Settra Ransomware Is the Last Thing That Happens

When most of us picture a ransomware attack, we picture the moment the screens go dark. Files won’t open, a ransom note shows up on the desktop, and somebody has to decide whether to pay.

That’s pretty much how I described it at the end of 2013, when I wrote a year-in-review piece on security, and CryptoLocker was the big ransomware story. The ransom was generally $300. I told readers there was really only one way to protect yourself, which was to back up your data so you could restore it and skip the extortionists altogether.

I thought about that advice while reading what Cynet Research Labs, the research arm of security vendor Cynet, published in September on a ransomware operation called Settra. There’s a full technical breakdown and a shorter account of the investigation, and between them researcher Itamar Medyoni and Cynet’s CyOps team describe an attack where the part that locks your files comes last, after the attackers have already taken what they came for.

What Cynet found inside the encryptor

Settra first showed up in June 2026, and Cynet puts the number of organizations named on the group’s leak site at somewhere between 50 and more than 70. That’s a count of what the group itself has claimed.

The file the attackers drop won’t run unless whoever launches it supplies a password on the command line. Without one, it quits and reports that everything went fine, which is enough to fool an automated sandbox. It’s a bit like a rental truck parked on your street. You can run the plates and look through the windshield, but whatever matters is padlocked in the back. Cynet says it got the key because its incident response team was working an active Settra case and recovered the password the attacker had used. That password has nothing to do with your files. It only unlocks the ransomware, which sits encrypted inside a thin loader until the operator runs it.

Once it’s unpacked, the encryptor spends a while getting the machine ready before it locks a single file. Cynet’s analysis says it powers down Hyper-V virtual machines so their disk files can be encrypted, turns off the Windows recovery environment, deletes the Windows Server Backup catalog, and clears 12 event logs along with the NTFS change journal that investigators use to rebuild a timeline. It also uses a built-in Windows feature called Restart Manager to shut down databases, mail servers, and other applications that are holding files open.

Most ransomware deletes shadow copies with a command that just about every security product watches for. Settra shrinks the storage set aside for them to 401 MB instead, and Windows purges the old restore points on its own to fit under the new limit. Whoever wrote that has read the same detection rules you have. So much for restoring from backup, at least if the backup lives on the same machine.

The data was gone before the encryptor arrived

Cynet says organizations often ask after an incident whether the ransomware uploaded their files. For Settra, the answer from the code is no. The encryptor has no HTTP client and no upload mechanism. It never calls home for keys, either, because the public key it needs is built into the binary and the private half never touches the victim’s machine.

So pulling the network cable once encryption starts won’t stop it. And a clean outbound traffic log from the ransomware itself tells you nothing about whether data left the building, because Cynet’s read is that the theft happens hours or days earlier.

By the time you see a ransom note, the movers have already come and gone, and the encryptor is the demolition crew sent in afterward. The intrusion Cynet describes starts with stolen credentials or a compromised VPN, moves through credential dumping and remote access tooling, and includes loading a signed but vulnerable driver, which Cynet identifies as part of Safetica’s STProcessMonitor family, to shut down security software from the kernel.

The note itself tells victims not to follow their standard emergency procedures, warns them off hiring recovery firms, and insists that all negotiation happen in a private Tor chat. That’s a long way from a $300 demand. It reads like it was written by somebody who has dealt with incident response firms before and would rather not do it again.

What the research means for defenders

Keep in mind that this is one vendor’s analysis of one sample recovered from one incident response case, and Cynet did the reverse engineering itself. I haven’t seen another team confirm the details.

A file that won’t run without a password won’t trip a sandbox or match a known signature, so the encryptor has to be caught by what it does once it starts. Cynet recommends blocking known vulnerable drivers with Microsoft’s blocklist, putting phishing-resistant MFA on VPNs and other remote access, isolating Hyper-V hosts on a dedicated management network, keeping backups offline under separate credentials, and forwarding logs off the machine in real time.

So my 2013 advice still stands, with a couple of amendments. Back up your data, but keep the backups somewhere the attacker’s stolen credentials can’t reach, and know that a backup won’t get back what they’ve already copied. And get your logs off the machine, because Settra erases them on every system it hits. If you don’t, the most detailed account of the attack you’ll have left may be the ransom note.

Tony Bradley: I have a passion for technology and gadgets and a desire to help others understand how technology can affect or improve their lives. I also love spending time with my wife, 7 kids, 3 dogs, 5 cats, a pot-bellied pig, and sulcata tortoise, and I like to think I enjoy reading and golf even though I never find time for either. You can contact me directly at tony@xpective.net. For more from me, you can follow me on Threads, Facebook, Instagram and LinkedIn.
Related Post