logo

North Korean Lazarus Group Now Working With Medusa Ransomware

ID: 847c8a3f-3fab-50af-a878-f1e56f110092

STIX ID: report--847c8a3f-3fab-50af-a878-f1e56f110092

Feed Name: security.com

Threat Score
88/100

Date Published: 2026-02-24

Date Updated: 2026-04-29

Author: Threat Hunter Team

...
...

North Korean state-backed Lazarus actors (including Stonefly/Andariel) have been observed using the Medusa ransomware (run as RaaS) in extortion campaigns targeting U.S. healthcare and other organizations; the report describes associated tooling (Comebacker, Blindingcan, ChromeStealer, Mimikatz, RP_Proxy, etc.), links to prior indictments, and provides numerous IOCs (file hashes, IPs, domains) and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.