Ransomware · 3 days ago

Settra Hides Ransomware in Legitimate RMM

Huntress found two Settra ransomware incidents, one in July and one in September, that used the legitimate MeshAgent remote management agent inside consumer retail and manufacturing environments. In the September case, Huntress says its own agent was installed mid-incident, showing the endpoint was already compromised before monitoring caught up.

Instead of dropping a clearly malicious tool, the operators used MeshAgent like ordinary admin software, then cleared logs and showed signs of bring your own vulnerable driver (BYOVD) activity to make the trail harder to follow. That means the post-compromise work can blend into the same remote-support traffic defenders already expect to see, while the evidence trail shrinks.

For teams that rely on RMM or other always-on admin tools, the exposure is not just the ransomware payload but the trust those tools already have. Where remote support is normal, malicious use of it can look like routine work until forensic visibility is already gone.

Timeline

Sources

3 sources covering this story

Part of the PlainSec briefing for 2026-09-21

Editions

Related stories