Urgent.News

What's breaking now, across thousands of outlets.

Tech

Settra ransomware appears in retail and manufacturing intrusions

Cybersecurity researchers have documented two attacks involving Settra ransomware, exposing a repeatable post-compromise playbook that combines legitimate remote-management software, recovery sabotage and efforts to erase forensic evidence. Huntress said the incidents affected a consumer services and retail organisation in July and a manufacturing company in September. Settra was first observed…

Two attacks involving ransomware known as Settra have been documented by cybersecurity researchers. These incidents targeted a consumer services organization in July and a manufacturing company in September. Settra was first publicly observed in June. Researchers are unsure of how the attackers initially gained access to the systems. The ransomware employs a repeatable post-compromise strategy, combining legitimate remote-management software, sabotage of recovery processes, and attempts to erase forensic evidence.

While the initial access method remains undiscovered, the attacks both utilized MeshAgent, a legitimate remote monitoring and management tool. The ransomware executables were specifically crafted for each victim, with filenames based on the victim's domain followed by "_win64.exe". The July intrusion first triggered endpoint detection alerts due to MeshAgent being renamed to "mvtcs.exe" and configured to communicate with a command-and-control address (45.13.122[.]7).

The following day, the ransomware executable was launched from the C:Perflogs directory. Files were encrypted and given a ".locked" extension, while a ransom note called "RESTORE_FILES.txt" was placed on the system. The attackers also executed commands to hinder recovery and investigation, such as clearing several Windows Event Logs, disabling the Windows Recovery Environment, and flushing the DNS cache.

They also attempted to remove a recovery partition using the Windows diskpart utility and overwrite free space on drives with the native cipher utility, making previously deleted material harder to recover.

In September, a similar pattern was observed. MeshAgent was installed while the intrusion was already underway, allowing analysts to capture evidence of the attacker's activity. The ransomware executable was launched from a compromised user's Documents folder, and encrypted files received the ".lockedwip" extension. The ransom note remained the same as in the July attack.

The ransomware also targeted a broad set of Windows logs covering various activities. However, unlike the July case, the attackers did not attempt to clear the Windows Defender event log in this incident.

The name "WIN-LIVFRVQFMKO" appeared in other malicious activity linked to Settra, dating back to December 2024. This name also corresponded with the September command-and-control address, suggesting infrastructure or operational overlap. Cynet Research Labs examined a Settra payload obtained during a separate incident-response case and found that the ransomware's inner encryptor was stored in an encrypted blob, requiring a victim-supplied password for execution.

If an incorrect or missing password was provided, the program would terminate, which could complicate automated malware analysis. The loader also checked for an attached debugger and dynamically resolved Windows programming interfaces. Once researchers obtained the victim-specific password, they were able to extract and examine the inner Windows encryptor.

Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at thearabianpost.com →

More in Tech

WaterPlum compromises 30,000 devices through fake interviews

North Korean cyber operators posing as recruiters have compromised at least 30,000 devices in more than 100 countries, using fraudulent job interviews to infect technology professionals and steal…

  • North Korean cyber operatives targeted 30,000 devices across 100+ countries.
  • WaterPlum group impersonated companies via social media and job platforms.
  • Attackers stole over 7,000 cryptocurrency wallets and $10.71M in yen.

More from Sunday 20 September →