logo

Lazarus APT group deployed Medusa Ransomware against Middle East target

ID: 23558d54-afdc-58b7-9922-7aa58d1f03aa

STIX ID: report--23558d54-afdc-58b7-9922-7aa58d1f03aa

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-02-25

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

North Korea-linked Lazarus APT has been observed deploying Medusa ransomware (a 2023 RaaS) against an unnamed Middle East organization and attempting an attack on a U.S. healthcare entity; Symantec and Carbon Black report overlaps in tooling and provide IoCs linking the activity to Lazarus subgroups such as Stonefly/Andariel, noting a shift toward ransomware-driven extortion and continued financially motivated intrusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.