Back Scworld Settra ransomware group uses MeshAgent RMM in recent attacks | news
An emerging threat called Settra ransomware was observed in two recent attacks by Huntress analysts, revealing the use of the MeshAgent RMM and potential Bring Your Own Vulnerable Driver (BYOVD) tactics by the threat actor, Huntress reported Thursday.
The Settra ransomware group, which has been active since June 2026, has so far claimed a total of 93 victims, according to information from SOCRadar . The group uses double extortion tactics, with at least four of the claimed victims having their data leaked by Settra, however, there is no evidence it operates under a ransomware-as-a-service model, according to MOXFIVE .
For initial access, Settra typically leverages compromised credentials, including VPN credentials, and exploits unpatched software, as previously reported by MOXFIVE and SOCRadar. In the attacks reported by Huntress, which occurred in July and September, the initial access methods could not be determined, but the use of the MeshAgent RMM and encryption of files was observed.
In the first incident, the MeshAgent RMM was deployed under the name mvtcs.exe. MeshAgent is an open-source remote device management tool for Windows, Linux, macOS and FreeBSD that is available on GitHub , with devices being managed through a MeshCentral server .
Trusted RMM tools weaponized for stealthy malware compromise
Phishing campaign targets widely used RMM platforms in 46 countries
New malware-as-a-service fronts as legit RMM provider
“We’ve seen MeshAgent across many attacks, but it’s not one of the most common RMMs Huntress sees being abused. In attacks, we’ve seen threat actors installing renamed malicious MeshAgent instances and using MeshAgent instances to install further RMMs ( like ScreenConnect ) for persistence,” Lindsey O’Donnell-Welch, principal technical community engagement writer at Huntress, told SC Media.
MeshAgent was also installed in the September attack, though it was not renamed, and connected to a separate IP address. In this later attack, Huntress found evidence of possible BYOVD tactics, specifically installation of the vulnerable Gigabyte gdrv.sys kernel driver. BYOVD is typically used to disrupt security tools at the kernel level.
Evasion and anti-recovery tactics were observed in both incidents, with the ransomware clearing multiple Windows Events Logs, disabling the Windows Recovery Environment via “reagentc /disable,” flushing the DNS cache with “ipconfig /flushdns” and using a script to run diskpart and remove the recovery partition in the first incident. It also used the Windows “cipher” utility to overwrite previously deleted free space in order to make it more difficult to recover deleted data.
In the second incident, in which the Huntress agent was installed mid-incident, the ransomware executable also disabled the Windows Recovery Environment, removed the recovery partition and cleared several Windows Event Logs. However, Huntress noted that an incorrect spelling of the “Microsoft-Windows-Windows-Defender/Operational” event log in the attacker’s code prevented its deletion in this case.
Both ransomware executables included the name of the victim organization’s domain appended with “_win64.exe” and in both cases a ransom note titled “RESTORE_FILES.txt” was created. In the first incident, the executable was launched from C:\Perflogs and encrypted files were given the “.locked” extension, while in the second incident, the executable was launched from the Documents folder and the encrypted files were appended with “.locked_wip”.
“The best opportunity for defenders to detect the attack and prevent encryption is during the threat actor’s initial attempts to gain access. Defenders should also prioritize alerts for unauthorized MeshAgent instances or suspicious driver deployment, especially when followed by event-log clearing or recovery tampering, since these early post-compromise behaviors offer the best chance to stop Settra before encryption begins,” O’Donnell-Welch told SC Media.
Settra typically communicates with victims for negotiations over Tox chat. The group appears to opportunistically target organizations with unpatched systems and exposed credentials rather than targeting a specific industry, with claimed victims including retail and hospitality, manufacturing and production, professional services, construction and engineering, and food and beverage companies, according to MOXFIVE.
Huntress’ investigation connected the workstation name and C2 IP address from the September incident to malicious activity dating back to Dec. 24, 2024. A VirusTotal for the IP address reveals 11 out of 89 security vendors flag this IP as malicious, with one community reporting its use in an attack deploying the AdaptixC2 framework.
An In-Depth Guide to Ransomware
Laura French has been a staff reporter for SC Media since 2023. Laura writes daily news stories, contributes to feature stories, covers industry events and edits briefs for the SC Media website. A New Jersey native, Laura graduated from Ramapo College in 2016 and has previously written for Labcompare, FireRescue1, EMS1 and Forensic Magazine.
SC Staff September 16, 2026
SC Staff September 16, 2026
SC Staff September 16, 2026
Get daily
You can skip this ad in 5 seconds
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
