Settra is a financially motivated ransomware and data-extortion operation first identified in June 2026. MOXFIVE reports direct incident-response work involving the group and describes a double-extortion model in which operators steal data, encrypt systems and threaten publication through a Tor-based leak site. Settra was still new at the time of the reviewed reporting, and public evidence does not establish a formal affiliate program, predecessor group or stable set of operators.
Activity and targeting
Settra began posting claimed victims in batches during late June 2026 and remained active through at least July 16. MOXFIVE observed nearly two dozen early listings and described activity spanning multiple sectors rather than a fixed geographic or industry target set. SOCRadar’s monitoring of an early Settra listing likewise placed claimed organizations across manufacturing, consumer services and technology and across countries including Singapore, the United States and Taiwan. Leak-site listings and claimed data volumes remain actor allegations unless corroborated by a victim, incident responder or verifiable technical evidence.
Settra says it is financially motivated and selects organizations with exploitable weaknesses rather than pursuing an ideological or country-specific agenda. That statement is consistent with the diverse early victim set, but it is the actor’s own characterization and does not establish a binding targeting policy. MOXFIVE also observed sporadic postings and delayed Tox responses, which could indicate a small operation, but the public record does not establish how many people are involved.
Methods and operational characteristics
In its direct case work, MOXFIVE observed Settra obtain initial access with compromised VPN credentials and use valid accounts to move through victim environments. Reported tooling included NetExec and Netscan for discovery, ProcDump and Mimikatz for credential access, and PAExec and NetExec for lateral movement. The actor used Mesh Agent for persistent remote access, cleared Windows event logs, deployed edr_blind to interfere with endpoint defenses and, in at least one case, abused the vulnerable STProcessMonitor_v114.sys driver to obtain kernel-level execution. These findings describe observed incidents and should not be treated as an invariant playbook for every Settra claim.
Settra uses Tox for negotiations and a Tor leak site to publish victim entries, samples, deadlines and threatened disclosures. LeMagIT assessed that the unusually detailed reports accompanying Settra posts were likely produced with AI-assisted analysis capable of identifying and summarizing sensitive files. That is a reporting assessment, not confirmed access to the group’s internal workflow, but it illustrates how Settra may convert stolen data into targeted regulatory, legal and reputational pressure.
What type of group is it?
Settra is best characterized as a financially motivated ransomware and data-extortion operation. Direct case evidence supports compromised access, hands-on-keyboard intrusion activity, data theft and encryption, but no reviewed public source identifies a Settra-specific encryptor or establishes that encryption occurred in every claimed incident. The operation’s structure remains unclear: it may be a small team, a closed service or an affiliate-driven program, and the available evidence does not distinguish among those models with confidence. The reviewed sources do not identify the operators, establish their jurisdiction, support state sponsorship or connect Settra to a predecessor ransomware brand.