Find notable cyber news and cases, enriched with sources, timelines, and signals.

Settra ransomware deployments against retail and manufacturing victims

Malware Activity
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

The Settra ransomware variant is being deployed against retail and manufacturing victims, encrypting files and hindering recovery. It first appeared in June and was later used in incidents in July and September, showing repeated operational use. Attackers used MeshAgent RMM for persistent access and added BYOVD and other recovery-disruption steps to make restoration harder. The activity also overlaps with double-extortion tactics, raising pressure on affected organizations beyond encryption alone.

Related Happenings

Settra ransomware multi-incident campaign

Campaign
H score35 First: 18.09.2026 16:30 Last: 18.09.2026 16:30 Sources 1

How related: The variant was first observed in June, and Huntress researchers highlighted notable post-compromise techniques used by threat actors deploying Settra in attacks against an organization in the consumer services and retail sector in July, and a manufacturing firm in September.

About this happening: The Settra ransomware operation has been linked to repeated attacks across retail and manufacturing victims, indicating a coordinated campaign rather than isolated inc...

Ransom Busters rogue ransomware middleman skims payments across RaaS operations

Threat Actor Meta
H score19 First: 19.08.2026 23:59 Last: 19.08.2026 23:59 Sources 1

About this happening: Researchers identified Ransom Busters as a suspected ransomware middleman that contacts victims before attacks are public, offering decryption and data-deletion help while...

Ransom Busters as a rogue ransomware affiliate posing as a recovery middleman

Threat Actor Meta
H score19 First: 19.08.2026 23:59 Last: 19.08.2026 23:59 Sources 1

About this happening: Ransom Busters has emerged as a suspected rogue ransomware affiliate posing as a recovery service, creating a criminal middleman layer that can siphon ransom payments...

Timeline

  1. 18.09.2026 16:30 2 articles · 1h ago

    Settra ransomware deployments against retail and manufacturing victims

    Initial Disclosure

    Settra was first observed in June and later resurfaced in incidents in July and September. Early activity already showed a ransomware operation focused on persistent access and recovery disruption.

    Show sources