Settra compromised a manufacturing firm, deployed MeshAgent using its default filename, and launched ransomware from the user's Documents folder, encrypting files with .locked_wip. The intrusion showed suspected use of the vulnerable Gigabyte gdrv.sys driver for BYOVD activity; a misspelled log-clearing command left the Windows Defender Operational log intact.
A Settra attack against a consumer services and retail organization deployed MeshAgent, renamed it mvtcs.exe, then executed ransomware from C:\Perflogs. The attackers encrypted files with a .locked extension and impaired recovery by clearing logs, disabling Windows Recovery Environment, removing a recovery partition, and overwriting free space.
Settra ransomware was first observed and became active in June 2026.
The workstation WIN-LIVFRVQFMKO, later linked to the September Settra intrusion, had been associated with IP address 193.5.65[.]114 as early as November 2025.
Huntress linked the September 2026 incident's workstation name and command-and-control IP to malicious activity dating to December 24, 2024.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.