Settra ransomware variant deployed in recent attacks | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Security researchers warn that a newly discovered ransomware variant called Settra has targeted virtual private network environments or compromised credentials for initial access before deploying remote monitoring and management tools to gain persistent access in targeted environments. 

Researchers from Huntress observed two specific attacks in recent months, including a July incident at a consumer services and retail organization and a September incident at a manufacturing firm, according to a blog post published Thursday.

“The attackers could be described as capable rather than sophisticated,” said Lindsey O’Donnell-Welch, principal technical community engagement writer at Huntress. “They used effective, established ransomware tradecraft: MeshAgent for persistence, a vulnerable driver to potentially impair defenses, log clearing and recovery tampering.”

Researchers from MoxFive said Settra used compromised VPN credentials to gain initial access and posted numerous victim organizations on its shaming site. The group claims to target organizations with exploitable weaknesses, such as unpatched systems or weak access management, according to a blog post from MoxFive. 

During both attacks, hackers used ransomware executables with the same name as the domain of the victim organization. Huntress said, in the first incident, the organization was an existing customer and, in the September incident, the security firm installed an agent in the middle of the attack sequence. However, Huntress was not able to confirm the method of initial access in either of these cases. 

During the July attack, Huntress noted the use of MeshAgent RMM tools. This was renamed mvtcs.exe, which led to a command-and-control address. A ransomware executable was launched the following day, according to Huntress. Files were encrypted and renamed before the hacker sent a ransom note. 

The hackers took several steps to cover their tracks, including clearing Windows Event Logs, disabling the Windows Recovery Environment and removing a recovery partition. 

During the September incident, Huntress found evidence hackers used the bring your own vulnerable driver (BYOVD) tactic in order to impact onboard security tools. The ransomware executable also included commands designed to disable recovery options and clear a number of Windows Event Logs.

——————————————————-


Click Here For The Original Source.