Settra ransomware multi-incident campaign
Campaign
Summary
Hide ▲
Show ▼
The Settra ransomware operation has been linked to repeated attacks across retail and manufacturing victims, indicating a coordinated campaign rather than isolated incidents. The activity spans June through September and pairs MeshAgent RMM, BYOVD, and recovery-disabling steps to maintain access and complicate recovery. The pattern increases the risk of renewed encryption and double-extortion pressure for similar organizations.
Related Happenings
Settra ransomware deployments against retail and manufacturing victims
Malware Activity
H score31
First: 18.09.2026 16:30
Last: 18.09.2026 16:30
Sources 1
How related:
A new ransomware variant named Settra has been deployed in incidents targeting the retail and manufacturing sectors, according to Huntress.
About this happening:
The Settra ransomware variant is being deployed against retail and manufacturing victims, encrypting files and hindering recovery. It first appeared in June and wa...
Settra ransomware deployments against retail and manufacturing victims
Malware ActivityHow related: A new ransomware variant named Settra has been deployed in incidents targeting the retail and manufacturing sectors, according to Huntress.
About this happening: The Settra ransomware variant is being deployed against retail and manufacturing victims, encrypting files and hindering recovery. It first appeared in June and wa...
Ransom Busters rogue ransomware middleman skims payments across RaaS operations
Threat Actor Meta
H score19
First: 19.08.2026 23:59
Last: 19.08.2026 23:59
Sources 1
About this happening:
Researchers identified Ransom Busters as a suspected ransomware middleman that contacts victims before attacks are public, offering decryption and data-deletion help while...
Ransom Busters rogue ransomware middleman skims payments across RaaS operations
Threat Actor MetaAbout this happening: Researchers identified Ransom Busters as a suspected ransomware middleman that contacts victims before attacks are public, offering decryption and data-deletion help while...
Ransom Busters as a rogue ransomware affiliate posing as a recovery middleman
Threat Actor Meta
H score19
First: 19.08.2026 23:59
Last: 19.08.2026 23:59
Sources 1
About this happening:
Ransom Busters has emerged as a suspected rogue ransomware affiliate posing as a recovery service, creating a criminal middleman layer that can siphon ransom payments...
Ransom Busters as a rogue ransomware affiliate posing as a recovery middleman
Threat Actor MetaAbout this happening: Ransom Busters has emerged as a suspected rogue ransomware affiliate posing as a recovery service, creating a criminal middleman layer that can siphon ransom payments...
Timeline
-
18.09.2026 16:30 2 articles · 1h ago
Settra ransomware targets retail and manufacturing organizations
Campaign Scope UpdateSettra ransomware has been used in incidents against retail and manufacturing organizations, with activity first observed in June and additional attacks in July and September. The post-compromise playbook included MeshAgent RMM for persistent access, recovery-sabotage steps such as clearing Windows Event Logs and disabling the Windows Recovery Environment, plus BYOVD on impacted systems; previous Settra activity was also linked to double-extortion pressure.
Show sources
- New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing — www.infosecurity-magazine.com — 18.09.2026 16:30
- New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing — www.infosecurity-magazine.com — 18.09.2026 16:30