Settra ransomware lists rcfassoc.com
The Settra ransomware group has publicly listed rcfassoc.com as a victim on their leak site with associated DNS records and screenshots.
The Settra ransomware operation has added rcfassoc.com to their victim disclosure site. The listing includes DNS record information and leak screenshots, indicating the group has likely exfiltrated data from the organization and is using the threat of publication to pressure payment.
This appears to be a standard ransomware extortion event following the double-extortion model, where operators both encrypt systems and threaten to leak stolen data. No specific details about the nature of the compromised data, the scope of the breach, or the initial access vector are provided in the source material.
The listing represents routine ransomware affiliate activity. Organizations should monitor for their domains appearing on such leak sites as an indicator of potential compromise, though the listing alone does not provide actionable technical intelligence about the attack methodology or timeline.
Mentioned in this report
Source reporting: https://www.ransomware.live/id/cmNmYXNzb2MuY29tQHNldHRyYQ==
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free