North Korea’s Lazarus Group Deploys Medusa Ransomware Against U.S. Healthcare
ID: d7da9e83-7a1f-56ba-95c2-db3d92b8c6c0
STIX ID: report--d7da9e83-7a1f-56ba-95c2-db3d92b8c6c0
Feed Name: securityonline.info
The Threat Hunter Team investigation links North Korean Lazarus affiliates (including Stonefly/Andariel) to a sustained Medusa ransomware campaign—deployed via Spearwing's RaaS—that has claimed over 366 attacks and targeted U.S. healthcare and vulnerable educational facilities, demanding an average of roughly $260,000; actors use a mix of custom backdoors and publicly available tools (Comebacker, Blindingcan, ChromeStealer, Mimikatz) to conduct intrusions, credential theft, and extortion to fund espionage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
