A newly cataloged ransomware family called Settra is quietly building a track record of aggressive, hands-on-keyboard attacks, and a fresh investigation from Huntress shows that even sophisticated threat actors can trip over their own typos.
First spotted in June 2026, Settra has already hit organizations in consumer retail and manufacturing, leaning on stolen VPN credentials, remote monitoring tools, and vulnerable driver abuse to lock down networks before encrypting files.
Public reporting, including analysis from MoxFive in July, indicates Settra’s operators favor compromised VPN access or stolen credentials to get a foothold, then install the legitimate MeshAgent RMM tool to maintain persistence while masquerading as normal administrative traffic.
Settra Ransomware Deploys MeshAgent RMM, BYOVD Attacks
SOCRadar has since classified Settra as a dedicated ransomware-and-extortion operation, though no evidence yet confirms it runs as a ransomware-as-a-service affiliate model.

Huntress investigated two Settra incidents of its own: one in July at a retail and consumer services firm, another in September at a manufacturer.
In both cases, the ransomware binary was named after the victim’s own domain, appended with _win64.exe, a small but telling signature suggesting a consistent build process across victims.
In the July incident, MeshAgent RMM was renamed to mvtcs.exe and beaconed to command-and-control infrastructure at 45.13.122[.]7 before the ransomware launched from the C:\Perflogs directory the following day. Files were encrypted with a .locked extension, and a RESTORE_FILES.txt ransom note appeared.
The attackers then cleared Windows Event Logs, disabled Windows Recovery Environment via reagentc /disable, flushed DNS, deleted recovery partitions with diskpart, and used the native cipher utility to overwrite free disk space in a methodical effort to frustrate recovery and forensics alike.
The September intrusion, caught mid-attack when Huntress’s agent was deployed onto an already-compromised host, revealed a Bring Your Own Vulnerable Driver (BYOVD) technique using the gdrv.sys driver, absent in the July case.
This time, MeshAgent ran unrenamed, pointing to 193.5.65[.]114, an IP tied to a workstation name, WIN-LIVFRVQFMKO, that Huntress has linked to malicious activity dating back to December 2024.
Here’s where Settra’s operators stumbled: their log-clearing routine targeted twelve Windows Event Logs, including one intended to erase Windows Defender activity.

But the embedded command misspelled the log path, omitting a duplicated “Windows,” leaving the actual Defender/Operational log fully intact and available to investigators.
Settra’s playbook echoes a broader pattern across emerging ransomware families like Crux, KawaLocker, and Cephalus: abuse of legitimate RMM software, BYOVD to disable security tools, and aggressive anti-forensic cleanup.
Organizations should audit RMM installations for anomalies, restrict or monitor diskpart, cipher, and reagentc usage, and ensure log forwarding to a SIEM so local log clearing can’t erase the trail because, as this case proves, even attackers make mistakes worth catching.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.