← Back to feed
Breaches & RansomwareEmerging1 sourceSep 18, 2026 · 07:55via CyberPress

New SETTRA Ransomware Wipes Recovery Options Before Locking Windows Files

Brief

Security researchers have uncovered new details about Settra ransomware, a recently observed Windows threat that attempts to destroy recovery options before encrypting files.

Huntress investigated two Settra incidents, one targeting a consumer services and retail organization in July and another affecting a manufacturing company in September.

Settra was first publicly identified in June. Earlier reporting linked the group to compromised VPN services and stolen credentials. However, Huntress could not confirm how attackers first entered either victim network.

Instead, its investigation revealed several post-compromise tactics, including the misuse of remote monitoring tools, Windows log clearing, recovery-disabling commands, and bring-your-own-vulnerable-driver, or BYOVD, activity.

In both attacks, the ransomware executable used a similar naming pattern.

Read more on CyberPress→