Settra ransomware deployments against retail and manufacturing victims
Malware Activity
Summary
Hide ▲
Show ▼
The Settra ransomware variant is being deployed against retail and manufacturing victims, encrypting files and hindering recovery. It first appeared in June and was later used in incidents in July and September, showing repeated operational use. Attackers used MeshAgent RMM for persistent access and added BYOVD and other recovery-disruption steps to make restoration harder. The activity also overlaps with double-extortion tactics, raising pressure on affected organizations beyond encryption alone.
Related Happenings
Settra ransomware multi-incident campaign
Campaign
H score35
First: 18.09.2026 16:30
Last: 18.09.2026 16:30
Sources 1
How related:
The variant was first observed in June, and Huntress researchers highlighted notable post-compromise techniques used by threat actors deploying Settra in attacks against an organization in the consumer services and retail sector in July, and a manufacturing firm in September.
About this happening:
The Settra ransomware operation has been linked to repeated attacks across retail and manufacturing victims, indicating a coordinated campaign rather than isolated inc...
Settra ransomware multi-incident campaign
CampaignHow related: The variant was first observed in June, and Huntress researchers highlighted notable post-compromise techniques used by threat actors deploying Settra in attacks against an organization in the consumer services and retail sector in July, and a manufacturing firm in September.
About this happening: The Settra ransomware operation has been linked to repeated attacks across retail and manufacturing victims, indicating a coordinated campaign rather than isolated inc...
Ransom Busters rogue ransomware middleman skims payments across RaaS operations
Threat Actor Meta
H score19
First: 19.08.2026 23:59
Last: 19.08.2026 23:59
Sources 1
About this happening:
Researchers identified Ransom Busters as a suspected ransomware middleman that contacts victims before attacks are public, offering decryption and data-deletion help while...
Ransom Busters rogue ransomware middleman skims payments across RaaS operations
Threat Actor MetaAbout this happening: Researchers identified Ransom Busters as a suspected ransomware middleman that contacts victims before attacks are public, offering decryption and data-deletion help while...
Ransom Busters as a rogue ransomware affiliate posing as a recovery middleman
Threat Actor Meta
H score19
First: 19.08.2026 23:59
Last: 19.08.2026 23:59
Sources 1
About this happening:
Ransom Busters has emerged as a suspected rogue ransomware affiliate posing as a recovery service, creating a criminal middleman layer that can siphon ransom payments...
Ransom Busters as a rogue ransomware affiliate posing as a recovery middleman
Threat Actor MetaAbout this happening: Ransom Busters has emerged as a suspected rogue ransomware affiliate posing as a recovery service, creating a criminal middleman layer that can siphon ransom payments...
Timeline
-
18.09.2026 16:30 2 articles · 1h ago
Settra ransomware deployments against retail and manufacturing victims
Initial DisclosureSettra was first observed in June and later resurfaced in incidents in July and September. Early activity already showed a ransomware operation focused on persistent access and recovery disruption.
Show sources
- New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing — www.infosecurity-magazine.com — 18.09.2026 16:30
- New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing — www.infosecurity-magazine.com — 18.09.2026 16:30