Advisory
Published 2026-09-17
Verified 2026-09-20

Huntress: Settra ransomware deploys MeshAgent RMM; September case used BYOVD (gdrv.sys)

Huntress (published 17 September 2026) documents two customer Settra ransomware incidents — July (consumer services/retail) and September (manufacturing; Huntress agent installed mid-incident). Initial access was not confirmed in either case; public reporting (MoxFive 22 Jul) previously tied Settra to VPN compromise and stolen credentials. Shared post-compromise TTPs: MeshAgent RMM for persistence (July: renamed mvtcs.exe → C2 45.13.122[.]7; September: unrebranded MeshAgent → 193.5.65[.]114), ransomware binary named <org-domain>_win64.exe, RESTORE_FILES.txt note, reagentc /disable, diskpart against a recovery-partition script, and Windows Event Log clearing. July also used cipher /w to wipe free space and encrypted to .locked from C:\Perflogs; September encrypted to .locked_wip from the user Documents folder and showed BYOVD via gdrv.sys (not seen in the July case). September operators misspelled the Windows Defender Operational log channel, so that log survived. Workstation name WIN-LIVFRVQFMKO previously linked by Huntress to 193.5.65[.]114. Australia relevance: desk already tracks AU Settra leak-site listings (pacific-abs-settra-20260917, verve-portraits-settra-20260903) — this card is the TTP/defence note, not a new AU victim. Primary: Huntress; wire: CyberSecurityNews 18 Sep.

Product
Settra ransomware; MeshAgent RMM; BYOVD via gdrv.sys (Sep case)
Versions
n/a (ransomware TTPs; Settra first publicly reported ~June 2026)
Exploited in Australia?
unknown
Patch to
Harden VPN/remote access (MFA, monitor); inventory and alert on unexpected RMM/MeshAgent installs; monitor for gdrv.sys / BYOVD driver loads; keep offline tested backups; preserve central Windows Event Log collection (local clearing is common). Distinct from AU victim cards pacific-abs-settra-20260917 and verve-portraits-settra-20260903.

Primary: Huntress — Ready, Settra, Go / MeshAgent + BYOVD (17 Sep 2026) · Vendor: Huntress blog (primary analysis) · CyberSecurityNews — Settra MeshAgent / BYOVD wire (18 Sep 2026)

breaches australia identity network