Huntress reported two Settra ransomware incidents in July and September, with attackers using MeshAgent RMM, hiding activity, disabling recovery, and clearing logs. One case showed possible BYOVD via gdrv.sys. #Settra #MeshAgent #Ransomware
Explore
If you're running into malicious #meshagent in #malspams, keep an eye on the .msh file for details:
