Settra is a ransomware and data-extortion threat actor that emerged publicly in 2026 through a cluster of claimed compromises and leak-site style victim disclosures. The group has been associated with attacks against organizations in multiple countries, including the United States, Germany, the United Kingdom, Tunisia, and Taiwan, with observed victim sectors including construction, business services, industrial manufacturing, mining, and e-commerce-related services. Settra’s operations are characterized by ransomware-linked intrusion claims combined with public assertions of data theft and exposure. Reported incidents indicate the group advertises stolen corporate documents and, in some cases, claims access to user information, consistent with double-extortion tradecraft in which data theft is used to pressure victims in addition to encryption or disruption. Public reporting has also associated Settra activity with the use of valid accounts and access to cloud-hosted data, aligning with ATT&CK techniques such as Valid Accounts (T1078) and Data from Cloud Storage (T1530). Victimology observed in 2026 suggests opportunistic targeting across diverse industries rather than a narrowly specialized vertical focus. Claimed victims include construction firms, registrar or business-services entities, industrial manufacturers supporting chemical and defense-related production, and consumer-facing technology subsidiaries. Settra has also appeared in ransomware claim-volume tracking, where it rapidly entered weekly rankings with a notable number of public claims, indicating an active leak-and-name operation during that period. Attribution to a specific nation state or government sponsor is not currently available. Available information supports describing Settra as an eCrime ransomware actor engaged in financially motivated extortion. No well-established sub-groups or widely used alternate aliases are currently available beyond the Settra name itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed a data breach against Pi Mobile Technology / PChome, alleging theft of internal documents and user data.
Conducting a ransomware attack and associated data breach against petradiamonds.com.
Conducting a ransomware attack resulting in a data breach against orion4value.com.
Conducting a ransomware attack against clc-tn.com / City Lumber Company in Tennessee.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.