Threats Tagged 'recovery inhibition'
View all threats tagged with 'recovery inhibition'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'recovery inhibition'
Click on any threat for detailed analysis and mitigation recommendations
Settra is a ransomware variant first observed in June 2026 targeting organizations via VPNs or compromised credentials. It uses MeshAgent RMM for persistence and encrypts files with .locked or .locked_wip extensions. The ransomware deploys ransom notes named RESTORE_FILES.txt, clears Windows event logs, and disables Windows recovery options using reagentc and diskpart. One incident involved Bring Your Own Vulnerable Driver (BYOVD) tactics with gdrv.sys. Attackers made an operational security error by misspelling the Windows Defender Event Log path, preventing its deletion. Two incidents in July and September 2026 affected consumer services, retail, and manufacturing sectors. The attacks showed similar patterns but used different command and control IP addresses. Join the discussion | AlienVault OTX General | 09/17/2026, 16:19:01 UTC Added: 09/18/2026, 08:46:41 UTC |
Showing 1 to 1 of 1 result