# Ransomware group Settra lists neolife.com as victim

Published: 2026-09-03 · Severity: routine
Canonical: https://vorant.io/reports/0bde97bb-5dfe-51c7-ae1f-27950d870043/ransomware-group-settra-lists-neolife-com-as-victim

> A ransomware.live listing shows the group tracked as 'Settra' claiming neolife.com as a victim, with minimal technical detail provided.

This entry from ransomware.live documents a claimed compromise of the domain neolife.com, attributed to a ransomware operation referenced by the tracking handle 'Settra' (derived from the leak site's naming convention). The posting itself contains no technical intrusion details, exploited vulnerabilities, or malware artifacts — it is a leak-site index entry summarizing exposure statistics (2 compromised employees, 3,488 compromised users, 1 third-party employee credential set, and 19 external attack surface findings) sourced from Hudson Rock's infostealer credential intelligence tooling.

No evidence of active exploitation, malware deployment, or specific TTPs is provided in this record. The listing appears to correlate infostealer-derived credential exposure with a ransomware claim, consistent with the increasingly common pattern where stolen credentials from infostealer infections facilitate initial access for ransomware actors, though no direct causal chain is described here. Defenders associated with or monitoring the neolife.com domain should validate whether employee or third-party credentials have been exposed via infostealer logs and review external attack surface for unauthorized access points.

Given the lack of technical detail, confirmed exploitation method, or malware identification, this should be treated as a low-confidence victim notification rather than an actionable threat report. Organizations should nonetheless treat any leak-site claim as a trigger for incident response verification.

## Mentioned in this report

- Threat actors: settra

Source reporting: https://www.ransomware.live/id/bmVvbGlmZS5jb21Ac2V0dHJh

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/0bde97bb-5dfe-51c7-ae1f-27950d870043/ransomware-group-settra-lists-neolife-com-as-victim.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
