[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f8BBkYXdRuhaF4fgFIvAN8tNb1I1lP6klr7BfdJGkrrw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":26,"created_at":27,"published_at":28,"article":29,"tags":33,"podcasts":52},"3a0d3f8b-85dd-4288-92df-a2ceaee63afe","settra-ransomware-abuses-rmm-tools-for-persistence-while-sabotaging-recovery","77b10692-55bd-4dc1-932d-13af3efea21b","Settra Ransomware Abuses RMM Tools for Persistence While Sabotaging Recovery","The Settra ransomware strain demonstrates how attackers leverage legitimate Remote Monitoring and Management (RMM) tools like MeshAgent to establish persistence, effectively blending into normal IT operations and evading detection. By disabling recovery environments and using Bring Your Own Vulnerable Driver (BYOVD) techniques, attackers ensure victims have limited options for remediation without paying. The deliberate clearing of Windows Event Logs highlights a calculated effort to destroy forensic evidence and hamper incident response — a tactic that ironically backfired in one case due to a typo, underscoring the importance of centralized, tamper-resistant logging. This incident illustrates why organizations must treat RMM tools as high-risk vectors and actively monitor for their unauthorized installation or misuse.","**Immediate actions:**\n- Audit all installed RMM tools across your environment and block unauthorized agents like MeshAgent using application allowlisting.\n- Enable centralized, offsite log aggregation (e.g., a SIEM) so that local event log clearing cannot eliminate forensic evidence.\n- Verify that Windows Recovery Environments and Volume Shadow Copies are intact and protected from unauthorized deletion.\n\n**Long-term improvements:**\n- Implement a formal RMM tool policy that restricts approved vendors, enforces MFA, and requires justification for any new agent deployment.\n- Apply driver allowlisting and Vulnerable Driver Blocklist policies (e.g., Microsoft HVCI) to prevent BYOVD-based security tool evasion.\n- Maintain immutable, offline backups tested regularly for restoration integrity to ensure ransomware cannot eliminate all recovery paths.\n\n**Detection measures:**\n- Create alerting rules for suspicious renaming of executables to match internal domain names, a known Settra obfuscation tactic.\n- Monitor for mass event log clearing commands (e.g., `wevtutil cl`) and treat any such activity as a high-priority incident signal.\n- Deploy behavioral detection controls that flag processes attempting to disable VSS, bcdedit recovery settings, or endpoint security services.",[12,13,14,15,16,17,18,19,20,21,22,23,24,25],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 8: Audit Log Management","CIS Control 10: Malware Defenses","CIS Control 11: Data Recovery","NIST SP 800-53 AU-9: Protection of Audit Information","NIST SP 800-53 CM-7: Least Functionality","NIST SP 800-53 CP-9: Information System Backup","NIST SP 800-53 SI-3: Malicious Code Protection","NIST Cybersecurity Framework: PR.IP-4 (Backups of information are conducted, maintained, and tested)","NIST Cybersecurity Framework: DE.CM-1 (Network monitoring to detect potential cybersecurity events)","MITRE ATT&CK T1219: Remote Access Software","MITRE ATT&CK T1070.001: Clear Windows Event Logs","MITRE ATT&CK T1490: Inhibit System Recovery","MITRE ATT&CK T1068: Exploitation for Privilege Escalation (BYOVD)","published","2026-09-17T18:21:03.788604+00:00","2026-09-17T18:21:03.162+00:00",{"id":7,"url":30,"slug":31,"title":32},"https:\u002F\u002Fwww.itsecurityguru.org\u002F2026\u002F09\u002F17\u002Fnew-settra-ransomware-strain-deploys-meshagent-rmm-for-persistence\u002F?utm_source=rss&utm_medium=rss&utm_campaign=new-settra-ransomware-strain-deploys-meshagent-rmm-for-persistence","new-settra-ransomware-strain-deploys-meshagent-rmm-for-persistence-ebd626","New Settra Ransomware Strain Deploys MeshAgent RMM for Persistence",[34,40,46],{"id":35,"name":36,"slug":37,"description":38,"color":39},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":41,"name":42,"slug":43,"description":44,"color":45},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":47,"name":48,"slug":49,"description":50,"color":51},"c8ff5d73-dec9-4911-88ee-ed016a89f3f4","Backup & Recovery","backup-recovery","No backups, untested recovery, ransomware impact","#f43f5e",[]]