A new ransomware variant named Settra has been deployed in incidents targeting the retail and manufacturing sectors, according to Huntress. The variant was first observed in June 2026, with notable post-compromise activity in attacks against an organisation in the consumer-services and retail sector in July and a manufacturing firm in September. The techniques are the story rather than the encryption itself: the operators deployed the MeshAgent remote monitoring and management tool for persistent access, launched the ransomware executable from C:\Perflogs, appended the .locked extension, and immediately set about destroying the victim's ability to recover — clearing Windows Event Logs, disabling the Windows Recovery Environment, running ipconfig /flushdns, invoking diskpart through a script to delete a recovery partition, and using cipher /w:D:\ to overwrite free space on multiple volumes so deleted data could not be recovered. The September manufacturing case added a bring-your-own-vulnerable-driver (BYOVD) step to disrupt onboard security tooling and crash antivirus-related services. Huntress says it could not confirm initial access for either incident, that the attackers misspelled one of the Event Logs they tried to clear — aborting that step — and that there is currently insufficient evidence to describe Settra as ransomware-as-a-service.
| Attribute | Detail |
|---|---|
| Sector | Retail & Entertainment & Sport |
| Date | 2026-09-21 |
| Source | Infosecurity Magazine |
| Reliability | Tier 3 |