North Korea's Lazarus Group targets healthcare orgs with Medusa ransomware
ID: db95b55a-f6bf-5c1f-908a-32e99e305bbb
STIX ID: report--db95b55a-f6bf-5c1f-908a-32e99e305bbb
Feed Name: The Register (Security)
Security researchers report that North Korea’s Lazarus Group has adopted Medusa ransomware in extortion campaigns, targeting at least one US healthcare organization and a Middle East victim; roughly 30 victims have appeared on the Medusa leak site since November 2025 (including multiple healthcare and nonprofit targets) with an average ransom demand of about $260,000. The analysis links Lazarus-associated tooling (Comebacker loader, Blindingcan RAT) and provides file indicators, while noting attribution uncertainty between Lazarus subgroups and Medusa affiliates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
