Skip to content

Security1 publisher3 min readPublished

Settra ransomware operators ran two intrusions through the open-source MeshAgent RMM

Huntress worked two Settra intrusions, in July and September, and found MeshAgent installed for remote control, Windows event logs cleared and recovery partitions removed. SOCRadar counts 93 victims claimed since June.

The Watch · Security desk

Illustration accompanying Settra ransomware operators ran two intrusions through the open-source MeshAgent RMM

What happened

  • Huntress reported two Settra ransomware intrusions in which the group installed MeshAgent, an open-source remote management agent, and in one case left signs of vulnerable-driver abuse.
  • In the July incident MeshAgent was deployed as mvtcs.exe; in September it was installed unrenamed and pointed at a different IP address.
  • Both ransomware executables were named after the victim's domain with _win64.exe appended and both wrote a ransom note called RESTORE_FILES.txt.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • capability MeshAgent gives an operator full remote control using software an IT team could plausibly have installed itself, so the deciding control is whether an organisation keeps a list of RMMs it permits and alerts on everything outside it.
  • exposure The recovery tampering happens before the ransom note, so by the time a victim knows, WinRE, the recovery partition and carvable free space are already gone and only off-host backups can restore.
  • decision Huntress puts the best detection window at initial access. A shop that funds only post-compromise alerting gets its first alert after the operator already has remote control of a host.
  • contradiction The 93 figure is Settra's own leak-site accounting relayed by SOCRadar, while four victims are corroborated by published data, so the count measures what the group says it did.

MeshAgent is a working remote management agent for Windows, Linux, macOS and FreeBSD, published on GitHub, and the hosts it lands on are administered from a MeshCentral server [7]. The operator runs that server.

Huntress says it does not see the tool abused often. Lindsey O'Donnell-Welch, principal technical community engagement writer at Huntress, told SC Media that the company has seen MeshAgent across many attacks but that it is not one of the most common RMMs Huntress sees being abused, and that in previous attacks threat actors have installed renamed malicious MeshAgent instances and used MeshAgent instances to install further RMMs, such as ScreenConnect, for persistence [8].

In July the agent ran as mvtcs.exe [6]. In September it ran under its own name, to a different IP address [9], and Huntress found the vulnerable Gigabyte gdrv.sys kernel driver installed on the host, which it treated as possible bring-your-own-vulnerable-driver activity [10]. BYOVD is how operators disable security products from the kernel [11].

Before encryption, both intrusions ran the same anti-recovery work: the Windows Recovery Environment turned off with reagentc /disable, the recovery partition removed via diskpart, several Windows event logs cleared, and the DNS cache flushed with ipconfig /flushdns [12]. The first incident also used the Windows cipher utility to overwrite previously deleted free space [13]. In the September case the attacker's code misspelled "Microsoft-Windows-Windows-Defender/Operational", so that log survived the clearing routine [15]. The Huntress agent went on mid-incident there [14].

SOCRadar's total of 93 claimed victims since June 2026 [2] is roughly 23 a month across June to September [1]. MOXFIVE says at least four of those have had data published, about 4 percent of the claimed count [3][2], and has found no evidence Settra runs as a service for affiliates [3]. Negotiation happens over Tox chat [19]. The claimed victims sit in retail and hospitality, manufacturing and production, professional services, construction and engineering, and food and beverage, with no industry pattern MOXFIVE could identify beyond unpatched systems and exposed credentials [20].

Huntress puts the intervention earlier than the RMM alert. "The best opportunity for defenders to detect the attack and prevent encryption is during the threat actor's initial attempts to gain access. Defenders should also prioritize alerts for unauthorized MeshAgent instances or suspicious driver deployment, especially when followed by event-log clearing or recovery tampering, since these early post-compromise behaviors offer the best chance to stop Settra before encryption begins," O'Donnell-Welch told SC Media [18].

Huntress could not name the initial access vector in either the July or the September incident [5]. MOXFIVE and SOCRadar have previously tied Settra to compromised credentials, including VPN credentials, and to exploitation of unpatched software [4]. Reputation feeds were thin on the September infrastructure: 11 of 89 vendors on VirusTotal flag that C2 address, about 12 percent [22][3], and Huntress linked the same address and the workstation name to malicious activity going back to Dec. 24, 2024 [21].

What to watch

  • Confirmation that gdrv.sys was loaded and used against endpoint agents in the September case, not only written to disk.
  • Whether SOCRadar's claimed-victim total keeps climbing at the June-to-September rate.
  • Other responders confirming Settra binaries named after the victim's own domain. That naming habit would hand defenders a cheap detection string.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories