Activity timeline
Stonefly appears in 3 tracked threats between and ; the busiest month was 2026-02 with 1 report.
ATT&CK techniques observed
- T1082 System Information Discovery — Discoveryobserved in 3 of 3 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 3 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 2 of 3 tracked threats
- T1053 Scheduled Task/Job — Persistenceobserved in 2 of 3 tracked threats
- T1059.001 PowerShell — Executionobserved in 2 of 3 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 2 of 3 tracked threats
- T1083 File and Directory Discovery — Discoveryobserved in 2 of 3 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 2 of 3 tracked threats
- T1486 Data Encrypted for Impact — Impactobserved in 2 of 3 tracked threats
- T1489 Service Stop — Impactobserved in 2 of 3 tracked threats
- T1490 Inhibit System Recovery — Impactobserved in 2 of 3 tracked threats
- T1566 Phishing — Initial Accessobserved in 2 of 3 tracked threats
- T1569.002 System Services: Service Execution — Executionobserved in 2 of 3 tracked threats
- T1003 OS Credential Dumping — Credential Accessobserved in 1 of 3 tracked threats
Tracked threats
- Xctdoor Backdoor Delivered via Resume-Themed LNK Files, PowerShell/VBScript Loaders, and ProximityUxHost.exe DLL Side-Loading (Andariel)HIGH
- Lazarus Group (Stonefly) Medusa Ransomware — DPRK State-Backed Actors Deploy Medusa RaaS Targeting U.S. HealthcareCRITICAL
- Lazarus Group Medusa Ransomware — North Korean State-Backed Extortion Targeting US Healthcare and Middle EastCRITICAL