NOTE: This is a Continuous Analysis Report of Settra Ransomware Group. The frequent updates of the group shall be found in this same article chronologically.
INDEX
- INTRODUCTION
- DLS OVERVIEW
- VICTIM PAGE
- DLS INTERNALS
- OBSERVED MODUS OPERANDI
- SETTRA CHAT PANEL
- SETTRA RANSOM NOTE
- CONCLUSION
INTRODUCTION
The group initially appeared in June 2026 targeting the US, Germany, UK, Canada and many more affecting various sectors like Tech, Manufacturing, Retail etc except Healthcare Industry.

IMG: SETTRA FROM WARHAMMER | SOURCE: REDDIT
NOTE: Settra is the name of a Warrior King created by Warhammer Fantasy [PC Game and Book Inspired]. He is the absolute, undying ruler of the Tomb Kings — a faction of ancient, Egyptian-style undead mummies and skeletons who rule the desert realm of Nehekhara (Land of Dead).
This analogy is not new in the Ransomware Ecosystem as we have seen many Ransomware Players adopting the Mythological/Game Character Names for their program such as Akira, Qilin, Anubis, Majinahanashi, Medusa, Tengu etc.

The group is notable for not listing/attacking a Healthcare industry unlike other Ransomware Groups.

DLS OVERVIEW
Their Data Leak Site can be reached at:-
settra5ldqwgtw5q7z5awbsvlksakyfojuc5slgrz5lvapune4fantqd.onion
The group uses Vanity Domain Name for their DLS and Negotiation Panel, but not for file servers, which we will see later in this article. Both has the word “SETTRA5”.
Like other groups, Settra also lists victims with a Countdown Timer. However, it takes about 2–4 days to list the complete data leak on the Victim’s Page, once the timer gets expired, which also depends on the exfiltrated size.

So far, the group had listed 64 Victims (ATTOW), the US leads the headcount. The group is also notable to use “forwards” apart from “Views” on their Victim’s Listed Section, which is unusual among Ransomware DLS.


VICTIM PAGE
The one feature which makes Settra stands out from other groups are the detailed/extensive profiling of Victims on the ‘Victim Page’ including the Financial Balance Sheets, Email Addresses, Legal etc which can be assumed to be summarized with the help of AI, after providing the entire breach to the AI Agents.
This method was previously adopted by TITAN Ransomware Group too, but in a minimal way.

The group moves 1 step ahead by exposing the Bank used by the Victim, Employee Termination Letter, Insurance Payout, Business Model etc.
The group also provides a number of screenshots of the files found in the breach to provide a quick-glance.

Let’s dive into the Victimology with a different approach here, focusing on Data Leak Size. Currently, the group had listed 56 Victims (both Timer Running & Expired).
doosan.com — 3.2TB dystar.com — 1.3TBflowco-inc.com — 1.2TBavkvalves.com — 1.37TB vcnyhome.com — 1TB zonarsystems.com — 849GBsamuelkoon.com — 748GBacilab.com — 653GB wcmanagement.info — 628GB bergdemo.com — 543GBam-bition.jp — 437GB wilmey.com — 410GB joyconstructionnyc.com — 261GB royalchain.com — 241GB menlosystems.com — 240GB qdi.com — 200GB cfsnow.com — 173GBowensborograin.com — 171GB manhattanloft.co.uk — 168GBconduril.pt — 163GB oligo.de — 144GB canopybrands.us — 141GB galmack.com.ec — 126GB hatch.group — 121GB howardlumber.com — 121GB ilex-paysages.com — 116GB tiltstudio.com — 108GB clc-tn.com — 99GBtranscar.com — 98GBinfinedi.net — 86GBprofinrg.nl — 74GBpetradiamonds.com — 50GBorion4value.com — 50GBgvsinc.com — 36GBhmcfarms.com — 35GBmakfreight.com — 34GBneolife.com — 33GBwlawllp.co.uk — 19GBdiversifiedbodyandpaint.com — 19GBgrecosteel.com — 18GBhvlawfirm.com — 1GB
It is evident that the group is capable to exfiltrate smaller file size ranging from 1 GB to 3 TB with effortlessly.
NOTE: Not all data leaks are analyzed in deep.
While assuming the file size, we can estimate that Settra might have used RClone, which is currently the fastest Exfiltration Tool available. The hefty 3.2TB of data could be exfiltrated from the victim within 7–8 Hours with 1Gbps connection and this would get more trimmed if the connection speed reaches 10Gbps, clocking under an hour. This also depends on the Victim Geography like South Korea is having a massive and decent Data Speed that clocks between 1–10Gbps.
The group had not announced any magnets (Torrent Share) and keeps all their Victim’s Data Breach being distributed on 3 Servers. Those are:-

- r2vpglmz42fs5762tchek55bg4kdg3c6ozipg7wqs2ghzbhsdtwkzmyd.onion
- rz5lecsm2re5ec4im362jnalrypxylxsdobuibuotbovvs4d3ctrcoyd.onion
- hhj2nouojnatg6gvhfgrcqdanoe244gf26pixpnrcoxs7jiqu4atvzyd.onion
The Victim Leak is navigable inside Victim Page itself like WorldLeaks Group. The whole breach is being distributed mainly among 3 Data Leak servers (nodes).


Earlier, the group had used other 4 Data Leak Servers (Nodes), which had been scrapped as of now. They were:-
- pbxvml6h3wz35qlr5muy2cg5jvjsd4qhjlsztmxj4lqkyohnfdrntqyd.onion
- 26z3gms2rshr2zzedxhw5fbucilmgt2inhmxzmuhteyztpxohoqplgyd.onion
- ttfy4zmtiaywfkkmykpxiwtlxkcr5ofvrhqgxxyspgwzbxkc3uze7jid.onion
- c3u3g7dz2yxkefci3x34jfvfa4gka4iogi4zfjkyxx2c536oqdld4kid.onion
These were dropped in late August 2026 and migrated to the above-mentioned File Server Onion Domains.
However, spotted another (node) server which is found in the new leak:-
wqdopgpr7cubbjcf2kiac6ilvamch3renqlzrly2dtwm3uyv2235zryd.onion

It is notable that the File Server Domains are not Vanity Domains of Settra as like DLS, which is quite common among Ransomware Groups.
DLS INTERNALS
The DLS of Settra is powered on an NGINX Server. However, it is clear that it is slow, often not gets loaded on first try, which makes anyone to think that the group went offline.
Upon analyzing the DLS of Settra, it is found that the group uses Anubis (by Techaro) — a popular open-source anti-bot / proof-of-work challenge system designed to stop scrapers, AI crawlers, and automated abuse.
NOTE: It is used to force clients to solve a computational challenge before being allowed through.
The cookie used is a JWT (EdDSA-signed).
{ "action": "CHALLENGE", "challenge": "01a06838–9295–7435–9c96–2c6be2faeda6", "exp": 1789059738, // ~10 Sep 2026 "iat": 1788454938, // issued on 3 Sep 2026 "method": "fast", "nbf": 1788454878, "policyRule": "ac980f49c4d35fab", "restriction": "12ca17b49af2289436f303e0166030a21e525d266e20926743801a8fd4071a0"}
Decoding the above response gives:-
➸Action is explicitly “CHALLENGE” — the client is being forced to solve a challenge
➸Method is “fast” (Anubis has different difficulty modes)
➸There’s a specific policyRule and a long restriction hash (likely binding the challenge to something like IP, user-agent, or path)
➸Signed with EdDSA (Ed25519) — Modern and Strong
Inspecting the JS file, following functionalities are uncovered which is also visible from the DLS present:-
➸Countdown timers (“Until full publication”) that flip to a green “PUBLISHED” state
➸Victim cards with site name, revenue, data size (cap), views, forwards
➸Markdown renderer for the overview text
➸Screenshot gallery + downloadable files
➸Download Nodes that are .onion links
➸When an onion link is clicked it opens an embedded file browser component that takes:
- baseUrl (the onion)
- postUid / clientId
- accessToken
The logo of Settra is customized a bit, which proves the group’s seriousness as there were many cases where the group directly adopted the logo from places like Vecteezy without any modification.

OBSERVED MODUS OPERANDI
While X-Checking the Victim List, it is found that there are few companies de-listed by the group.
This either means the group had agreed for the Ransom Payment, else it’s a pressure tactic used by the group to make us think that the Payment had been made and as a result, it got de-listed by the group from their DLS.
The list encompasses following who got de-listed by Settra on their DLS:-
➸turbodata.com: 233GB➸lifevantage.com: 585GB➸pchome.com.tw: 102GB➸touredge.com: 103GB➸makfreight.com: N/A➸alphanumeric.com: 161GB➸zayo.com: 460GB➸buroboot.nl: 717GB➸medevolve.com: 820GB➸int.diasorin.com: 221GB
NOTE: This can’t be confirmed unless we get a direct evidence from the victim.
The group provides about 18 Days as a Standard Count Down Timer for the victim.

The group is capable to host huge file sizes (in TBs) as we have seen 5 Data Breaches are in TBs.
Analyzing the Victim List, it can be assumed that the Initial Vector of Compromise is Infostealer Infection which comprises 50% of
NOTE: Infostealer does not solidify the statement of Initial Attack Vector, however it is just a factor to understand that the credentials were available on Dark Web for anyone to purchase and conduct the attack.
The group specializes in Initial Hook — A method to display the most critical/sensitive information display in a single line.




Apart from the Ransom Note, the group can be generally reached via TOX at: D288571294F08ADDFE46DF631194745143BE8B40F9F846379040DC40EB39BC2E8CE056B66927
As of now, the group has not announced any Affiliate Program, making it a player like PLAY Ransomware Group who does not open any Affiliate Programs.
SETTRA CHAT PANEL
The group also has a dedicated Negotiation Portal which can be accessed at:-
settra5ceeidlmbt2d7zupsb3r7djl2azjj4mho5kznmdap6vnoxoxqd.onion
It runs on nginx/1.22.14

Like other groups, a Unique Identifier found in the Ransom Note called “LOGIN ID” that helps to login to the Negotiation Portal.
Now, let’s enter into the Chat Room to see the internals:-

Once logged in, a “Return Key” is automatically generated by the Chat Panel which needs to be saved for next log-in. By using this Return Key, the victim would be able to launch the initiated Chat. If using the same Unique Identifier (Login ID) on next login, a new Return Key gets generated and the previous chat will not be shown though the Chat Room is same.
This methodology helps to preserve the Session Chat, so that no Intruder/Researcher can access the previous chat and acquire the intel.
So in short, if you want to get the real chat, you need to get the real Return Key rather than the Login ID found in the Ransom Note.
From the panel, it is evident that the group had setup the panel with necessary information for the victim to understand quickly by dividing into various sections.

NOTE: All the sections are general information which are common, however it is being arranged professionally which grasps quick attention.
The Negotiation Window is open for 20 days (in this case) and failure of negotiation would publish the data.
The demand went from: $900,000 -> $800,000 -> $700,000 -> $650,000 -> $600,000 -> $500,000

NOTE: Though a new BTC Wallet was allocated when the final deal was agreed which is bc1qfvm4gllzxdf6dwxx3e5dml02zealvkwqemxkv0wf8h0wr6ejc2mseeyhpw

After timeout, the group gives inbox notification about the Data Leak (when not paid), which is only visible to the victim at the moment, but eventually gets published on DLS and saved to Settra File Servers.

SETTRA RANSOM NOTE
File name is: RESTORE_FILES.txt
**By the time you read this message, you have already encountered not a malfunction, but the consequences of a targeted impact on your company's internal infrastructure**Before encrypting your company, we uploaded a large volume of your corporate data.**Systems are unavailable****Files are encrypted****Backups are encrypted or destroyed** **INSTRUCTION ON HOW TO CONTACT US. READ THIS MESSAGE IN FULL**Instructions for accessing the chat are in the last section. **IMPORTANT FOR YOU**At this stage, the main threat is not only the consequences of the incident themselves, but also erroneous decisions made in the first hours. Attempts to act according to a standard emergency scenario, without understanding the full scale of the breach, almost always worsen the final damage.Therefore:– Do not rename, replace, or move files manually.– Do not change the current state of the affected environment.– Do not launch unverified recovery procedures.– Do not delete files.If you violate these rules, recovery of your infrastructure will be impossible.From this moment on, the cost of every hasty action increases.Every incorrect intervention reduces the room for recovery.Every attempt to regain control blindly only creates new losses.Preserve the current state of your infrastructure. **WHAT HAPPENS NEXT**The present will determine not only the volume of technical damage, but also how deeply this incident will enter the operational, legal, and reputational history of your company.We know what damage we have caused you by blocking and uploading data from your network, which is now being fully studied and prepared for publication and notification of your clients, employees, regulators, and all those who may sue your company if you ignore the dialogue and payment.In this case, your losses will be catastrophic. **WHY IT IS IMPORTANT FOR YOU TO START A DIALOGUE**By entering into dialogue with us, you will be able to save your money, and possibly even lose almost nothing.We are not interested in destroying your business. Our goal is to receive fair compensation for maintaining the confidentiality of the extracted data, restoring control over your infrastructure, and providing a report on all vulnerabilities in your network to prevent future attacks on your company. We fully study the structure of your company and the uploaded data from your network for a reasonable demand.Why do we carefully study the stolen data? If negotiations drag on or you refuse to pay, your data will be published on our blog with detailed information and the contents of your data. **LINK BLOG**http://settra5ldqwgtw5q7z5awbsvlksakyfojuc5slgrz5lvapune4fantqd.onionWe are ready for any negotiations and always try to find a way to settle everything as quickly as possible so that the agreement suits both sides. **NEGOTIATION RULES**Negotiations with us are conducted strictly in the chat. We do not contact you by email or by any other means, and we are not responsible if you pay someone through third-party communication platforms while ignoring the chat.You will be able to access this chat using the instructions provided below in this message.Ignore any attempts to start a dialogue by email or to redirect you to a fake chat. Such attempts will certainly be made against you after your name appears on our blog, if you ignore the negotiations. **ADDITIONAL INSTRUCTION (if unable to contact)**If for some reason you are unable to contact us through the chat, on our blog in the information section our current contacts for direct communication will be indicated. **CAUTION: RECOVERY COMPANIES**When working with recovery companies, be careful. They always try to hide information that will be published in the blog and in the dialogue. Most importantly, they hide the amount of our demand, which they always inflate for you in order to make additional profit from your problem.We recommend that you conduct the negotiations yourself in order to minimize the costs of downtime and reputational damage to your company. They are not interested in solving your problem if they cannot earn a large amount of money by negotiating with us. **INSTRUCTION FOR ACCESSING THE CHAT**1. Install Tor Browser to access our chat:https://www.torproject.org/download/2. After installing Tor Browser, launch it and follow the link:http://settra5ceeidlmbt2d7zupsb3r7djl2azjj4mho5kznmdap6vnoxoxqd.onion/0000000000000xxxxxxxxx00000000This is your personal room for negotiations with us.3. Use this ID to log in:xxxxxxxxxx00000xxxxxxx000The faster you respond to this message, the fewer potential losses and risks you will incur.
CONCLUSION
From the observed tactics and professionalism, it can be concluded that the group is not new, though the brand is. This is a promising Ransomware Group who has the potential to target more sectors geographically.
NOTE: The updates would be added to this very article on regular basis whenever a new pattern emerges.
To view the IOCs in GitHub, you can find it here.
Follow me on Twitter/X for interesting DarkWeb/InfoSec Short findings!
Leave a Reply