logo

North Korea’s Lazarus Group Deploys Medusa Ransomware Against U.S. Healthcare

ID: d7da9e83-7a1f-56ba-95c2-db3d92b8c6c0

STIX ID: report--d7da9e83-7a1f-56ba-95c2-db3d92b8c6c0

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-02-26

Date Updated: 2026-04-23

Author: Ddos

...
...

The Threat Hunter Team investigation links North Korean Lazarus affiliates (including Stonefly/Andariel) to a sustained Medusa ransomware campaign—deployed via Spearwing's RaaS—that has claimed over 366 attacks and targeted U.S. healthcare and vulnerable educational facilities, demanding an average of roughly $260,000; actors use a mix of custom backdoors and publicly available tools (Comebacker, Blindingcan, ChromeStealer, Mimikatz) to conduct intrusions, credential theft, and extortion to fund espionage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.