Lazarus Group Medusa Ransomware — North Korean State-Backed Extortion Targeting US Healthcare and Middle East
Lazarus Group Medusa Ransomware (TL-2026-0140), also tracked as Medusa Ransomware, is a critical-severity ransomware operation, first published 2026-02-24. It is attributed to Lazarus Group (North Korea) with high confidence, affects Healthcare Organizations Hospital IT Systems, maps to 29 MITRE ATT&CK techniques (T1003.001, T1005, T1021.001), and is covered by 9 detection rules and 35 indicators of compromise.
Key facts for TL-2026-0140
- Threat ID
- TL-2026-0140
- Also known as
- Medusa Ransomware, Spearwing RaaS, Operation Stonefly Healthcare
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-02-24
- Last reviewed
- 2026-02-24
- Attribution
- Lazarus Group
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- healthcare, non-profit, education, defense, technology, government, critical-infrastructure
- Target regions
- North America, Middle East, East Asia
- Detection rules
- 9
- Indicators of compromise
- 35
Malware and tooling in Lazarus Group Medusa Ransomware
Malware and tooling: BLINDINGCAN, ChromeStealer, ComeBacker, MEDUSA - S1220, Advanced IP Scanner, AnyDesk, Mimikatz
North Korean Lazarus Group (Stonefly/Andariel sub-group) operating as Medusa RaaS affiliates, targeting US healthcare organizations and Middle Eastern entities. Third known DPRK ransomware family partnership after Maui and Play. Custom toolset includes Comebacker backdoor, Blindingcan RAT, ChromeStealer, RP_Proxy. Medusa has claimed 366+ victims since 2023. Ransom demands averaging $260K against healthcare/non-profit targets.
How Lazarus Group Medusa Ransomware works
Symantec/Broadcom Threat Hunter Team has uncovered evidence that North Korean state-backed Lazarus Group actors are now operating as Medusa ransomware-as-a-service (RaaS) affiliates, deploying Medusa ransomware in attacks against organizations in the Middle East and US healthcare sector.
This represents North Korea's third known ransomware family partnership, following previous collaborations with the Maui ransomware family and Play ransomware group (reported by Palo Alto Unit 42 in October 2024). The attacks are attributed to the Stonefly (Andariel) sub-group of Lazarus, although Symantec notes that specific tools like the Comebacker backdoor have also been associated with the Pompilus (Diamond Sleet) sub-group.
The Medusa ransomware operation, run by the Spearwing cybercrime group, has been active since June 2021 and operates as a RaaS platform where affiliates deploy the ransomware in exchange for a percentage of ransom payments. More than 366 attacks have been claimed by Medusa operators as of February 2025. Analysis of the Medusa leak site reveals attacks against four healthcare and non-profit organizations in the US since November 2025, including a non-profit in the mental health sector and an educational facility for autistic children, with an average ransom demand of $260,000.
The motivation behind Lazarus/Stonefly's involvement in ransomware was illuminated by a US DOJ indictment in July 2025, which charged a North Korean national named Rim Jong Hyok with ransomware attacks targeting US hospitals. The indictment alleged that proceeds from ransomware operations fund espionage activities targeting defense, technology, and government sectors in the US, Taiwan, and South Korea. Despite the indictment and a $10 million FBI reward for information on Rim, Stonefly continued operations.
The attacker toolset combines custom Lazarus malware with commodity tools: Comebacker (custom backdoor/loader exclusively associated with Lazarus), Blindingcan (RAT), ChromeStealer (browser credential theft), Infohook (information stealer), Mimikatz (credential dumping), RP_Proxy (custom proxying tool), and curl for data transfer. Medusa's broader operational TTPs include initial access via phishing and exploitation of known vulnerabilities (CVE-2024-1709 ScreenConnect, CVE-2023-48788 Fortinet EMS), living-off-the-land techniques, PowerShell with multiple evasion layers, PsExec for lateral movement, Rclone for exfiltration, and vulnerable driver exploitation to kill EDR tools.
The CISA advisory AA25-071a (March 2025) provides comprehensive TTPs and IOCs for Medusa operations broadly. Symantec's February 2026 report specifically ties Lazarus to these operations with 40+ file IOCs and 12 network indicators unique to the North Korean-affiliated campaign.
MITRE ATT&CK techniques used in TL-2026-0140
credential-access
T1003.001 LSASS Memory; T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers
collection
lateral-movement
T1021.001 Remote Desktop Protocol; T1021.002 SMB/Windows Admin Shares
defense-evasion
T1027 Obfuscated Files or Information; T1027.013 Encrypted/Encoded File; T1070.003 Clear Command History; T1218 System Binary Proxy Execution
discovery
T1046 Network Service Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery
execution
T1047 Windows Management Instrumentation; T1059.001 PowerShell; T1059.003 Windows Command Shell; T1569.002 Service Execution
command-and-control
T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1219 Remote Access Tools; T1572 Protocol Tunneling
initial-access
T1190 Exploit Public-Facing Application; T1566 Phishing
impact
T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery
persistence
T1543 Create or Modify System Process
exfiltration
T1567.002 Exfiltration to Cloud Storage
defense-impairment
Affected products and versions in Lazarus Group Medusa Ransomware
- Healthcare Organizations — Hospital IT Systems
Vulnerable versions: All Windows-based healthcare environments - Non-Profit Organizations — IT Infrastructure
Vulnerable versions: All Windows-based environments - ConnectWise — ScreenConnect
Vulnerable versions: < 23.9.8
Fixed in: 23.9.8+ - Fortinet — FortiClient EMS
Vulnerable versions: 7.0.1-7.0.10; 7.2.0-7.2.2
Fixed in: 7.0.11+; 7.2.3+
Remediation for Lazarus Group Medusa Ransomware
Patches
- Patch CVE-2024-1709 (ScreenConnect authentication bypass)
- Patch CVE-2023-48788 (Fortinet EMS SQL injection)
- Apply all OS and software patches within risk-informed timeframes
Immediate actions
- Block all IOC IPs and domains at perimeter firewall and DNS sinkholes
- Hunt for Comebacker and Blindingcan SHA256 hashes across all endpoints
- Audit and restrict PsExec and RDP usage to authorized admin accounts only
- Verify EDR agents are running and not tampered with on all critical systems
- Implement network segmentation for healthcare/clinical systems
Workarounds
- Disable unnecessary remote access tools (AnyDesk, Splashtop, etc.) where not required
- Block PowerShell execution for non-admin users via AppLocker/WDAC
- Monitor and alert on certutil.exe usage for file transfers
- Restrict WMI remote access via firewall rules
Longer-term hardening
- Deploy application whitelisting to prevent unauthorized executables
- Implement LSASS protection (Credential Guard) to prevent Mimikatz attacks
- Enforce MFA on all remote access and admin accounts
- Deploy EDR with tamper protection and vulnerable driver blocking
- Establish offline backup regimen with regular restore testing
- Monitor for abnormal Rclone or curl data transfers to external destinations
Weaknesses (CWE) in Lazarus Group Medusa Ransomware
CWE-778, CWE-306
Timeline of Lazarus Group Medusa Ransomware
- Medusa ransomware first identified as a closed ransomware variant. Source: CISA AA25-071A
- Palo Alto Unit 42 reports Lazarus/DPRK collaboration with Play ransomware group — second known RaaS partnership. Source: https://unit42.paloaltonetworks.com/north-korean-threat-group-play-ransomware/
- Symantec Threat Hunter Team discovers Stonefly intrusions against three US organizations with financial motivation. Source: https://www.security.com/threat-intelligence/stonefly-north-korea-extortion
- FBI/CISA/MS-ISAC publish joint advisory AA25-071A on Medusa ransomware — 300+ victims across critical infrastructure. Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a
- US DOJ indicts Rim Jong Hyok (Stonefly) for hospital ransomware attacks. $10M FBI reward issued. Source: https://www.justice.gov/opa/pr/north-korean-government-hacker-charged-involvement-ransomware-attacks-targeting-us-hospitals
- Medusa leak site reveals attacks against four US healthcare and non-profit organizations since November 2025, including mental health non-profit and autism education facility. Average ransom: $260K.
- Symantec/Broadcom publishes evidence of Lazarus Group operating as Medusa RaaS affiliates — confirmed attacks on Middle East target and US healthcare. 40+ file IOCs, 12 network indicators. Source: https://www.security.com/threat-intelligence/lazarus-medusa-ransomware
- As of 2026-05-29, this DPRK Lazarus/Medusa healthcare ransomware campaign remains ACTIVE: Symantec/Carbon Black disclosed it Feb 2026, the Medusa leak site posts victims (e.g. UMMC) and the access-vector CVE-2024-1709 stays in CISA KEV, exploited into 2026. Lazarus is fully operational (~$577M crypto stolen Jan-Apr 2026, KelpDAO heist), with no takedown or successor.
Sources cited for Lazarus Group Medusa Ransomware
- Symantec: North Korean Lazarus Group Now Working With Medusa Ransomware
- CISA Advisory AA25-071A: #StopRansomware: Medusa Ransomware
- US DOJ Indictment: Rim Jong Hyok — Hospital Ransomware
- FBI Wanted: Rim Jong Hyok ($10M Reward)
- Symantec: Stonefly North Korea Extortion (Oct 2024)
- Unit 42: North Korean Threat Group Collaborates with Play Ransomware
- Microsoft: ZINC Attacks Against Security Researchers (Comebacker)
Threats related to Lazarus Group Medusa Ransomware
Detection coverage for TL-2026-0140
As of 2026-02-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0140 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.