• Home
  • Privacy Policy
  • Terms and Conditions
  • DMCA
  • Disclaimer
  • Contact us
Friday, September 18, 2026
No Result
View All Result
NEWSLETTER defal
Lebanon Hub
NEWSLETTER
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up
No Result
View All Result
Lebanon Hub
No Result
View All Result

New Settra Ransomware Variant Deployed in Attacks on Retail and Manufa

September 18, 2026
in Cyber Security
0
Home Cyber Security
0
VIEWS
Share on FacebookShare on Twitter


A new ransomware variant named Settra has been deployed in incidents targeting the retail and manufacturing sectors, according to Huntress.

The variant was first observed in June, and Huntress researchers highlighted notable post-compromise techniques used by threat actors deploying Settra in attacks against an organization in the consumer services and retail sector in July, and a manufacturing firm in September.

These techniques include deploying remote monitoring and management (RMM) tools for persistent access, efforts to disable the victims’ recovery options, and installing bring your own vulnerable driver (BYOVD) to impacted systems.

The Huntress blog, published on September 17, highlighted how previous research on Settra showed the variant was used for double-extortion tactics, with the attackers threatening to release sensitive corporate information alongside encrypting systems.

There is currently not enough evidence to state that Settra is a ransomware-as-a-service (RaaS) operation, the researchers noted.

Key Post-Compromise Activities

Huntress said it was unable to confirm how the attackers gained initial access for the two incidents.

In the July attack on a retail organization, the threat actor installed the MeshAgent RMM in the victims’ environment, which connected to an IP address linked to the command-and-control (C2) infrastructure.

The next day, the ransomware executable was launched from the C:\Perflogs folder. This led to victim files being encrypted and renamed with the .locked file extension, before a ransom note was created.

EDR telemetry showed that immediately after the ransomware executable was launched, the threat actor took steps to prevent the victim organization’s recovery. This included clearing several Windows Event Logs, disable the Windows Recovery Environment, used ipconfig /flushdns to flush the DNS cache, and ran the diskpart native Window utility via a script to remove a recovery partition.

In addition, threat actors used the command cmd.exe /c cipher /w:D:\ >nul 2>&1 to launch the native Windows cipher utility to overwrite free space on multiple file volumes. This was done to make it more difficult to recover deleted data.

In the September attack on a manufacturing organization, similar techniques were used by threat actors, including the installation of the MeshAgent RMM and the disabling of recovery options once the ransomware executable was launched. However, there was one notable addition – the use of BYOVD. These drivers are installed for a range of purposes, including impacting onboard security tooling and crashing services related to antivirus applications.

The researchers noted that the attackers misspelled one of the Windows Event Logs they were attempting to clear, stopping this action from being carried out.

The workstation name WIN-LIVFRVQFMKO was associated with the malicious activity carried out during the September incident. This name was previously observed as associated with other incidents going back to December 2024 by Huntress.

In both incidents, the ransomware executable was named for the impacted organization’s domain name, appended with _win64.exe.

“While there were slight differences between the two incidents, such as the naming and C2 IP address of the MeshAgent RMM, as well as the folders the threat actors operated from, the overall conduct of the attacks were remarkably similar,” the researchers wrote.

Recommendations for Defenders

The researchers noted that new ransomware variants are frequently emerging, and each come with their own distinct tactics, techniques and procedures (TTPs).

Read now: A New Ransomware Threat Actor Emerges Every Week, Warns Report

They urged security teams to stay up-to-date with these variants, and the post-compromise techniques used to help detect and respond to such attacks.

Defenders should also continue to focus on the “fundamentals” of cyber defense to prevent these attacks occurring, the blog added.



Source link

Next Post

This Google Messages feature is finally breaking RCS exclusivity

Beirut, LB
28°
Partly Cloudy
06:2218:40 EEST
Feels like: 30°C
Wind: 11km/h SW
Humidity: 58%
Pressure: 1011.18mbar
UV index: 7
SatSunMon
30°C / 25°C
31°C / 26°C
31°C / 26°C
powered by Weather Atlas

Recent News

SBI, Kyobo Complete Japan-Korea Stablecoin Test With No Dollar Leg – Bitcoin News

September 18, 2026

Ethereum Institutional Supports Ethlabs’ Motion to Reduce Ethereum Block Times

September 18, 2026

Recent trends in the liteverse 🧐

September 18, 2026

The Missing Tail lets you and a friend become cats in a medieval co-op adventure – GamingPH.com

September 18, 2026

Next Week on XBOX: New Games for September 21 to 25

September 18, 2026

Surprise Hit 2020 PS5 RPG Under $5 in PS Store Deal

September 18, 2026

Silent Hill: Townfall’s Scotland setting is “really weird for players,” but it’s one of the game’s highlights

September 18, 2026

King faces potential strike in Sweden over collective agreement

September 18, 2026
Lebanon Hub

Get the Latest Lebanon News and world News on LebanonHub.com. Local News, Sports, Technology, Music, Celebrity, Gaming News and Cryptocurrency Updates.

Category

  • Altcoin
  • Australia
  • Bitcoin
  • Blockchain
  • Celebrity
  • Cyber Security
  • Ethereum
  • Exchange
  • Litecoin
  • Local News
  • Mobile
  • Movies
  • Music
  • New Released
  • PC
  • PlayStation
  • Reviews
  • Sports
  • Startups
  • Technology
  • TV
  • XBOX

Recent News

SBI, Kyobo Complete Japan-Korea Stablecoin Test With No Dollar Leg – Bitcoin News

September 18, 2026

Ethereum Institutional Supports Ethlabs’ Motion to Reduce Ethereum Block Times

September 18, 2026
  • Home
  • DMCA
  • Disclaimer
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2022 - Lebanon Hub.

No Result
View All Result
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up

Copyright © 2022 - Lebanon Hub.