logo

North Korean Lazarus Group Adopts Medusa Ransomware in Global Attacks

ID: d387a526-51c1-51ba-93c1-059ed31e6bbf

STIX ID: report--d387a526-51c1-51ba-93c1-059ed31e6bbf

Feed Name: HackRead

Threat Score
88/100

Date Published: 2026-02-24

Date Updated: 2026-04-22

Author: Waqas

...
...

Symantec and Carbon Black research shows North Korea’s Lazarus Group has adopted the Medusa ransomware-as-a-service, executing multi-stage intrusions that disable defenses, deploy backdoors (Blindingcan, Comebacker), steal credentials (ChromeStealer, Mimikatz), stage/exfiltrate sensitive data (Infohook, RP_Proxy), and finally encrypt systems with Medusa; targets include healthcare and social-service organizations and ransom demands average around $260,000.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.