Settra is a ransomware and data-extortion group that emerged in June 2026, focusing on global extortion primarily for financial gain. They utilize double-extortion tactics, exfiltrating sensitive data before encrypting victims' systems and maximizing reputational pressure through published narratives on their dark web site.
Key insights
•Employs double-extortion tactics, threatening to release sensitive corporate information.
•Utilizes compromised credentials and unpatched software for initial access.
•Clears Windows Event Logs to evade detection during attacks.
•Targets a wide range of sectors including construction, manufacturing, and technology.
•Communicates with victims using Tox for negotiations.
•Exfiltrates various types of sensitive information such as employee records and financial documents.