Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors settra

Also known as: tracked as, Seth, Ra, Kitty, Country Motors, APT43, nxc, Country Honda, Samurai Panda, PLA Navy, APT4, Wisp Team

Description

Settra first appeared in early June 2026, rapidly exposing more than two dozen organizations nationwide. The attackers obtain initial footholds by exploiting compromised VPN credentials and infostealer‑harvested passwords, enabling them to abuse legitimate administrative tools such as PsExec and WMI for lateral movement. Once inside, Settra focuses on data exfiltration rather than immediate system encryption. Using PowerShell and other Windows utilities, they harvest files, metadata, and credential artifacts, then upload the content to a Tor‑hosted leak site. The group communicates threat levels over the encrypted Tox messaging protocol and automates victim disclosure via pre‑defined schedules and deadlines. Settra’s approach is intentionally rapid and high‑volume: victims are posted in batches with roughly 20‑day dwell times, providing both urgency for ransom payments and a public reputation weapon. While they presently lack a widely deployed ransomware payload, speculation suggests that encryption may be introduced later to reinforce pressure. The group explicitly avoids military or government targets, focusing instead on commercial enterprises perceived as vulnerable. In sum, Settra represents an evolving data‑extortion threat that blends classic credential abuse with sophisticated exfiltration and leak‑site monetization, all wrapped in a fast‑moving operational tempo.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Defense
Financial services
Manufacturing
Retail
Healthcare
Government
Energy
Food agriculture
Education
Construction
Information technology
Transportation
Critical infrastructure

Targeted Countries / Regions

US
TW
GB
DE
BR
KR
SG
CA
FR
SA
RU

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

Settra is a medium‑sophistication criminal group that emerged in June 2026 and targets nearly any sector for financial gain through double‑extortion tactics. Using compromised VPN credentials and infostealer malware, the actors exfiltrate data and threaten public exposure via a Tor leak site before demanding ransom. Despite no confirmed ransomware engine yet, Settra’s rapid, batch disclosures have already impacted 25 victims across 11 countries.

Goals & Targeting

The core objective of Settra is financial gain via double‑extortion; the attackers first steal and threaten to publish sensitive data before demanding payment. They target a broad spectrum of sectors—defense, finance, manufacturing, retail, healthcare, government, energy, agriculture, education, construction, IT, transportation, and critical infrastructure—to maximize both revenue potential and media exposure. Settra specifically excludes military and certain government entities, indicating a strategic preference for commercial victims whose reputational stakes may drive faster ransom resolution.

Enhanced Description

Key Capabilities

  • Credential‑based initial access via compromised VPN credentials or infostealer‑harvested passwords
  • Lateral movement using valid accounts and legitimate administrative tools (PsExec, WMI, PowerShell)
  • Large‑scale data exfiltration to Tor‑hosted leak sites
  • Public disclosure of stolen data for reputational damage
  • Rapid, batch victim posting with automated deadlines
  • Communication via encrypted Tox messaging
  • Use of infostealer malware and credential harvesting tools (Mimikatz, procdump)
  • Potential use of ransomware payloads (BlackCat, Babuk, Qilin) once confirmed

MITRE ATT&CK Tactics

Initial Access
Credential Access
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1041
T1078.001
T1486
T1047
T1548.002
T1566.001
T1566.002
T1530
T1135
T1082
T1071
T1005
T1567.002
T1083
T1057
T1039
T1078.004
T1078.003
T0560

Software / Tooling

BlackCat
Babuk
Embargo
Qilin
Ruler
Mimikatz
Wevtutil
PsExec
phishing
Nmap
procdump
Netscan
PowerShell
AnyDesk
SpyPress
Crisis
Leverage
Guard
Payload
Gentlemen
Global
Icarus
PLAY
Silence
ZimReaper
Group Policy
Windows Command Shell
Custom-built malware
Telegram
GitHub
Infostealer Malware
KryBit
Advanced IP Scanner
SentinelOne
PAExec
Alphv

Campaigns & Victims

Settra’s known campaign footprint shows a fast‑moving, batch‑disclosure pattern beginning in June 2026. Over two months the group impacted 25 victims across diverse industries and 11 countries, with an average dwell time of roughly 20 days before extortion demands were issued. Initial access is almost always provided by compromised VPN credentials or infostealer harvests, after which lateral movement through administrative tools amplifies their reach. The organization has yet to definitively deploy a ransomware payload; however, their use of double‑extortion tactics signals an impending shift toward encryption. Public disclosures on a Tor leak site and communication via the Tox protocol underline Settra’s reliance on anonymity and reputation for rapid escalation.

IOC Patterns

  • domain
  • file
  • email
  • url
  • compromised vpn credentials
  • enriched tox messaging
  • tor-based leak site
  • hash
  • c2 ip address
  • campaign domain
  • mutex
  • host‑based registry artifact

Recommended Actions

  • Implement MFA and strengthen password policies to curb credential theft.
  • Monitor VPN and remote authentication logs for anomalous lateral movement patterns.
  • Harden externally accessible authentication services and enforce least privilege.
  • Deploy data loss prevention controls on sensitive employee and customer data.
  • Establish baseline exfiltration alerts to detect Tor or anonymizing network traffic.
  • Set up monitoring for compromised credential usage and abnormal login attempts.
  • Segment privileged accounts and use role‑based access control.
  • Create incident response playbooks for public disclosure threats.
  • Implement SIEM rules focusing on PowerShell abuse, registry changes, file deletions.
  • Secure web-facing infrastructure to mitigate leak site hosting.

Suggested Tags

double-extortion
ransomware
data-exfiltration
tor-based-leak-site
tox-encrypted-messaging
credential-compromise
extortion-via-publication
reputational-damage-focus
exfiltration-first
rapid-posting-rhythm
financial-motive
automation
non-military-targets
fast-moving-threat

Confidence Assessment

The available intelligence on Settra is moderately reliable, derived from two corroborating threat‑intel blogs and a consistent set of TTPs. However, gaps remain: no confirmed ransomware payload has been observed in the field yet, and details about exfiltration volumes and specific victim footprints are limited to high‑level reports. Consequently, confidence is sufficient for tactical protective measures but lower for strategic long‑term threat modeling.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 11 Filename 6 Email Address 1 URL 2

References

  1. www.moxfive.com — Cited by web research for: nxc
  2. mallory.ai — Cited by web research for: T1078
  3. cyberxtron.com — Cited by web research for: T1078.001
  4. www.provendata.com — Cited by web research for: Dark
  5. www.provendata.com — Cited by web research for: AnyDesk
  6. www.dexpose.io — Cited by web research for: Persistence mechanisms

Intel Summary

25

Techniques

47

Tools

37

Campaigns

23

IOCs

0

Observed Data

10

Tactics

Tags

double-extortion
ransomware
data-exfiltration
tor-based-leak-site
tox-encrypted-messaging
credential-compromise
extortion-via-publication
reputational-damage-focus
exfiltration-first
rapid-posting-rhythm
financial-motive
automation
non-military-targets
fast-moving-threat

Details

MITRE ID
APT4
Type
Criminal
Sophistication
Medium
Resource Level
Government
Primary Motivation
Organizational gain
Country of Origin
China (CN)
Confidence
80%
First Seen
Jun 2, 2026
Last Seen
Jul 21, 2026
Added
Jul 13, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.