Ransomware & Extortion · Ransomware

Settra Hides Ransomware in Legitimate RMM

Huntress found two Settra ransomware incidents, one in July and one in September, that used the legitimate MeshAgent remote management agent inside consumer retail and manufacturing environments. In the September case, Huntress says its own agent was installed mid-incident, showing the endpoint was already compromised before monitoring caught up.

Instead of dropping a clearly malicious tool, the operators used MeshAgent like ordinary admin software, then cleared logs and showed signs of bring your own vulnerable driver (BYOVD) activity to make the trail harder to follow. That means the post-compromise work can blend into the same remote-support traffic defenders already expect to see, while the evidence trail shrinks.

For teams that rely on RMM or other always-on admin tools, the exposure is not just the ransomware payload but the trust those tools already have. Where remote support is normal, malicious use of it can look like routine work until forensic visibility is already gone.

3 sources · 3 days ago

Timeline

Sources

Part of the PlainSec briefing for 2026-09-21

Every edition of this story: Settra Hides Ransomware in Legitimate RMM

More from today