Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-21 · updated: 2026-09-21 · tags: [incident, retail, ransomware] · confidence: high · severity: medium · affected_sectors: [retail] · au_impact: true

A new ransomware variant named Settra has been deployed in incidents targeting the retail and manufacturing sectors, according to Huntress. The variant was first observed in June 2026, with notable post-compromise activity in attacks against an organisation in the consumer-services and retail sector in July and a manufacturing firm in September. The techniques are the story rather than the encryption itself: the operators deployed the MeshAgent remote monitoring and management tool for persistent access, launched the ransomware executable from C:\Perflogs, appended the .locked extension, and immediately set about destroying the victim's ability to recover — clearing Windows Event Logs, disabling the Windows Recovery Environment, running ipconfig /flushdns, invoking diskpart through a script to delete a recovery partition, and using cipher /w:D:\ to overwrite free space on multiple volumes so deleted data could not be recovered. The September manufacturing case added a bring-your-own-vulnerable-driver (BYOVD) step to disrupt onboard security tooling and crash antivirus-related services. Huntress says it could not confirm initial access for either incident, that the attackers misspelled one of the Event Logs they tried to clear — aborting that step — and that there is currently insufficient evidence to describe Settra as ransomware-as-a-service.

Attribute Detail
Sector Retail & Entertainment & Sport
Date 2026-09-21
Source Infosecurity Magazine
Reliability Tier 3