Ransomware Group intelligence
Settra
ActiveTrack Settra with 123 published victims and 10 known leak locations in a single intelligence view.
Overview
Settra is tracked by Breach House as a ransomware group with 123 published victims.
United States is currently the most targeted country in this dataset.
10 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (10)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 9 | Onion service | Up checked 4h ago | r2vpglmz42fs5762tchek55bg4kdg3c6ozipg7wqs2ghzbhsdtwkzmyd.onion |
| Leak location 10 | Onion service | Up checked 4h ago | rz5lecsm2re5ec4im362jnalrypxylxsdobuibuotbovvs4d3ctrcoyd.onion |
| Leak location 8 | Onion service | Up checked 4h ago | hhj2nouojnatg6gvhfgrcqdanoe244gf26pixpnrcoxs7jiqu4atvzyd.onion |
| Leak location 6 | Onion service | Up checked 4h ago | settra5ceeidlmbt2d7zupsb3r7djl2azjj4mho5kznmdap6vnoxoxqd.onion |
| Leak location 1 | Onion service | Up checked 4h ago | settra5ldqwgtw5q7z5awbsvlksakyfojuc5slgrz5lvapune4fantqd.onion |
| Leak location 2 | Web location | Up checked 4h ago | settra5ldqwgtw5q7z5awbsvlksakyfojuc5slgrz5lvapune4fantqd.onion/leaks |
| Leak location 7 | Onion service | Down checked 4h ago | ttfy4zmtiaywfkkmykpxiwtlxkcr5ofvrhqgxxyspgwzbxkc3uze7jid.onion |
| Leak location 5 | Onion service | Down checked 4h ago | pbxvml6h3wz35qlr5muy2cg5jvjsd4qhjlsztmxj4lqkyohnfdrntqyd.onion |
| Leak location 4 | Onion service | Down checked 4h ago | c3u3g7dz2yxkefci3x34jfvfa4gka4iogi4zfjkyxx2c536oqdld4kid.onion |
| Leak location 3 | Onion service | Down checked 4h ago | 26z3gms2rshr2zzedxhw5fbucilmgt2inhmxzmuhteyztpxohoqplgyd.onion |
Top Activity Sectors (14)
- Manufacturing / Engineering 12
- Retail / E-commerce 9
- IT 9
- Finance / Legal / Insurance 6
- Construction / Real Estate 3
- Services 2
- Healthcare / Pharma 2
- Telecommunications 2
- Transportation / Travel / Logistics 2
- Not identified 2
- Agriculture / Food 2
- Hospitality / Food & Beverage / Tourism 1
- Energy 1
- NGOs / Associations 1
Typical Attacks (9)
▼MITRE ATT&CK does not currently catalogue Settra, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: settra executes malicious payloads through PowerShell scripts to deploy ransomware binaries and evade host-based detection.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: settra disables security tools by terminating antivirus processes and modifying Windows Defender service configurations on targeted engineering workstations.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: settra deletes Volume Shadow Copies and backup directories via vssadmin commands to prevent recovery from manufacturing server snapshots.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1049 System Network Connections Discovery Discovery
What they do: settra discovers system network connections to identify high-value engineering servers and isolate compromised retail environments.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1083 File and Directory Discovery Discovery
What they do: settra uses file and directory discovery via PowerShell to enumerate critical business documents and backups across manufacturing networks.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: settra moves laterally through SMB/Windows Admin Shares using stolen credentials to compromise retail and finance systems across corporate networks.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1560.001 Archive via Utility Collection
What they do: settra archives sensitive operational data using built-in utility commands prior to encryption to maximize financial theft impact.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1486 Data Encrypted for Impact Impact
What they do: settra encrypts victim data using custom symmetric encryption routines targeting engineering CAD files and financial ledgers before demanding ransom.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: settra inhibits system recovery by corrupting Windows restore points and disabling automated backup restoration processes on finance endpoints.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (123)
Search, filter and paginate the victim timeline for Settra. Showing 101–123 of 123.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | canopybrands.us id30056 View details | Canada | Retail / E-commerce | ||
|
Canopy Brands US operates in the retail and e-commerce sector, offering various products to customers in Canada. As an e-commerce company, it provides online shopping experiences. Canopy Brands US was listed as a ransomware victim associated with Settra. |
|||||
| Ransomware | canopybrands.us id30056 View details | Canada | Retail / E-commerce | ||
|
Limit of Travel A holding company that sells people safety at height failed to keep its own data saf... |
|||||
| Ransomware | conduril.pt id30057 View details | Portugal | Construction / Real Estate | ||
|
Conduril.pt is a Portugal-based company operating in the construction and real estate sector, providing various services to its clients. The company is involved in multiple projects across Portugal. Conduril.pt was listed as a ransomware victim associated with settra |
|||||
| Ransomware | conduril.pt id30057 View details | Portugal | Construction / Real Estate | ||
|
CONDURIL: WHAT THE COMPANY THAT BUILDS EVERYTHING IS BUILDING PROLOGUE: A FOUNDATION OF PAPER Condur... |
|||||
| Ransomware | hmcfarms.com id30058 View details | United States | Agriculture / Food | ||
|
Hmcfarms.com operates in the agriculture and food sector in the United States, providing various offerings to its customers. As an entity in this sector, it plays a role in the country's food supply chain. Hmcfarms.com was listed as a ransomware victim associated with settra |
|||||
| Ransomware | hmcfarms.com id30058 View details | United States | Agriculture / Food | ||
|
THE HMC GROUP: OPEN FIELD A California Central Valley agricultural holding feeds America peaches. It... |
|||||
| Ransomware | doosan.com id30059 View details | Korea, Republic of | Manufacturing / Engineering | ||
|
Doosan is a South Korean conglomerate with a diverse range of businesses in the manufacturing and engineering sector. The company offers various products and services, including construction equipment, engines, and industrial systems. Doosan operates globally, with its headquarters located in Seoul, South Korea. It was listed as a ransomware victim associated with Settra |
|||||
| Ransomware | doosan.com id30059 View details | Korea, Republic of | Manufacturing / Engineering | ||
|
How Doosan / Geith / Bobcat Buries Defects and Protects Its Secrets PROLOGUE: 3.27 TERABYTES OF FILE... |
|||||
| Ransomware | tmscentral.com id30060 View details | United States | Transportation / Travel / Logistics | ||
|
Tmscentral.com is a US-based company operating in the transportation and logistics sector, providing services to facilitate the movement of goods. The company's offerings cater to the needs of the travel and logistics industry. Tmscentral.com was listed as a ransomware victim associated with settra |
|||||
| Ransomware | tmscentral.com id30060 View details | United States | Transportation / Travel / Logistics | ||
|
A SIGNAL WITH NO BACKUP: How Total Monitoring Services Sells Multi-Channel Protection and Routes the... |
|||||
| Ransomware | va-glass.com id30061 View details | Holy See (Vatican City State) | Manufacturing / Engineering | ||
|
Va-glass.com is a company based in Virginia, operating in the manufacturing and engineering sector, providing various products and services. The company's offerings cater to the needs of its clients in the region. Va-glass.com was listed as a ransomware victim associated with settra |
|||||
| Ransomware | va-glass.com id30061 View details | Holy See (Vatican City State) | Manufacturing / Engineering | ||
|
THE TRANSPARENT MIRROR A company that sells people glass and reflections failed to protect its own r... |
|||||
| Ransomware | pchome.com.tw id30062 View details | Taiwan, Province of China | Retail / E-commerce | ||
|
Pchome.com.tw is a prominent e-commerce platform in Taiwan, offering a wide range of products and services to its customers. As a major player in the retail sector, it provides online shopping experiences to consumers across the country. Pchome.com.tw was listed as a ransomware victim associated with settra |
|||||
| Ransomware | pchome.com.tw id30062 View details | Taiwan, Province of China | Retail / E-commerce | ||
|
HOW A TAIWANESE GIANT SOLD OUT ITS CUSTOMERS A payment company sells trust, security, and reliabilit... |
|||||
| Ransomware | dystar.com id30063 View details | Singapore | Manufacturing / Engineering | ||
|
DyStar is a global leader in the manufacturing and engineering sector, providing high-quality products and services to its customers. Located in Singapore, the company operates in a competitive market, offering innovative solutions to meet the evolving needs of its clients. DyStar was listed as a ransomware victim associated with Settra. |
|||||
| Ransomware | dystar.com id30063 View details | Singapore | Manufacturing / Engineering | ||
|
The Complete Digital Archive of DyStar PROLOGUE: WHAT WE HAVE IN OUR HANDS 1.3 terabytes of data — f... |
|||||
| Ransomware | qdi.com id30064 View details | Taiwan, Province of China | IT | ||
|
Qdi.com is an IT company based in Taiwan, providing various IT services. The company operates in the IT sector, offering solutions to its clients. Qdi.com was listed as a ransomware victim associated with settra |
|||||
| Ransomware | qdi.com id30064 View details | Taiwan, Province of China | IT | ||
|
HOW QUALITY DINING CONVERTS LOSS INTO PROFIT PROLOGUE: ONE STORY ABOUT FINANCIAL ADJUSTMENTS Quality... |
|||||
| Ransomware | qdi.com id30064 View details | United States | IT | ||
|
HOW QUALITY DINING CONVERTS LOSS INTO PROFIT PROLOGUE: ONE STORY ABOUT FINANCIAL ADJUSTMENTS Quality... |
|||||
| Ransomware | turbodata.com id30065 View details | United States | IT | ||
|
Turbodata.com is an IT company based in the United States, offering various services within the IT sector. As a US-based entity, turbodata.com operates in a highly competitive market, providing solutions to its clients. Turbodata.com was listed as a ransomware victim associated with settra. |
|||||
| Ransomware | turbodata.com id30065 View details | United States | IT | ||
|
TICKET ISSUED: How Turbo Data Systems Built a Dossier on Half of California From a Slip of Paper Und... |
|||||
| Ransomware | lifevantage.com id30066 View details | United States | Healthcare / Pharma | ||
|
Lifevantage.com is a US-based company operating in the healthcare and pharma sector, offering various products and services. The company is involved in the development and distribution of health-related products. Lifevantage.com was listed as a ransomware victim associated with settra |
|||||
| Ransomware | lifevantage.com id30066 View details | United States | Healthcare / Pharma | ||
|
THE NEUTRALIZING FACTOR: How LifeVantage Corporation Profits from Hope and Buries the Truth PROLOGUE... |
|||||