started · updated
Settra ransomware uses MeshAgent RMM for persistence
Security researchers from Huntress and MoxFive have identified a pattern in recent attacks involving a ransomware strain known as Settra. The group has targeted a consumer services and retail organization in July and a manufacturing firm in September.
In both instances, the attackers utilized a repeatable playbook to maintain persistence. They deployed the legitimate MeshAgent remote monitoring and management (RMM) tool, often renaming the executable to evade detection. The ransomware itself was frequently named after the victim’s own domain with a “_win64.exe” suffix.
While the exact method of initial entry for the most recent attacks remains unconfirmed, prior analysis suggests the group likely gains access through compromised VPNs or stolen credentials. Once inside, the attackers employ established tradecraft, including clearing Windows Event Logs, disabling the Windows Recovery Environment, and tampering with recovery partitions to hinder defense and recovery efforts.