logo

Lazarus Group Uses Medusa Ransomware in Middle East and U.S. Healthcare Attacks

ID: 178eb029-48b5-5b94-9c47-3393397f6429

STIX ID: report--178eb029-48b5-5b94-9c47-3393397f6429

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-02-24

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** North Korea-linked Lazarus Group has been observed deploying Medusa ransomware in attacks against an unnamed Middle Eastern entity and attempting an attack on a U.S. healthcare organization; the campaign leverages a mix of custom and public tools (RP_Proxy, Mimikatz, Comebacker, InfoHook, BLINDINGCAN, ChromeStealer) and aligns with a wider trend of DPRK actors partnering with RaaS operators to pursue financially motivated intrusions against healthcare and other organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.