logo

North Korea's Lazarus Group targets healthcare orgs with Medusa ransomware

ID: db95b55a-f6bf-5c1f-908a-32e99e305bbb

STIX ID: report--db95b55a-f6bf-5c1f-908a-32e99e305bbb

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2026-02-24

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Security researchers report that North Korea’s Lazarus Group has adopted Medusa ransomware in extortion campaigns, targeting at least one US healthcare organization and a Middle East victim; roughly 30 victims have appeared on the Medusa leak site since November 2025 (including multiple healthcare and nonprofit targets) with an average ransom demand of about $260,000. The analysis links Lazarus-associated tooling (Comebacker loader, Blindingcan RAT) and provides file indicators, while noting attribution uncertainty between Lazarus subgroups and Medusa affiliates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.