Lazarus Group Picks a New Poison: Medusa Ransomware
ID: cbfe08f5-13a8-5ca3-9ddd-da00ba21e7a5
STIX ID: report--cbfe08f5-13a8-5ca3-9ddd-da00ba21e7a5
Feed Name: Dark Reading
Threat Score
Symantec and Carbon Black investigators attribute recent Medusa ransomware deployments to the North Korean Lazarus Group, which used additional tooling (Comebacker backdoor, Blindingcan RAT, Infohook infostealer) in attacks that targeted a large Middle Eastern organization and attempted an attack on a U.S. healthcare entity; the report notes TTPs including BYOVD/EDR-killer techniques and provides IOCs and behavioral indicators to detect and block the activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
