Redpacketsecurity Settra Ransomware Targets Retail and Manufacturing Sectors
Article Content
- •Settra ransomware targets retail and manufacturing sectors using RMM and BYOVD techniques.
- •Affected organizations face significant delays in recovery, potentially weeks from full operations.
- •Immediate action is advised to review RMM configurations and vulnerable drivers.
A new variant of the Settra ransomware has emerged, specifically targeting the retail and manufacturing sectors. This ransomware employs Remote Monitoring and Management (RMM) tools and Bring Your Own Vulnerable Driver (BYOVD) techniques to infiltrate systems. The attacks have resulted in significant operational disruptions, with many firms reporting delays in recovery efforts. Current estimates suggest that affected organizations may take weeks to return to full operations. The ransomware exploits vulnerabilities in widely used software, although specific CVEs have not been disclosed in the articles. As of now, the situation remains fluid, with ongoing investigations into the scope and impact of the attacks. Security experts recommend immediate reviews of RMM configurations and driver vulnerabilities to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Settra in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Settra Ransomware Variant Targets Organizations with MeshAgent RMM The Settra ransomware variant, first identified in June 2026, has been linked to multiple attacks using compromised VPN credentials for initial access. Huntress reported two incidents involving Settra, one in July and another in September, where attackers deployed the MeshAgent RMM for persistence and encrypted files.…
Japan Faces Record Ransomware Attacks in H1 2026 In the first half of 2026, Japan recorded a staggering 123 ransomware attacks, the highest since data collection began in 2020. The National Police Agency (NPA) reported an average of 13,687 suspicious access attempts per IP address daily, marking a significant increase from the previous year. Small and medium-sized…