"While there were slight differences between the two incidents... the overall conduct of the attacks were remarkably similar," Huntress researchers wrote on September 17, describing a new ransomware variant deployed against retail and manufacturing firms.
Timeline: Settra first seen in June; tracked in July and September incidents
Huntress first observed the Settra ransomware variant in June and published detailed findings on September 17. The researchers highlighted two post-compromise cases: an attack against an organization in the consumer services and retail sector in July, and a separate incident against a manufacturing firm in September.
How the July retail incident unfolded
In the July case, Huntress reported that attackers installed the MeshAgent remote monitoring and management (RMM) tool in the victim environment. That MeshAgent instance connected to an IP address Huntress linked to the attackers’ command-and-control (C2) infrastructure. The ransomware executable was launched the next day from the C:\Perflogs folder. Victim files were encrypted and renamed with the .locked extension, and a ransom note was created.
Endpoint detection and response (EDR) telemetry showed a sequence of actions taken immediately after the ransomware launched: attackers cleared several Windows Event Logs, disabled the Windows Recovery Environment, ran ipconfig /flushdns to flush DNS cache, and executed the native Windows diskpart utility via script to remove a recovery partition. The actors also ran cmd.exe /c cipher /w:D:\ >nul 2>&1 to overwrite free space on multiple volumes, a tactic intended to make recovery of deleted data more difficult.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildSeptember manufacturing incident: similar pattern plus BYOVD
The September attack against a manufacturing organization showed largely the same post-compromise playbook: installation of MeshAgent RMM, launching a domain-named executable (the ransomware binary matched the victim organization’s domain name with _win64.exe appended), and attempts to disable recovery options. Huntress noted one distinct addition in this incident: the use of a bring your own vulnerable driver (BYOVD).
Huntress described BYOVD as a driver installed to impact onboard security tooling and to crash services related to antivirus applications. During the September activity, the attackers also attempted to clear Windows Event Logs but misspelled one of the logs they targeted, which prevented that particular clearing action from succeeding. Huntress associated the workstation name WIN-LIVFRVQFMKO with the malicious activity in September; that hostname had previously been observed in incidents going back to December 2024 in Huntress telemetry.
MeshAgent, C2 behavior, and the shape of the threat
Across both incidents the researchers called out recurring operational details: MeshAgent RMM was used to establish persistent access and to pivot to ransomware execution; the ransomware executables were consistently named for the victim domain with a _win64.exe suffix; and operators moved to disable recovery and frustrate restoration by clearing logs, removing recovery partitions, and overwriting free space.
Huntress also noted prior research linking Settra to double-extortion tactics, where attackers both encrypt systems and threaten to release sensitive corporate information. At the same time, the researchers said there is currently not enough evidence to classify Settra as a ransomware-as-a-service (RaaS) operation.
What this means for security teams, retail firms, and manufacturers
- Security teams: The incidents highlight a post-compromise emphasis—persistent RMM deployment, recovery sabotage, and BYOVD use—that defenders should monitor in telemetry and hunt for in their environments.
- Retail firms: The July case demonstrates how a retail organization’s environment can be used to stage ransomware rapidly once RMM access is established; defenders should watch for unusual MeshAgent installations and C2 connections tied to known malicious IPs.
- Manufacturers: The September case shows an additional risk vector in BYOVD deployment, which can directly affect onboard security tooling and antivirus services; manufacturers should validate driver inventories and monitor for unexpected driver installs.
Recommendations Huntress issued for defenders
Huntress urged defenders to stay current with emerging ransomware variants and to track the specific post-compromise techniques actors use to detect and respond effectively. The researchers also emphasized focusing on cyber defense "fundamentals" to prevent these attacks — a recommendation that mirrors the concrete techniques observed in both incidents, from detecting unauthorized RMM software to monitoring for attempts to disable recovery mechanisms.
Settra’s early operational pattern — repeatable RMM deployment, recovery sabotage, and, in one case, BYOVD installation — presents a compact set of behaviors defenders can hunt for. The continuing open question Huntress noted is whether Settra represents a broader service model such as RaaS; for now, the evidence remains insufficient to declare that classification.




