Settra Ransomware Targets Retail and Manufacturing
A new ransomware variant called Settra is attacking retail and manufacturing firms. According to Huntress, the malware uses RMM tools for persistence and disables victim recovery options.

A new ransomware variant named Settra has been deployed in attacks against the retail and manufacturing sectors. Huntress researchers first observed the malware in June and documented its use in a July attack on a consumer services and retail organization and a September attack on a manufacturing firm.
The threat actors employ notable post-compromise techniques. These include deploying remote monitoring and management (RMM) tools for persistent access, disabling victims' recovery options, and installing bring your own vulnerable driver (BYOVD) software on compromised systems. Huntress highlighted these methods in a blog post published on September 17. Previous research indicated Settra is used for double-extortion, where attackers threaten to release stolen corporate data while encrypting files.
Huntress stated there is not currently enough evidence to confirm if Settra operates as a ransomware-as-a-service (RaaS) platform.
Key Post-Compromise Activities
Huntress could not confirm the initial access vector for the two incidents. In the July retail attack, the threat actor installed the MeshAgent RMM tool, which connected to a command-and-control (C2) IP address.
The ransomware executable launched from the C:Perflogs folder the following day. It encrypted victim files, renaming them with the.locked extension, and then created a ransom note. Endpoint detection and response (EDR) telemetry showed the actor immediately worked to prevent recovery. They cleared several Windows Event Logs, disabled the Windows Recovery Environment, flushed the DNS cache with ipconfig /flushdns, and used a script with the diskpart utility to remove a recovery partition.
Attackers also used the command cmd.exe /c cipher /w:D:\ >nul 2>&1 to launch the Windows cipher utility. This overwrote free space on multiple file volumes to hinder data recovery.
The September manufacturing attack used similar techniques, including MeshAgent RMM installation and recovery option disabling. It added the use of BYOVD. These drivers can impact security tools and crash antivirus-related services.
The researchers noted the attackers misspelled one Windows Event Log name, which stopped that clearing action. Malicious activity in the September incident was linked to a workstation named WIN-LIVFRVQFMKO. Huntress had previously observed this name in other incidents dating back to December 2024.
In both attacks, the ransomware executable was named using the victim organization's domain name followed by _win64.exe. While there were slight differences between the two incidents, such as the naming and C2 IP address of the MeshAgent RMM, as well as the folders the threat actors operated from, the overall conduct of the attacks were remarkably similar, the researchers wrote.
Recommendations for Defenders
The Huntress blog noted that new ransomware variants with distinct tactics, techniques, and procedures (TTPs) emerge frequently. It urged security teams to stay informed about these variants and their post-compromise techniques to improve detection and response.
Defenders should also maintain focus on the fundamental practices of cyber defense to help prevent such attacks from occurring. The blog referenced a report warning that a new ransomware threat actor emerges every week.





