New SETTRA Ransomware Leverages MeshAgent RMM and BYOVD for System Encryption
The emerging SETTRA ransomware targets Windows systems by exploiting legitimate remote management tools like MeshAgent and employing Bring Your Own Vulnerable Driver (BYOVD) techniques to hinder recovery.

A new ransomware strain, dubbed SETTRA, is posing a significant threat to Windows networks by combining the misuse of legitimate remote management tools with advanced techniques to disrupt recovery efforts. Investigators have linked SETTRA to at least two recent intrusions, demonstrating a sophisticated approach that encrypts files, leaves ransom notes, and actively works to impede both forensic analysis and restoration processes.
Initial access for SETTRA operators appears to be gained through compromised virtual private networks (VPNs) or previously stolen credentials. This highlights the ongoing risks associated with exposed remote access points and weak account security. The ransomware's reliance on legitimate administration software, such as MeshAgent, reflects a broader trend of attackers repurposing widely used tools for malicious purposes, making detection more challenging.
Analysts from Huntress identified two distinct incidents involving SETTRA. The first occurred in July, affecting an organization in the consumer services and retail sector, while the second impacted a manufacturing company in September. Although the exact initial access vectors for these breaches remain unconfirmed, the post-compromise activities exhibited a strikingly similar pattern in both cases. The ransomware executable itself was often named based on the affected organization's domain, a tactic likely intended to blend in with legitimate system files.
In both observed incidents, SETTRA operators deployed MeshAgent, a legitimate remote monitoring and management (RMM) tool. Attackers leverage such tools to maintain persistent control over compromised machines, execute commands, and advance their operations without solely relying on custom-built malware. This mirrors other observed attacks where RMM utilities are repurposed for malicious ends after an initial network breach.
The September incident provided evidence of the "Bring Your Own Vulnerable Driver" (BYOVD) technique. This method involves using a legitimate but flawed driver to interfere with defensive software, potentially allowing an attacker to disable security services before initiating the encryption process. The use of BYOVD is a recurring concern in ransomware investigations, as it exploits the trust inherent in signed Windows drivers.
Beyond encryption, SETTRA operators actively disrupt recovery mechanisms. In both incidents, they cleared Windows Event Logs, disabled the Windows Recovery Environment, and utilized DiskPart, apparently to remove recovery partitions. These actions are designed to delay incident response and reduce the amount of forensic evidence available to security teams. In one case, the Cipher utility was used to overwrite free space on a data drive, making deleted data harder to retrieve.
To mitigate the risks posed by SETTRA and similar threats, organizations are advised to focus on fundamental security controls. This includes protecting VPN access with strong multi-factor authentication, strictly monitoring and restricting the use of remote management tools, and investigating any unexpected driver installations or suspicious processes. Maintaining tested, offline backups and verifying the availability of recovery features are also critical safeguards. Furthermore, regularly testing incident response playbooks against simulated encryption events, including scenarios involving loss of endpoint visibility, can significantly improve an organization's resilience.
Huntress researchers have detailed additional post-compromise techniques observed in Settra ransomware attacks, including the deployment of MeshAgent RMM for persistent access, efforts to disable victim recovery options, and the use of bring your own vulnerable driver (BYOVD) to hinder security tooling. The variant was observed targeting both retail and manufacturing sectors in July and September, respectively, with attackers employing methods to overwrite free disk space and clear event logs to impede recovery.