Settra Ransomware: TTPs, Victims, and Defense Guide

What is Settra Ransomware? 

Settra is a ransomware and data extortion group first identified in June 2026. The group combines data theft with encryption, a method known as double extortion, and threatens to publish stolen data on a Tor-based leak site if a ransom isn't paid. Settra communicates with victims through Tox, an encrypted messaging protocol favored by several ransomware groups for negotiation.

MOXFIVE Threat Intelligence began tracking Settra activity in late June 2026, when the group burst onto the scene, posting nearly two dozen victims to its leak site in a short span. While this sharp growth is not fully substantiated, MOXFIVE has direct case work involving Settra and can confirm it as a real, active threat actor currently carrying out attacks.

Settra leak site postings

Is Settra Still Active?

Settra remains active as of July 16, 2026, with new victims being posted to the group's data leak site. Notably, Settra appears to operate sporadically, posting victims in batches, and often taking several days between responses on their Tox chat. This can be an indication of an actor that is comprised of only a few individuals, or even a sole actor, unlike larger RaaS (ransomware-as-a-service) groups.

How Settra's Extortion Model Works

Settra's approach follows a familiar double extortion pattern: exfiltrate data, then encrypt systems, then use the threat of public exposure to increase pressure on the victim to pay.

Settra publicly describes its motivation

Publicly, Settra has described its motivation as financial rather than ideological. The group has said it does not target specific countries or industries, and instead targets organizations with exploitable weaknesses, including unpatched systems and weak access management.

Top industries targeted by Settra

Settra Initial Access Methods

In our own case work, MOXFIVE has observed Settra gain initial access through compromised VPN credentials, then use those valid credentials to move through victim environments, a pattern common among ransomware groups.

Settra's stated approach

Once inside, MOXFIVE has observed Settra move quickly from a single foothold to a broader view of the environment, relying on legitimate administrative and red-team tools rather than custom-built malware, a choice that helps its activity blend into normal network traffic. The specific tools observed at each stage are detailed below.

Settra Attack Chain

From initial access to encryption, here is what MOXFIVE has directly observed in cases involving Settra:

  • Initial Access: Credential compromise, using valid credentials to establish a foothold in the victim environment.
  • Discovery: NetExec (also known as nxc, a widely used red-team tool) and Netscan have been used to map out victim networks and validate which credentials work where.
  • Credential Access: Procdump and Mimikatz have been used to pull additional credentials from compromised systems.
  • Lateral Movement: PAExec, similar to PsExec, along with NetExec, has been used to move across victim environments using compromised credentials.
  • Defense Evasion: Settra has used a tool called edr_blind to disable endpoint detection tools and manually cleared Windows event logs to cover its tracks. In at least one case, it also escalated privileges using a known vulnerable driver, STProcessMonitor_v114.sys, a technique called "bring your own vulnerable driver" (BYOVD) to gain kernel-level execution.
  • Command and Control: Mesh Agent, a legitimate remote access tool, has been used to maintain persistent access into victim environments.
Settra's stated rules of engagement

How to Defend Against Settra Ransomware

The controls that matter most against Settra are largely the same fundamentals that defend against other threat actors.

  • Enforce phishing-resistant MFA: Credential compromise has served as both an entry point and a way to move deeper into victim environments in Settra cases, making phishing-resistant MFA one of the most direct ways to close that gap.
  • Watch for credential-dumping activity: Procdump and Mimikatz both leave a detectable footprint when used against credential material in memory. Monitoring and alerting on unusual access to processes like LSASS is a direct way to catch this stage in progress.
  • Monitor for dual-use administrative tools: NetExec, PAExec, and Mesh Agent are legitimate administrative and red-team tools, which is exactly what makes them effective in the wrong hands. Implement strict "default deny" lists for approved RMM tools using EDR rules or web filtering to alert or block unexpected and unapproved tools.
  • Guard against vulnerable-driver abuse: Settra has used a known vulnerable driver to disable security tooling and escalate privileges. Blocklisting known vulnerable drivers, including STProcessMonitor_v114.sys, and monitoring for unusual driver installation activity closes this specific path.
  • Forward logs where attackers can't reach them: Settra has been observed manually clearing Windows event logs to cover its tracks. Centralized log forwarding preserves visibility even when local logs are deleted.
  • Detect exfiltration before encryption: Data theft typically precedes encryption in double extortion intrusions, which gives defenders a window to catch an attack before it reaches its most damaging phase. Watching for unusually large outbound transfers, especially to unfamiliar cloud storage or file-sync destinations, can surface that activity while it's still happening rather than after the fact. Detection built around encryption events alone risks missing that earlier window entirely.
  • Protect backup infrastructure: Offline, immutable backups that are not accessible through domain accounts remain one of the most reliable paths to recovery, regardless of which specific techniques a given group uses against production systems.

MOXFIVE's Approach

MOXFIVE is actively responding to incidents involving Settra. Our incident response teams work across the legal, insurance, executive, and technical stakeholders involved in a cyber incident, helping organizations make informed decisions under pressure and restore operations with confidence.

If your organization has questions about Settra or believes it may be affected, MOXFIVE is available to help. Our team has handled hundreds of ransomware cases against some of the most advanced and active operations, aligning preventive, detective, and recovery controls to current threat actor TTPs. Contact us at 833-568-6695 or email our team at incident@moxfive.com.

Luke Moran

Luke is an IT and cybersecurity professional specializing in complex ransomware recovery and Cloud/SaaS investigations. He applies his deep hands-on experience running IT operations to his role leading restoration teams in recovering business operations following ransomware attacks. At MOXFIVE, Luke has led containment and remediation responses for some of the largest incidents worldwide. Luke’s incident response leadership includes responding to cutting-edge Cloud and SaaS incidents including AWS/Azure/GCP, Salesforce, Snowflake, GitHub, and CI/CD compromises.​

Experts predict there will be a ransomware
attack every 11
seconds in 2021.
from Cybercrime Magazine

Our mission is to minimize the business impact of cyber attacks. 

HOW WE CAN HELP

Incident Response

MOXFIVE provides the clarity and peace of mind needed for attack victims during the incident response process. Our platform approach enables victims of attacks to work with a Technical Advisor who provides the expertise and guidance needed in a time of crisis, and facilitates the delivery of all technical needs required, consistently and efficiently.

Learn More

Business Resilience

With experience on the front lines responding to incidents daily, MOXFIVE Technical Advisors have the unique ability to connect the dots between business, information technology, and security objectives to help you quickly identify the gaps and build a more resilient environment.

Learn More