VORANT. Threat Intelligence Sign in Get the full feed

Settra ransomware lists ilex-paysages.com

medium threat

The Settra ransomware group claimed ilex-paysages.com as a victim on their leak site, with DNS records and screenshots posted.

The Settra ransomware operation has added ilex-paysages.com to its public data leak site. The listing includes DNS records for the victim's domain and leak screenshots, indicating the threat actors have compromised the organization and exfiltrated data. The post follows the typical pattern of ransomware groups using leak sites to pressure victims into paying ransom demands by threatening to publish stolen data.

Settra is a relatively newer ransomware operation that follows the double-extortion model, where attackers both encrypt victim systems and exfiltrate sensitive data before encryption. The group threatens to publicly release stolen data if ransom demands are not met. Details about the scope of the compromise, the initial access vector, and the timeline of the attack were not provided in the available information.

Mentioned in this report

Threat actors settra
Malware Settra

Source reporting: https://www.ransomware.live/id/aWxleC1wYXlzYWdlcy5jb21Ac2V0dHJh

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free