Skip to content
Settra Ransomware Variant Targets Organizations with Double Extortion Tactics

Settra Ransomware Variant Targets Organizations with Double Extortion Tactics

First seen 17 Sep 2026, 14:27 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 17, 2026 at 16:32 UTC
  • Settra ransomware employs double extortion tactics, encrypting data and threatening public exposure.
  • Initial access is commonly gained through compromised VPN credentials.
  • Recent attacks utilized RMM tools and left ransom notes, impacting multiple sectors.

Settra, a ransomware variant first identified in June 2026, utilizes double extortion tactics by encrypting data and threatening to publish it if the ransom is not paid. The group has been active since late June, with nearly two dozen victims reported on their leak site. Initial access methods include compromised VPN credentials, allowing attackers to move laterally within victim networks using legitimate administrative tools. Recent incidents involved deploying remote monitoring and management (RMM) tools for persistence and encrypting files while leaving ransom notes. The attacks have affected organizations in various sectors, including consumer services, retail, and manufacturing. Settra's operations appear sporadic, indicating a small team or individual actor behind the attacks. As of September 2026, the threat remains active, with ongoing monitoring by cybersecurity firms.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-01
Settra ransomware first identified
Settra ransomware variant emerged, targeting organizations with double extortion tactics.
MoxFive
2026-07-01
Huntress investigates first Settra incidents
Huntress began investigating two incidents involving Settra ransomware, confirming its operational pattern.
Huntress
2026-09-01
Settra attacks reported in manufacturing sector
A notable attack occurred in September, affecting a manufacturing company and following similar patterns to previous incidents.
Huntress
2026-09-17
Settra remains active
As of September 2026, Settra continues to post new victims on its leak site, indicating ongoing operations.
MoxFive

More articles in this cluster (2)

Following this threat?

Track Cephalus and Crux in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed