North Korean Lazarus Group Expands Ransomware Activity With Medusa
ID: 47872d22-897b-5505-aada-45f96bd15ae4
STIX ID: report--47872d22-897b-5505-aada-45f96bd15ae4
Feed Name: Infosecurity Magazine (News)
Threat Score
Researchers from Symantec and Carbon Black link the Medusa ransomware (operated via RaaS by affiliates) to North Korean state-backed actors associated with the Lazarus/Stonefly umbrella, reporting active campaigns that have claimed 366+ incidents, four US healthcare/non-profit victims since November 2025, average ransom demands of ~$260,000, and continued intrusion attempts despite prior indictments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
