Settra Ransomware Group Exploits MeshAgent RMM in Recent Attacks
Settra ransomware group leverages MeshAgent RMM in recent cyber incidents
Introduction
A newly identified threat actor known as Settra ransomware has been linked to two recent cyberattacks, as disclosed by Huntress analysts. The group’s operations involve the deployment of the MeshAgent RMM tool and potential exploitation of vulnerable drivers, according to findings shared by the security firm.
Settra Ransomware Overview
Settra, which has been active since June 2026, has reportedly targeted 93 organizations, as noted by SOCRadar. The group employs double extortion strategies, with at least four victims experiencing data leaks, though no evidence of a ransomware-as-a-service model has been confirmed by MOXFIVE.
Targeted Industries
Affected entities include retail, hospitality, manufacturing, professional services, construction, and food and beverage sectors, as reported by MOXFIVE.
Attack Methods and Techniques
Initial Access Vectors
Initial access vectors for Settra typically include compromised credentials, such as those for virtual private networks, and unpatched software vulnerabilities, as previously documented by MOXFIVE and SOCRadar.
MeshAgent RMM Deployment
In the attacks reported by Huntress, which occurred in July and September, the exact methods of initial entry remained undetermined. However, both incidents involved the deployment of the MeshAgent RMM and subsequent file encryption. In the first incident, the tool was installed under the filename mvtcs.exe.
MeshAgent is an open-source remote management solution supporting Windows, Linux, macOS, and FreeBSD, with administration facilitated through a MeshCentral server.
BYOVD Tactics
Evidence of potential Bring Your Own Vulnerable Driver (BYOVD) tactics emerged, specifically the installation of the vulnerable Gigabyte gdrv.sys kernel driver. This technique is designed to bypass security mechanisms at the system level.
Notable Incidents
July Attack
In the first incident, the executable was executed from the C:\\Perflogs directory, encrypting files with the “.locked” extension. Both attacks featured evasion and anti-recovery measures, including the deletion of Windows system restore points.
September Attack
In the September attack, the tool was deployed without renaming and connected to a distinct IP address. In the second incident, the ransomware executable disabled the Windows Recovery Environment, removed the recovery partition, and cleared multiple system logs. Both malicious payloads included the victim organization’s domain name appended with “_win64.exe,” and a ransom note titled “RESTORE_FILES.txt” was created.
Recommendations for Defenders
Defenders are advised to monitor for anomalies in MeshAgent deployments and kernel driver activity. Organizations are encouraged to review their endpoint protection strategies and investigate any unauthorized deployment of remote management tools.
Conclusion
Technical details surrounding the attacks underscore the importance of proactive patch management, credential hygiene, and monitoring for unusual RMM behavior. Settra communicates with victims through the Tox messaging platform for negotiation purposes. The group appears to target organizations with unpatched systems and exposed credentials rather than focusing on specific industries.
