search

LEMON BLOG

Settra Ransomware Abuses Legitimate RMM Tools and Disables Recovery Before Encryption

A newly observed ransomware strain called Settra is drawing attention because of the way it combines stolen access, legitimate remote-management software, recovery sabotage and encryption into one coordinated attack chain. Security researchers first observed the ransomware in June 2026, with the known incidents involving either compromised VPN access or stolen credentials as the likely entry point.

What makes Settra particularly concerning is that the attackers do not rely solely on obvious malware after gaining access. They have been seen deploying legitimate Remote Monitoring and Management, or RMM, tools to maintain persistent control of affected Windows systems before launching the ransomware itself. In the two documented incidents since July, the ransomware executable was even named after the victim organisation's own domain, suggesting the attackers customised parts of the deployment for each target.

Legitimate RMM Software Becomes Part of the Attack

One of the tools observed during Settra intrusions is MeshAgent, a legitimate remote-management utility. In a normal environment, tools like this allow administrators to remotely manage devices, run commands and troubleshoot systems. In the wrong hands, however, the same capabilities can give attackers a reliable way to maintain control without depending entirely on custom malware that security products may detect more easily.

This is one of the more difficult aspects of modern ransomware defence. A remote-management application may be perfectly legitimate and even approved in some organisations, which means defenders cannot simply assume that the presence of an RMM tool is malicious. The more useful question is whether the installation, management account and destination server are authorised.

That makes application inventory and behavioural monitoring increasingly important. An unexpected RMM deployment, especially on systems that have never required remote-management software before, should be treated as something worth investigating rather than dismissed simply because the software itself is legitimate.

Attackers Try to Destroy the Recovery Path

Settra does more than encrypt files. Researchers observed the operators clearing Windows Event Logs, disabling the Windows Recovery Environment, and using DiskPart in both documented incidents, apparently to remove recovery partitions. During the July attack, the operators also flushed the DNS cache.

These actions are designed to make incident response harder after encryption has already begun. Removing recovery options can reduce the victim's ability to restore systems locally, while clearing logs can erase valuable evidence that investigators would normally use to understand how the attacker entered, moved through the network and deployed the ransomware.

Interestingly, the attackers were not flawless. During a September incident, they attempted to remove Windows Defender logging but misspelled the relevant log-channel name, leaving the Defender Event Log intact.

That mistake reinforces why defenders should preserve logs wherever possible. Even attackers that deliberately erase evidence may leave behind enough information in another source to help reconstruct the intrusion.

BYOVD Activity Adds Another Layer of Risk

One of the two observed incidents also showed signs of Bring Your Own Vulnerable Driver, commonly known as BYOVD. This technique involves introducing a legitimate but vulnerable driver and then abusing its flaws to interfere with security software.

For ransomware operators, this can be particularly valuable because endpoint protection may otherwise detect or stop the encryption process. If the attacker can disable or impair those defences first, the ransomware has a much better chance of running successfully across the environment.

The broader lesson is that organisations need to think beyond detecting obviously malicious executables. Legitimate software, signed drivers and trusted administrative tools can all become part of the attack chain when an adversary has already obtained sufficient privileges.

Settra Uses Double Extortion

The ransomware is also associated with double-extortion tactics. Instead of relying only on file encryption, the operators reportedly threaten to release sensitive corporate information as additional pressure on the victim. The advisory notes that potentially exposed material can include employee records and financial documents.

This means a successful backup strategy alone may not eliminate the business impact. Even if an organisation can rebuild affected systems without paying a ransom, attackers may still possess sensitive information that creates privacy, regulatory, legal and reputational risks.

Settra has so far been associated with sectors including construction, manufacturing and technology, showing that the operators are not restricted to one narrow industry.

Only Two Incidents Are Known, but the Activity Appears Consistent

The advisory emphasises that Settra has currently been linked to two known incidents, rather than a large publicly documented campaign. However, the similarity of the post-compromise activity across different sectors and different months suggests that the operators are following a consistent methodology. Researchers also consider the ransomware to remain active.

That distinction is important. Settra may not yet have the victim count associated with more established ransomware operations, but consistency across multiple attacks suggests that this is not simply an isolated experiment.

Organisations therefore should not wait for the number of victims to become large before taking the techniques seriously. Many of the controls needed to reduce Settra risk also help against other credential-based and ransomware intrusions.

There Is No Single Patch That Fixes the Problem

There is currently no single disclosed software patch capable of blocking the entire Settra attack chain. The threat combines several different techniques, including potentially stolen credentials, VPN access, abuse of legitimate RMM software, vulnerable drivers, interference with security products and eventual ransomware execution.

That means defence needs to be layered rather than centred around installing one update. Identity security, endpoint monitoring, VPN auditing, application control, logging and recovery architecture all become important because the attackers can potentially move through several different stages before encryption begins.

In practical terms, organisations should pay particular attention to a few areas:

Recovery Systems Need to Be Isolated From Production Access

One recommendation deserves particular attention: recovery infrastructure should not depend on the same credentials or administrative paths used by production systems.

If an attacker compromises an administrator account and that same identity can modify backups or recovery systems, then the organisation may effectively give the attacker everything needed to destroy both the production environment and the recovery path. Separating those privileges creates another barrier even after the attacker gains high-level access elsewhere.

This principle applies well beyond Settra. Modern ransomware operators increasingly look for backups and recovery systems because organisations are much less likely to pay when they can restore quickly. Protecting the recovery environment is therefore part of ransomware prevention, not simply disaster recovery.

The Observed Techniques Map Across the Attack Lifecycle

The advisory maps Settra activity to several recognised attack techniques, covering execution, persistence, defence evasion, discovery, lateral movement and impact. These include Valid Accounts (T1078), Ingress Tool Transfer (T1105), Impair Defences (T1562), Network Service Discovery (T1046), Remote Services (T1021), Remote Desktop Protocol (T1021.001), Data Encrypted for Impact (T1486) and Inhibit System Recovery (T1490).

Taken together, these techniques show that the ransomware itself is only the final stage. The more important defensive opportunity may exist earlier, when attackers are authenticating with stolen credentials, deploying remote-management tools, moving across systems or tampering with security and recovery controls.

Stopping the attack before encryption is far preferable to trying to recover afterward.

Final Thoughts

Settra is a useful reminder that ransomware attacks are becoming less about one malicious executable and more about an entire sequence of legitimate tools, stolen identities and deliberate attempts to undermine recovery. The operators appear to use compromised credentials or VPN access to gain entry, deploy legitimate RMM software for persistence, interfere with defensive controls, remove recovery options and only then launch encryption.

The limited number of publicly identified incidents should not make the threat easy to dismiss. The repeated methodology suggests the operators already have a working playbook, and the ransomware remains active.

For defenders, the most important takeaway is that ransomware protection now starts long before the ransomware appears. Strong credential management, close monitoring of VPN and RMM activity, isolated recovery systems and preserved security logs can provide opportunities to detect or contain an intrusion before attackers reach the encryption stage.

Once ransomware begins encrypting files and destroying recovery options, many of the best defensive opportunities have already passed.

The Psychology of Empty Space: Why Great Design Of...
Discord Begins Global Rollout of Its Revised Age V...

Related Posts

 

Comments 0

Loading latest comments...
Thursday, 24 September 2026

Captcha Image

LEMON VIDEO CHANNELS

Step into a world where web design & development, gaming & retro gaming, and guitar covers & shredding collide! Whether you're looking for expert web development insights, nostalgic arcade action, or electrifying guitar solos, this is the place for you. Now also featuring content on TikTok, we’re bringing creativity, music, and tech straight to your screen. Subscribe and join the ride—because the future is bold, fun, and full of possibilities!

My TikTok Video Collection