logo

Lazarus hackers adopt Medusa ransomware for extortion campaigns, targeting healthcare and nonprofits

ID: e8820c42-a471-538f-9cba-1d8783c07ff0

STIX ID: report--e8820c42-a471-538f-9cba-1d8783c07ff0

Feed Name: DataBreaches.Net

Threat Score
74/100

Date Published: 2026-02-24

Date Updated: 2026-04-19

Author: Dissent

...
...

Symantec and Carbon Black Threat Hunter teams report evidence that North Korea–linked Lazarus Group is leveraging Medusa ransomware in ongoing extortion operations, with a confirmed Middle East victim and a thwarted attempt against a U.S. healthcare organization, signaling continued ransomware campaigns against healthcare and nonprofit targets despite prior U.S. indictments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.