Settra ransomware activity using MeshAgent
Malware Activity
Summary
Hide ▲
Show ▼
The Settra ransomware group used MeshAgent remote access software in two analyzed intrusions, adding persistence and file encryption to its attack chain. Attackers dropped RESTORE_FILES.txt ransom notes, cleared Windows event logs, and disabled Windows recovery options to hinder response and recovery. One intrusion also showed signs of Bring Your Own Vulnerable Driver (BYOVD) abuse, and the group has since been tied to 70 claimed victims across multiple countries.
Related Happenings
Aurora ransomware Cursor Agent exploitation campaign
Campaign
H score24
First: 28.08.2026 11:00
Last: 28.08.2026 11:00
Sources 1
About this happening:
Aurora ransomware operators used Cursor Agent and Claude Sonnet to support post-compromise exploitation against 10 victims between April 8 and May 26, 2026...
Aurora ransomware Cursor Agent exploitation campaign
CampaignAbout this happening: Aurora ransomware operators used Cursor Agent and Claude Sonnet to support post-compromise exploitation against 10 victims between April 8 and May 26, 2026...
Ransom Busters rogue ransomware middleman skims payments across RaaS operations
Threat Actor Meta
H score19
First: 19.08.2026 23:59
Last: 19.08.2026 23:59
Sources 1
About this happening:
Researchers identified Ransom Busters as a suspected ransomware middleman that contacts victims before attacks are public, offering decryption and data-deletion help while...
Ransom Busters rogue ransomware middleman skims payments across RaaS operations
Threat Actor MetaAbout this happening: Researchers identified Ransom Busters as a suspected ransomware middleman that contacts victims before attacks are public, offering decryption and data-deletion help while...
Ransom Busters as a rogue ransomware affiliate posing as a recovery middleman
Threat Actor Meta
H score19
First: 19.08.2026 23:59
Last: 19.08.2026 23:59
Sources 1
About this happening:
Ransom Busters has emerged as a suspected rogue ransomware affiliate posing as a recovery service, creating a criminal middleman layer that can siphon ransom payments...
Ransom Busters as a rogue ransomware affiliate posing as a recovery middleman
Threat Actor MetaAbout this happening: Ransom Busters has emerged as a suspected rogue ransomware affiliate posing as a recovery service, creating a criminal middleman layer that can siphon ransom payments...
Chaos ransomware deployment in STAC4749 intrusions
Malware Activity
H score31
First: 30.07.2026 18:56
Last: 30.07.2026 18:56
Sources 1
About this happening:
The Chaos ransomware activity was deployed in at least three intrusions, including one case that reached file encryption in under 17 hours. Attackers used Microsoft...
Chaos ransomware deployment in STAC4749 intrusions
Malware ActivityAbout this happening: The Chaos ransomware activity was deployed in at least three intrusions, including one case that reached file encryption in under 17 hours. Attackers used Microsoft...
IT services firm in South Asia hit by ransomware attack
Incident
H score31
First: 16.07.2026 13:00
Last: 16.07.2026 13:00
Sources 1
About this happening:
The IT services firm in South Asia suffered a Spirals ransomware intrusion that moved from initial access to data theft and encryption in less than 24 hours, putti...
IT services firm in South Asia hit by ransomware attack
IncidentAbout this happening: The IT services firm in South Asia suffered a Spirals ransomware intrusion that moved from initial access to data theft and encryption in less than 24 hours, putti...
Timeline
-
17.09.2026 20:32 2 articles · 11h ago
Settra deploys MeshAgent in two ransomware intrusions
Initial DisclosureThe Settra ransomware group used MeshAgent remote access software in two intrusions analyzed by Huntress, showing a ransomware operation that incorporated unauthorized remote access tooling into the intrusion chain.
Show sources
- ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories — thehackernews.com — 17.09.2026 20:32
- ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories — thehackernews.com — 17.09.2026 20:32