Quick Summary
AllegedExecutive Summary
Golden Neo Life, a health and wellness company operating in the United States via neolife[.]com, has been identified as a victim of the settra ransomware group. The group’s dark web portal listed Golden Neo Life on September 3, 2026, according to SOCRadar’s Dark Web Monitoring service. This incident adds to a significant and ongoing pattern of settra activity targeting organizations across various sectors, particularly in the U.S. The healthcare and wellness industry, while not historically the sole focus of settra, has become an increasingly common target for ransomware and extortion operations. The settra ransomware group has demonstrated a consistent operational tempo. In the 60 days preceding this listing, settra claimed 32 other victims. The United States was the most frequently targeted country, followed by Germany and the United Kingdom. The group’s primary targets include the technology, professional services, and manufacturing sectors, although their scope is broad, evidenced by the inclusion of healthcare firms. Notable recent U.S. victims in settra’s portfolio include Zonar Systems (transportation), Zayo Group (technology), Howard Lumber Company (manufacturing), and Diversified Body Acquisition (manufacturing). The claim against Golden Neo Life signifies the group’s expansion into the consumer health and wellness domain.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry returned no records associated with the domain neolife[.]com within the queried sample. It is critical to understand that a null result from this specific query does not definitively confirm that Golden Neo Life is unaffected by the threat actor. The observed telemetry query covers only a paginated and limited sample of available stealer logs. It is possible that credentials may exist under alternate corporate domains, through personal email aliases used for corporate accounts, or within data feeds not included in this particular dataset. Furthermore, credentials associated with a compromise may have been utilized and subsequently rotated before being indexed in the queried logs, or the data may not have been indexed at all. The absence of evidence within this specific log sample is not conclusive proof that no compromise has occurred. The presence of exposed credentials, regardless of the source or the specific telemetry findings, can potentially facilitate initial access for ransomware operations, often through methods like exploiting VPNs, remote-access portals, or compromised Microsoft 365 accounts. Given the nature of these findings, continued monitoring of the dark web and stealer logs for any emerging information related to Golden Neo Life remains advisable. Proactive credential hygiene measures, including regular password rotation, thorough review of multi-factor authentication configurations, and vigilant monitoring of Microsoft 365, VPN, and remote-access activity, are essential steps for mitigating potential risks.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.