logo

Lazarus Group Picks a New Poison: Medusa Ransomware

ID: cbfe08f5-13a8-5ca3-9ddd-da00ba21e7a5

STIX ID: report--cbfe08f5-13a8-5ca3-9ddd-da00ba21e7a5

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2026-02-24

Date Updated: 2026-04-21

Author: Rob Wright

...
...

Symantec and Carbon Black investigators attribute recent Medusa ransomware deployments to the North Korean Lazarus Group, which used additional tooling (Comebacker backdoor, Blindingcan RAT, Infohook infostealer) in attacks that targeted a large Middle Eastern organization and attempted an attack on a U.S. healthcare entity; the report notes TTPs including BYOVD/EDR-killer techniques and provides IOCs and behavioral indicators to detect and block the activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.