← Back to feed
Breaches & RansomwareEmerging1 sourceSep 17, 2026 · 16:26via IT Security Guru

New Settra Ransomware Strain Deploys MeshAgent RMM for Persistence

Brief

Researchers at Huntress have detailed two ransomware incidents involving Settra, a relatively new strain first observed in June, and revealed a consistent set of post-compromise tactics defenders can use to spot the threat before encryption takes hold.

In a blog post published this week, Huntress researchers Harlan Carvey and Lindsey O’Donnell-Welch said the company had investigated two Settra attacks since July: one at a consumer services and retail organisation, and a second, in September, at a manufacturing firm.

In the more recent case, the Huntress agent was only installed after the environment had already been compromised, meaning the attacker may still have been active on the network at the time.

Huntress said it was unable to confirm exactly how the attackers first gained access in either case.

Read more on IT Security Guru→