Find notable cyber news and cases, enriched with sources, timelines, and signals.

Settra ransomware multi-incident campaign

Campaign
First reported
Last updated
Happening score
H score 35
1 unique sources, 1 articles

Summary

Hide ▲

The Settra ransomware operation has been linked to repeated attacks across retail and manufacturing victims, indicating a coordinated campaign rather than isolated incidents. The activity spans June through September and pairs MeshAgent RMM, BYOVD, and recovery-disabling steps to maintain access and complicate recovery. The pattern increases the risk of renewed encryption and double-extortion pressure for similar organizations.

Related Happenings

Settra ransomware deployments against retail and manufacturing victims

Malware Activity
H score31 First: 18.09.2026 16:30 Last: 18.09.2026 16:30 Sources 1

How related: A new ransomware variant named Settra has been deployed in incidents targeting the retail and manufacturing sectors, according to Huntress.

About this happening: The Settra ransomware variant is being deployed against retail and manufacturing victims, encrypting files and hindering recovery. It first appeared in June and wa...

Ransom Busters rogue ransomware middleman skims payments across RaaS operations

Threat Actor Meta
H score19 First: 19.08.2026 23:59 Last: 19.08.2026 23:59 Sources 1

About this happening: Researchers identified Ransom Busters as a suspected ransomware middleman that contacts victims before attacks are public, offering decryption and data-deletion help while...

Ransom Busters as a rogue ransomware affiliate posing as a recovery middleman

Threat Actor Meta
H score19 First: 19.08.2026 23:59 Last: 19.08.2026 23:59 Sources 1

About this happening: Ransom Busters has emerged as a suspected rogue ransomware affiliate posing as a recovery service, creating a criminal middleman layer that can siphon ransom payments...

Timeline

  1. 18.09.2026 16:30 2 articles · 1h ago

    Settra ransomware targets retail and manufacturing organizations

    Campaign Scope Update

    Settra ransomware has been used in incidents against retail and manufacturing organizations, with activity first observed in June and additional attacks in July and September. The post-compromise playbook included MeshAgent RMM for persistent access, recovery-sabotage steps such as clearing Windows Event Logs and disabling the Windows Recovery Environment, plus BYOVD on impacted systems; previous Settra activity was also linked to double-extortion pressure.

    Show sources