<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Meshagent - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/meshagent/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 22 Sep 2026 07:57:52 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/meshagent/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Settra Ransomware Variant Deploys MeshAgent RMM</title><link>https://feed.craftedsignal.io/briefs/2026-09-settra-ransomware/</link><pubDate>Tue, 22 Sep 2026 07:57:52 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-settra-ransomware/</guid><description>The Settra ransomware actor is utilizing legitimate MeshAgent remote management software to maintain persistence and facilitate post-compromise activity in victim environments.</description><content:encoded><![CDATA[<p>Huntress analysts have identified two recent incidents involving the Settra ransomware variant, which was first publicly documented in June 2026. The threat actor is leveraging MeshAgent, a legitimate Remote Monitoring and Management (RMM) tool, to establish and maintain persistent, unauthorized remote access to compromised Windows endpoints. This technique allows the actor to bypass traditional detection mechanisms that focus on known malicious tools, instead utilizing dual-use administrative software to conduct reconnaissance, move laterally, and exfiltrate data before deploying the final ransomware payload. The shift toward native RMM tools for post-compromise persistence highlights the importance of monitoring for unauthorized remote management installations.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Initial access is gained through an undisclosed vector, potentially credential compromise or exploitation of externally facing services.</li>
<li>The actor downloads the MeshAgent installer binary onto the target system.</li>
<li>MeshAgent is executed, establishing a persistent connection to the attacker-controlled C2 server via HTTPS.</li>
<li>The actor uses the MeshAgent interface to conduct internal network reconnaissance and identify high-value targets.</li>
<li>The actor performs lateral movement to gain administrative credentials or access sensitive file shares.</li>
<li>Data identified during reconnaissance is staged and exfiltrated from the environment.</li>
<li>The final ransomware payload is deployed across the network, encrypting files and appending a specific extension to compromised files.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful deployment of the Settra ransomware results in the full encryption of organizational data, significant operational downtime, and potential data exfiltration. The use of legitimate RMM tools like MeshAgent extends the attacker's dwell time, increasing the risk of data theft and lateral spread before the ransomware is eventually triggered.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Audit endpoints for the presence of unauthorized remote management software, specifically MeshAgent binaries.</li>
<li>Implement application whitelisting or endpoint controls to prevent the installation of unauthorized RMM agents.</li>
<li>Monitor for unexpected network traffic outbound from internal hosts to known MeshAgent or other RMM-associated infrastructure.</li>
<li>Review access logs for non-standard administrative sessions or unexpected use of remote management utilities.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>ransomware</category><category>persistence</category><category>rmm</category><category>meshagent</category></item></channel></rss>