Lazarus Group (Stonefly) Medusa Ransomware — DPRK State-Backed Actors Deploy Medusa RaaS Targeting U.S. Healthcare
Lazarus Group (Stonefly) Medusa Ransomware (TL-2026-0172), also tracked as Medusa RaaS, is a critical-severity ransomware operation scored CVSS 9, first published 2026-03-03. It is attributed to Lazarus Group (North Korea) with high confidence, maps to 24 MITRE ATT&CK techniques (T1003, T1016, T1021), and is covered by 9 detection rules and 19 indicators of compromise.
Key facts for TL-2026-0172
- Threat ID
- TL-2026-0172
- Also known as
- Medusa RaaS, Spearwing
- Severity
- CRITICAL
- CVSS
- 9
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-03-03
- Last reviewed
- 2026-03-03
- Attribution
- Lazarus Group
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- healthcare, nonprofit, education, defense, technology, government, manufacturing
- Target regions
- United States, Middle East, South Korea, Taiwan
- Detection rules
- 9
- Indicators of compromise
- 19
Malware and tooling in Lazarus Group (Stonefly) Medusa Ransomware
Malware and tooling: MEDUSA - S1220, Mimikatz
North Korean state-sponsored Lazarus Group, specifically the Stonefly/Andariel subgroup, has adopted Medusa ransomware-as-a-service for extortion campaigns targeting U.S. healthcare organizations, nonprofits, and Middle Eastern entities. Symantec and Carbon Black confirmed Lazarus involvement through exclusive tools including the Comebacker backdoor.
How Lazarus Group (Stonefly) Medusa Ransomware works
Symantec and Carbon Black Threat Hunter Team published findings on February 24, 2026 documenting North Korean state-sponsored actors deploying Medusa ransomware in targeted extortion campaigns. The investigation revealed Lazarus Group operators successfully attacked an unnamed organization in the Middle East and mounted an unsuccessful attempt against a U.S. healthcare organization.
Medusa is a ransomware-as-a-service (RaaS) platform operated by the Spearwing cybercrime group since 2023. Affiliates deploy Medusa variants in exchange for a percentage of ransom payments. More than 366 attacks have been claimed by Medusa affiliates across its operational history, targeting critical sectors including healthcare, education, legal, insurance, technology, and manufacturing. A joint FBI/CISA advisory in March 2025 specifically warned about Medusa's impact on critical infrastructure.
The Lazarus Group is an umbrella designation for North Korean state-sponsored cyber operations. The Stonefly subgroup (also tracked as Andariel, Onyx Sleet, and Silent Chollima) operates under North Korea's Reconnaissance General Bureau (RGB) military intelligence. Stonefly has a documented history of ransomware use — previously deploying Maui ransomware against healthcare targets and collaborating with the Play ransomware group in October 2024.
Attribution to Lazarus was confirmed through the presence of the Comebacker backdoor, a custom malware family exclusively associated with Lazarus Group. Additional tooling included Blindingcan (AIRDRY/ZetaNile) RAT, ChromeStealer for browser credential theft, InfoHook information stealer, Mimikatz for credential dumping, RP_Proxy custom proxy utility, and standard tools like curl. The attackers also employed DLL sideloading techniques for initial payload execution.
Analysis of the Medusa leak site identified four U.S. healthcare and nonprofit victims since November 2025, including a mental health nonprofit and an educational facility for autistic children. Average ransom demands during this period were $260,000. The U.S. Justice Department previously indicted Rim Jong Hyok, an alleged Stonefly member linked to RGB, for ransomware attacks against U.S. hospitals. The indictment revealed that ransomware proceeds fund DPRK espionage operations against defense, technology, and government sectors in the U.S., Taiwan, and South Korea.
Another Lazarus-adjacent group, Moonstone Sleet, was separately identified using Qilin ransomware against South Korean financial firms, indicating a broader strategic shift among DPRK cyber actors toward established RaaS platforms rather than custom-developed ransomware. This pragmatic approach reduces development overhead while leveraging battle-tested encryption and extortion infrastructure.
The Symantec report included extensive file-based IOCs covering Medusa ransomware, Comebacker backdoor variants, loaders, SSH loaders, DLL sideloading components, RP_Proxy instances, Mimikatz, ChromeStealer, and numerous suspicious files. Network indicators included four C2 IP addresses in the 23.27.x.x range and eight attacker-controlled domains used for command-and-control communications.
MITRE ATT&CK techniques used in TL-2026-0172
credential-access
T1003 OS Credential Dumping; T1555 Credentials from Password Stores
discovery
T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery
lateral-movement
defense-evasion
T1036 Masquerading; T1078 Valid Accounts
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1053 Scheduled Task/Job; T1059.001 PowerShell; T1569.002 Service Execution
command-and-control
T1071.001 Web Protocols; T1090 Proxy; T1105 Ingress Tool Transfer
initial-access
T1190 Exploit Public-Facing Application
impact
T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery
persistence
T1547.001 Registry Run Keys / Startup Folder; T1574.001 DLL
collection
resource-development
Timeline of Lazarus Group (Stonefly) Medusa Ransomware
- Lazarus/Andariel begins deploying custom Maui ransomware against healthcare targets.
- Medusa RaaS platform launched by Spearwing cybercrime group.
- Stonefly collaboration with Play ransomware group reported by Unit 42.
- FBI/CISA publish joint advisory AA25-071A warning about Medusa ransomware.
- DOJ indicts Rim Jong Hyok for ransomware attacks on U.S. hospitals. $10M reward.
- Medusa leak site lists U.S. healthcare/nonprofit victims. Avg ransom $260K.
- Lazarus deploys Medusa against Middle Eastern org. Comebacker confirms attribution.
- Symantec/Carbon Black publishes findings on Lazarus adoption of Medusa RaaS.
- As of 2026-05-29, this threat remains ACTIVE: Symantec/Carbon Black confirmed Lazarus (Stonefly) deploying Medusa RaaS against US healthcare/nonprofits, with 366 claimed Medusa victims and attacks ongoing since Nov 2025. No takedown reported; indictments and a $10M reward have not deterred continued DPRK operations.
Sources cited for Lazarus Group (Stonefly) Medusa Ransomware
- Symantec/Carbon Black — North Korean Lazarus Group Now Working With Medusa Ransomware
- The Register — North Korea's Lazarus Group Targets Healthcare Orgs with Medusa Ransomware
- The Hacker News — Lazarus Group Uses Medusa Ransomware
- BleepingComputer — North Korean Lazarus Group Linked to Medusa Ransomware
- Dark Reading — Lazarus Group New Position: Medusa Ransomware
- Infosecurity Magazine — North Korean Lazarus Group Expands Ransomware Activity
- Industrial Cyber — Lazarus Hackers Adopt Medusa Ransomware
- HIPAA Journal — North Korean Hackers Medusa Ransomware Healthcare
- FBI/CISA — StopRansomware: Medusa Advisory AA25-071A
- U.S. DOJ — Rim Jong Hyok Indictment
- Bank Info Security — North Korean Hackers Target US Healthcare
Threats related to Lazarus Group (Stonefly) Medusa Ransomware
Detection coverage for TL-2026-0172
As of 2026-03-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0172 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.