Huntress investigated two Settra ransomware and data-extortion incidents affecting a consumer services and retail organization and a manufacturing company. In both cases, attackers installed MeshAgent remote monitoring and management software for persistence, ran a victim-domain-named ransomware payload ending in _win64.exe, encrypted files, and left RESTORE_FILES.txt ransom notes.
The operators attempted to prevent recovery and hinder forensic investigation by disabling the Windows Recovery Environment, executing DiskPart with a likely recovery-partition removal script, and clearing Windows Event Logs. One intrusion also used the vulnerable gdrv.sys driver, consistent with a bring-your-own-vulnerable-driver technique, while another ran cipher /w to overwrite free disk space and impede recovery of deleted files.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
Huntress linked WIN-LIVFRVQFMKO with 193.5.65[.]114 in incidents observed from November 2025 through February 2026.
Huntress observed the workstation name WIN-LIVFRVQFMKO in other incidents dating to December 24, 2024.
The manufacturing-targeting ransomware binary ran reagentc.exe /disable and DiskPart against an unrecovered script, and cleared numerous Windows Event Logs. Its attempt to clear the Windows Defender Operational log failed because it used a misspelled log name.
A Settra incident affected a manufacturing company. The attackers used the gdrv.sys bring-your-own-vulnerable-driver, deployed MeshAgent communicating with 193.5.65[.]114, encrypted files with a .locked_wip extension, and created RESTORE_FILES.txt ransom notes.
During the consumer-services incident, attackers cleared Windows Event Logs, disabled the Windows Recovery Environment, ran DiskPart against an unrecovered script likely targeting a recovery partition, and used cipher /w to overwrite free space on the D: volume.
A Settra incident affected a consumer services and retail organization. Attackers deployed MeshAgent renamed to mvtcs.exe, encrypted files with a .locked extension, and left RESTORE_FILES.txt ransom notes.
Settra, a ransomware and data-extortion variant described as focused on global extortion, was first publicly observed in June.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.