Lazarus Group Medusa Ransomware — North Korean State-Backed Extortion Targeting US Healthcare and Middle East

Lazarus Group Medusa Ransomware (TL-2026-0140), also tracked as Medusa Ransomware, is a critical-severity ransomware operation, first published 2026-02-24. It is attributed to Lazarus Group (North Korea) with high confidence, affects Healthcare Organizations Hospital IT Systems, maps to 29 MITRE ATT&CK techniques (T1003.001, T1005, T1021.001), and is covered by 9 detection rules and 35 indicators of compromise.

Key facts for TL-2026-0140

Threat ID
TL-2026-0140
Also known as
Medusa Ransomware, Spearwing RaaS, Operation Stonefly Healthcare
Severity
CRITICAL
Status
ACTIVE
Category
RANSOMWARE
First published
2026-02-24
Last reviewed
2026-02-24
Attribution
Lazarus Group
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
healthcare, non-profit, education, defense, technology, government, critical-infrastructure
Target regions
North America, Middle East, East Asia
Detection rules
9
Indicators of compromise
35

Malware and tooling in Lazarus Group Medusa Ransomware

Malware and tooling: BLINDINGCAN, ChromeStealer, ComeBacker, MEDUSA - S1220, Advanced IP Scanner, AnyDesk, Mimikatz

North Korean Lazarus Group (Stonefly/Andariel sub-group) operating as Medusa RaaS affiliates, targeting US healthcare organizations and Middle Eastern entities. Third known DPRK ransomware family partnership after Maui and Play. Custom toolset includes Comebacker backdoor, Blindingcan RAT, ChromeStealer, RP_Proxy. Medusa has claimed 366+ victims since 2023. Ransom demands averaging $260K against healthcare/non-profit targets.

How Lazarus Group Medusa Ransomware works

Symantec/Broadcom Threat Hunter Team has uncovered evidence that North Korean state-backed Lazarus Group actors are now operating as Medusa ransomware-as-a-service (RaaS) affiliates, deploying Medusa ransomware in attacks against organizations in the Middle East and US healthcare sector.

This represents North Korea's third known ransomware family partnership, following previous collaborations with the Maui ransomware family and Play ransomware group (reported by Palo Alto Unit 42 in October 2024). The attacks are attributed to the Stonefly (Andariel) sub-group of Lazarus, although Symantec notes that specific tools like the Comebacker backdoor have also been associated with the Pompilus (Diamond Sleet) sub-group.

The Medusa ransomware operation, run by the Spearwing cybercrime group, has been active since June 2021 and operates as a RaaS platform where affiliates deploy the ransomware in exchange for a percentage of ransom payments. More than 366 attacks have been claimed by Medusa operators as of February 2025. Analysis of the Medusa leak site reveals attacks against four healthcare and non-profit organizations in the US since November 2025, including a non-profit in the mental health sector and an educational facility for autistic children, with an average ransom demand of $260,000.

The motivation behind Lazarus/Stonefly's involvement in ransomware was illuminated by a US DOJ indictment in July 2025, which charged a North Korean national named Rim Jong Hyok with ransomware attacks targeting US hospitals. The indictment alleged that proceeds from ransomware operations fund espionage activities targeting defense, technology, and government sectors in the US, Taiwan, and South Korea. Despite the indictment and a $10 million FBI reward for information on Rim, Stonefly continued operations.

The attacker toolset combines custom Lazarus malware with commodity tools: Comebacker (custom backdoor/loader exclusively associated with Lazarus), Blindingcan (RAT), ChromeStealer (browser credential theft), Infohook (information stealer), Mimikatz (credential dumping), RP_Proxy (custom proxying tool), and curl for data transfer. Medusa's broader operational TTPs include initial access via phishing and exploitation of known vulnerabilities (CVE-2024-1709 ScreenConnect, CVE-2023-48788 Fortinet EMS), living-off-the-land techniques, PowerShell with multiple evasion layers, PsExec for lateral movement, Rclone for exfiltration, and vulnerable driver exploitation to kill EDR tools.

The CISA advisory AA25-071a (March 2025) provides comprehensive TTPs and IOCs for Medusa operations broadly. Symantec's February 2026 report specifically ties Lazarus to these operations with 40+ file IOCs and 12 network indicators unique to the North Korean-affiliated campaign.

MITRE ATT&CK techniques used in TL-2026-0140

credential-access

T1003.001 LSASS Memory; T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers

collection

T1005 Data from Local System

lateral-movement

T1021.001 Remote Desktop Protocol; T1021.002 SMB/Windows Admin Shares

defense-evasion

T1027 Obfuscated Files or Information; T1027.013 Encrypted/Encoded File; T1070.003 Clear Command History; T1218 System Binary Proxy Execution

discovery

T1046 Network Service Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery

execution

T1047 Windows Management Instrumentation; T1059.001 PowerShell; T1059.003 Windows Command Shell; T1569.002 Service Execution

command-and-control

T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1219 Remote Access Tools; T1572 Protocol Tunneling

initial-access

T1190 Exploit Public-Facing Application; T1566 Phishing

impact

T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery

persistence

T1543 Create or Modify System Process

exfiltration

T1567.002 Exfiltration to Cloud Storage

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Lazarus Group Medusa Ransomware

  • Healthcare Organizations — Hospital IT Systems
    Vulnerable versions: All Windows-based healthcare environments
  • Non-Profit Organizations — IT Infrastructure
    Vulnerable versions: All Windows-based environments
  • ConnectWise — ScreenConnect
    Vulnerable versions: < 23.9.8
    Fixed in: 23.9.8+
  • Fortinet — FortiClient EMS
    Vulnerable versions: 7.0.1-7.0.10; 7.2.0-7.2.2
    Fixed in: 7.0.11+; 7.2.3+

Remediation for Lazarus Group Medusa Ransomware

Patches

  • Patch CVE-2024-1709 (ScreenConnect authentication bypass)
  • Patch CVE-2023-48788 (Fortinet EMS SQL injection)
  • Apply all OS and software patches within risk-informed timeframes

Immediate actions

  • Block all IOC IPs and domains at perimeter firewall and DNS sinkholes
  • Hunt for Comebacker and Blindingcan SHA256 hashes across all endpoints
  • Audit and restrict PsExec and RDP usage to authorized admin accounts only
  • Verify EDR agents are running and not tampered with on all critical systems
  • Implement network segmentation for healthcare/clinical systems

Workarounds

  • Disable unnecessary remote access tools (AnyDesk, Splashtop, etc.) where not required
  • Block PowerShell execution for non-admin users via AppLocker/WDAC
  • Monitor and alert on certutil.exe usage for file transfers
  • Restrict WMI remote access via firewall rules

Longer-term hardening

  • Deploy application whitelisting to prevent unauthorized executables
  • Implement LSASS protection (Credential Guard) to prevent Mimikatz attacks
  • Enforce MFA on all remote access and admin accounts
  • Deploy EDR with tamper protection and vulnerable driver blocking
  • Establish offline backup regimen with regular restore testing
  • Monitor for abnormal Rclone or curl data transfers to external destinations

Weaknesses (CWE) in Lazarus Group Medusa Ransomware

CWE-778, CWE-306

Timeline of Lazarus Group Medusa Ransomware

  • Medusa ransomware first identified as a closed ransomware variant. Source: CISA AA25-071A
  • Palo Alto Unit 42 reports Lazarus/DPRK collaboration with Play ransomware group — second known RaaS partnership. Source: https://unit42.paloaltonetworks.com/north-korean-threat-group-play-ransomware/
  • Symantec Threat Hunter Team discovers Stonefly intrusions against three US organizations with financial motivation. Source: https://www.security.com/threat-intelligence/stonefly-north-korea-extortion
  • FBI/CISA/MS-ISAC publish joint advisory AA25-071A on Medusa ransomware — 300+ victims across critical infrastructure. Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a
  • US DOJ indicts Rim Jong Hyok (Stonefly) for hospital ransomware attacks. $10M FBI reward issued. Source: https://www.justice.gov/opa/pr/north-korean-government-hacker-charged-involvement-ransomware-attacks-targeting-us-hospitals
  • Medusa leak site reveals attacks against four US healthcare and non-profit organizations since November 2025, including mental health non-profit and autism education facility. Average ransom: $260K.
  • Symantec/Broadcom publishes evidence of Lazarus Group operating as Medusa RaaS affiliates — confirmed attacks on Middle East target and US healthcare. 40+ file IOCs, 12 network indicators. Source: https://www.security.com/threat-intelligence/lazarus-medusa-ransomware
  • As of 2026-05-29, this DPRK Lazarus/Medusa healthcare ransomware campaign remains ACTIVE: Symantec/Carbon Black disclosed it Feb 2026, the Medusa leak site posts victims (e.g. UMMC) and the access-vector CVE-2024-1709 stays in CISA KEV, exploited into 2026. Lazarus is fully operational (~$577M crypto stolen Jan-Apr 2026, KelpDAO heist), with no takedown or successor.

Sources cited for Lazarus Group Medusa Ransomware

Threats related to Lazarus Group Medusa Ransomware

Detection coverage for TL-2026-0140

As of 2026-02-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0140 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats