North Korean Lazarus Group Adopts Medusa Ransomware in Global Attacks
ID: d387a526-51c1-51ba-93c1-059ed31e6bbf
STIX ID: report--d387a526-51c1-51ba-93c1-059ed31e6bbf
Feed Name: HackRead
Threat Score
Symantec and Carbon Black research shows North Korea’s Lazarus Group has adopted the Medusa ransomware-as-a-service, executing multi-stage intrusions that disable defenses, deploy backdoors (Blindingcan, Comebacker), steal credentials (ChromeStealer, Mimikatz), stage/exfiltrate sensitive data (Infohook, RP_Proxy), and finally encrypt systems with Medusa; targets include healthcare and social-service organizations and ransom demands average around $260,000.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
