Settra is the name researchers have given a ransomware operation that gets in through VPN gateways or stolen logins, then parks itself behind remote monitoring and management agents.
Huntress watched it twice: a consumer services and retail business in July, a manufacturer in September. A second firm, MoxFive, tracks the same crew posting victims to a shaming site and picking targets with unpatched systems or loose access management.
Tradecraft is conventional rather than novel, said Huntress’s Lindsey O’Donnell-Welch, listing MeshAgent for persistence, a vulnerable driver to knock out defenses, wiped logs and broken recovery options.
The tell is in filenames. Executables arrived named after each victim’s own domain. In July, MeshAgent was renamed mvtcs.exe and called home to a command-and-control address, with encryption and a ransom note arriving a day later.
Cleanup was thorough: Windows Event Logs cleared, the Windows Recovery Environment switched off, a recovery partition removed. September brought a bring-your-own-vulnerable-driver move to blunt onboard security tools.
Where to aim defenses
Stolen credentials at the VPN edge are the entry point, which puts phishing-resistant authentication and session review at the top of the list. Cut RMM agents down to an approved inventory. And when logs or recovery partitions go missing, respond as if an intruder is still inside.
