Also known as: tracked as, Seth, Ra, Kitty, Country Motors, APT43, nxc, Country Honda, Samurai Panda, PLA Navy, APT4, Wisp Team
Settra first appeared in early June 2026, rapidly exposing more than two dozen organizations nationwide. The attackers obtain initial footholds by exploiting compromised VPN credentials and infostealer‑harvested passwords, enabling them to abuse legitimate administrative tools such as PsExec and WMI for lateral movement. Once inside, Settra focuses on data exfiltration rather than immediate system encryption. Using PowerShell and other Windows utilities, they harvest files, metadata, and credential artifacts, then upload the content to a Tor‑hosted leak site. The group communicates threat levels over the encrypted Tox messaging protocol and automates victim disclosure via pre‑defined schedules and deadlines. Settra’s approach is intentionally rapid and high‑volume: victims are posted in batches with roughly 20‑day dwell times, providing both urgency for ransom payments and a public reputation weapon. While they presently lack a widely deployed ransomware payload, speculation suggests that encryption may be introduced later to reinforce pressure. The group explicitly avoids military or government targets, focusing instead on commercial enterprises perceived as vulnerable. In sum, Settra represents an evolving data‑extortion threat that blends classic credential abuse with sophisticated exfiltration and leak‑site monetization, all wrapped in a fast‑moving operational tempo.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Settra is a medium‑sophistication criminal group that emerged in June 2026 and targets nearly any sector for financial gain through double‑extortion tactics. Using compromised VPN credentials and infostealer malware, the actors exfiltrate data and threaten public exposure via a Tor leak site before demanding ransom. Despite no confirmed ransomware engine yet, Settra’s rapid, batch disclosures have already impacted 25 victims across 11 countries.
Goals & Targeting
The core objective of Settra is financial gain via double‑extortion; the attackers first steal and threaten to publish sensitive data before demanding payment. They target a broad spectrum of sectors—defense, finance, manufacturing, retail, healthcare, government, energy, agriculture, education, construction, IT, transportation, and critical infrastructure—to maximize both revenue potential and media exposure. Settra specifically excludes military and certain government entities, indicating a strategic preference for commercial victims whose reputational stakes may drive faster ransom resolution.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Settra’s known campaign footprint shows a fast‑moving, batch‑disclosure pattern beginning in June 2026. Over two months the group impacted 25 victims across diverse industries and 11 countries, with an average dwell time of roughly 20 days before extortion demands were issued. Initial access is almost always provided by compromised VPN credentials or infostealer harvests, after which lateral movement through administrative tools amplifies their reach. The organization has yet to definitively deploy a ransomware payload; however, their use of double‑extortion tactics signals an impending shift toward encryption. Public disclosures on a Tor leak site and communication via the Tox protocol underline Settra’s reliance on anonymity and reputation for rapid escalation.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence on Settra is moderately reliable, derived from two corroborating threat‑intel blogs and a consistent set of TTPs. However, gaps remain: no confirmed ransomware payload has been observed in the field yet, and details about exfiltration volumes and specific victim footprints are limited to high‑level reports. Consequently, confidence is sufficient for tactical protective measures but lower for strategic long‑term threat modeling.
No observed data linked yet.
25
Techniques
47
Tools
37
Campaigns
23
IOCs
0
Observed Data
10
Tactics