www.moxfive.com Settra Ransomware Variant Targets Organizations with Double Extortion Tactics
Article Content
- •Settra ransomware employs double extortion tactics, encrypting data and threatening public exposure.
- •Initial access is commonly gained through compromised VPN credentials.
- •Recent attacks utilized RMM tools and left ransom notes, impacting multiple sectors.
Settra, a ransomware variant first identified in June 2026, utilizes double extortion tactics by encrypting data and threatening to publish it if the ransom is not paid. The group has been active since late June, with nearly two dozen victims reported on their leak site. Initial access methods include compromised VPN credentials, allowing attackers to move laterally within victim networks using legitimate administrative tools. Recent incidents involved deploying remote monitoring and management (RMM) tools for persistence and encrypting files while leaving ransom notes. The attacks have affected organizations in various sectors, including consumer services, retail, and manufacturing. Settra's operations appear sporadic, indicating a small team or individual actor behind the attacks. As of September 2026, the threat remains active, with ongoing monitoring by cybersecurity firms.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Cephalus and Crux in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…