Select your language

WHAT ARE YOU LOOKING FOR?

Popular Tags

Raleigh, NC

32°F
Light rain Humidity: 91%
Wind: 0.45 M/S

SETTRA Ransomware Leverages MeshAgent RMM and BYOVD Techniques to Encrypt Windows Devices

SETTRA Ransomware Leverages MeshAgent RMM and BYOVD Techniques to Encrypt Windows Devices

SETTRA ransomware has surfaced as a significant cyber threat targeting Windows-based environments, following investigations that connected the malware to two recent intrusion campaigns involving remote management software and tactics designed to hinder system recovery.

The ransomware is engineered to encrypt victim files, deploy ransom notes, and complicate both forensic investigations and restoration efforts. Reports suggest that SETTRA operators typically gain initial access through exposed VPN services or previously compromised credentials, highlighting the risks associated with unsecured remote access and inadequate identity protection measures.

The campaign also reflects a growing trend among threat actors who abuse legitimate remote administration tools to maintain persistence and evade detection after infiltrating a network.

Security researchers at Huntress analyzed two separate incidents: one involving a consumer services and retail organization in July, and another targeting a manufacturing company in September. Although investigators were unable to definitively determine the initial entry point in either case, both attacks followed an almost identical post-compromise workflow.

According to Huntress, the attacks are particularly concerning because they combine rapid file encryption with deliberate efforts to obstruct recovery operations and eliminate valuable forensic evidence. In both incidents, the ransomware executable was named using the victim organization's domain, potentially helping it blend in with legitimate files and avoid suspicion.

MeshAgent Used for Persistent Access

Following initial compromise, SETTRA operators deployed MeshAgent, a legitimate remote monitoring and management (RMM) tool. By leveraging such software, attackers can maintain reliable access to affected systems, execute commands remotely, and continue their operations without depending solely on custom malware.

A similar abuse of MeshAgent was previously observed during a FortiGate-related intrusion, further demonstrating how legitimate RMM platforms can be repurposed for malicious activity. In the July attack, the threat actors renamed the MeshAgent executable and configured it to communicate with an attacker-controlled command-and-control (C2) server.

Researchers observed the ransomware executing the following day from a Windows performance log directory. It subsequently encrypted files using a unique extension and dropped ransom notes across the compromised system.

BYOVD Technique Observed in September Attack

The September incident revealed evidence of a Bring Your Own Vulnerable Driver (BYOVD) attack technique. This method involves deploying legitimate but vulnerable drivers that can be exploited to bypass or disable security protections, allowing threat actors to interfere with defensive tools before launching ransomware.

The use of trusted yet vulnerable Windows drivers has become an increasingly common tactic among ransomware operators seeking to evade endpoint security solutions.

Unlike the July incident, MeshAgent was not renamed during the September compromise and was linked to a different command-and-control server. The ransomware executed from the affected user’s Documents folder, applied a different file extension to encrypted files, and distributed ransom notes throughout multiple directories.

Researchers also identified links between the malicious activity and a workstation name previously associated with the same command-and-control infrastructure.

Recovery and Forensic Efforts Deliberately Targeted

Once the encryption phase began, the attackers took several steps aimed at disrupting recovery and limiting forensic visibility. These actions included clearing multiple Windows Event Logs and disabling the Windows Recovery Environment (WinRE).

In both incidents, the attackers used DiskPart to remove recovery partitions, making system restoration significantly more challenging. During the July attack, they additionally flushed the DNS cache and executed the Windows Cipher utility to overwrite free space on a data drive, reducing the likelihood of recovering deleted information.

In the September case, the operators attempted to delete Microsoft Defender logging data. However, a typo in the specified log channel prevented them from successfully removing the Windows Defender Event Log, leaving valuable evidence intact for investigators.

These findings underscore the importance of centralized log collection, which can preserve critical forensic data even when attackers successfully erase logs from compromised endpoints.

Defensive Recommendations

Organizations can reduce the likelihood and impact of SETTRA-related attacks by implementing fundamental security controls, including:

  • Enforcing strong authentication and multi-factor authentication (MFA) for VPN and remote access services.
  • Restricting, monitoring, and auditing the use of remote management and RMM tools.
  • Investigating unexpected driver installations and suspicious processes executing from user directories or Windows system locations.
  • Maintaining regularly tested, offline, or otherwise protected backup systems.
  • Verifying that Windows recovery mechanisms remain operational and accessible.
  • Conducting ransomware response exercises that simulate encryption events and loss of endpoint visibility.

Conclusion

The two observed incidents demonstrate that SETTRA does not rely on highly sophisticated or novel malware capabilities to cause significant disruption. Instead, the ransomware combines legitimate administrative tools, vulnerable drivers, and native Windows utilities to accelerate attacks, impair recovery efforts, and pressure defenders.

As ransomware operators increasingly blend malicious actions with trusted software and built-in system tools, organizations must prioritize rapid detection of abnormal RMM activity, robust logging practices, and thoroughly tested recovery procedures to minimize the impact of future attacks.

Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post. 

Cybersecurity Insight delivers timely updates on global cybersecurity developments, including recent system breaches, cyber-attacks, advancements in artificial intelligence (AI), and emerging technology innovations. Our goal is to keep viewers well-informed about the latest trends in technology and system security, and how these changes impact our lives and the broader ecosystem

Please fill the required field.