
Settra is a ransomware and data extortion group first identified in June 2026. The group combines data theft with encryption, a method known as double extortion, and threatens to publish stolen data on a Tor-based leak site if a ransom isn't paid. Settra communicates with victims through Tox, an encrypted messaging protocol favored by several ransomware groups for negotiation.
MOXFIVE Threat Intelligence began tracking Settra activity in late June 2026, when the group burst onto the scene, posting nearly two dozen victims to its leak site in a short span. While this sharp growth is not fully substantiated, MOXFIVE has direct case work involving Settra and can confirm it as a real, active threat actor currently carrying out attacks.

Settra remains active as of July 16, 2026, with new victims being posted to the group's data leak site. Notably, Settra appears to operate sporadically, posting victims in batches, and often taking several days between responses on their Tox chat. This can be an indication of an actor that is comprised of only a few individuals, or even a sole actor, unlike larger RaaS (ransomware-as-a-service) groups.
Settra's approach follows a familiar double extortion pattern: exfiltrate data, then encrypt systems, then use the threat of public exposure to increase pressure on the victim to pay.

Publicly, Settra has described its motivation as financial rather than ideological. The group has said it does not target specific countries or industries, and instead targets organizations with exploitable weaknesses, including unpatched systems and weak access management.

In our own case work, MOXFIVE has observed Settra gain initial access through compromised VPN credentials, then use those valid credentials to move through victim environments, a pattern common among ransomware groups.

Once inside, MOXFIVE has observed Settra move quickly from a single foothold to a broader view of the environment, relying on legitimate administrative and red-team tools rather than custom-built malware, a choice that helps its activity blend into normal network traffic. The specific tools observed at each stage are detailed below.
From initial access to encryption, here is what MOXFIVE has directly observed in cases involving Settra:

The controls that matter most against Settra are largely the same fundamentals that defend against other threat actors.
MOXFIVE is actively responding to incidents involving Settra. Our incident response teams work across the legal, insurance, executive, and technical stakeholders involved in a cyber incident, helping organizations make informed decisions under pressure and restore operations with confidence.
If your organization has questions about Settra or believes it may be affected, MOXFIVE is available to help. Our team has handled hundreds of ransomware cases against some of the most advanced and active operations, aligning preventive, detective, and recovery controls to current threat actor TTPs. Contact us at 833-568-6695 or email our team at incident@moxfive.com.


MOXFIVE provides the clarity and peace of mind needed for attack victims during the incident response process. Our platform approach enables victims of attacks to work with a Technical Advisor who provides the expertise and guidance needed in a time of crisis, and facilitates the delivery of all technical needs required, consistently and efficiently.
Learn More
With experience on the front lines responding to incidents daily, MOXFIVE Technical Advisors have the unique ability to connect the dots between business, information technology, and security objectives to help you quickly identify the gaps and build a more resilient environment.