Quick Summary
AllegedExecutive Summary
Diasorin, the Italian multinational specializing in immunoassay and molecular diagnostics, has been listed as a victim by the settra ransomware group on their dark web portal as of September 3, 2026. SOCRadar’s Dark Web Monitoring service identified this listing, which targeted the company’s international digital infrastructure subdomain, int[.]diasorin[.]com. The size and global operational scope of Diasorin position it as a significant entity within settra’s recent victimology. In the 60 days preceding this listing, settra claimed responsibility for 32 other victims. Their primary targets have been organizations in the United States, Germany, the United Kingdom, and other European countries, with a strong focus on the technology, professional services, and manufacturing sectors. While healthcare firms have also been targeted, Diasorin’s inclusion suggests settra may be expanding its scope beyond its typical small-to-mid-market profile, indicating a potentially less opportunistic approach to target selection. Notable recent victims from Europe include Greco Steel Products (Greece, manufacturing), Belgicast Internacional (Sweden, manufacturing), Manhattan Loft Corporation Limited (United Kingdom, hospitality), and Hatch Communications (United Kingdom, professional services).
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry returned no records specifically for the queried domain, int[.]diasorin[.]com, within the analyzed data slice. It is crucial to note that the queried domain is an international subdomain and not Diasorin’s primary corporate domain. Employee credentials for Diasorin are more likely to be found in logs associated with diasorin[.]com or its various regional subdomains. Therefore, the absence of specific records for int[.]diasorin[.]com does not preclude the possibility of credential exposure across the organization’s broader digital presence. The potential for infostealer-harvested credentials to facilitate ransomware operations remains a significant concern. While direct telemetry for the specific subdomain queried did not yield results, the broad targeting patterns of ransomware groups often involve the acquisition of valid corporate credentials through various means, including compromised accounts on platforms like Microsoft 365, VPNs, or remote-access portals. Such credentials can provide initial access or facilitate lateral movement within a victim’s network. Given the listing on a ransomware leak site, organizations are advised to maintain continuous dark web and stealer-log monitoring. Proactive credential hygiene checks, including mandatory password rotation and multi-factor authentication review, are essential. Furthermore, monitoring of alternate corporate domains and thorough review of activity logs for Microsoft 365, VPNs, and remote-access systems are recommended to detect any potential unauthorized access or suspicious behavior.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.