Lazarus Group (Stonefly) Medusa Ransomware — DPRK State-Backed Actors Deploy Medusa RaaS Targeting U.S. Healthcare

Lazarus Group (Stonefly) Medusa Ransomware (TL-2026-0172), also tracked as Medusa RaaS, is a critical-severity ransomware operation scored CVSS 9, first published 2026-03-03. It is attributed to Lazarus Group (North Korea) with high confidence, maps to 24 MITRE ATT&CK techniques (T1003, T1016, T1021), and is covered by 9 detection rules and 19 indicators of compromise.

Key facts for TL-2026-0172

Threat ID
TL-2026-0172
Also known as
Medusa RaaS, Spearwing
Severity
CRITICAL
CVSS
9
Status
ACTIVE
Category
RANSOMWARE
First published
2026-03-03
Last reviewed
2026-03-03
Attribution
Lazarus Group
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
healthcare, nonprofit, education, defense, technology, government, manufacturing
Target regions
United States, Middle East, South Korea, Taiwan
Detection rules
9
Indicators of compromise
19

Malware and tooling in Lazarus Group (Stonefly) Medusa Ransomware

Malware and tooling: MEDUSA - S1220, Mimikatz

North Korean state-sponsored Lazarus Group, specifically the Stonefly/Andariel subgroup, has adopted Medusa ransomware-as-a-service for extortion campaigns targeting U.S. healthcare organizations, nonprofits, and Middle Eastern entities. Symantec and Carbon Black confirmed Lazarus involvement through exclusive tools including the Comebacker backdoor.

How Lazarus Group (Stonefly) Medusa Ransomware works

Symantec and Carbon Black Threat Hunter Team published findings on February 24, 2026 documenting North Korean state-sponsored actors deploying Medusa ransomware in targeted extortion campaigns. The investigation revealed Lazarus Group operators successfully attacked an unnamed organization in the Middle East and mounted an unsuccessful attempt against a U.S. healthcare organization.

Medusa is a ransomware-as-a-service (RaaS) platform operated by the Spearwing cybercrime group since 2023. Affiliates deploy Medusa variants in exchange for a percentage of ransom payments. More than 366 attacks have been claimed by Medusa affiliates across its operational history, targeting critical sectors including healthcare, education, legal, insurance, technology, and manufacturing. A joint FBI/CISA advisory in March 2025 specifically warned about Medusa's impact on critical infrastructure.

The Lazarus Group is an umbrella designation for North Korean state-sponsored cyber operations. The Stonefly subgroup (also tracked as Andariel, Onyx Sleet, and Silent Chollima) operates under North Korea's Reconnaissance General Bureau (RGB) military intelligence. Stonefly has a documented history of ransomware use — previously deploying Maui ransomware against healthcare targets and collaborating with the Play ransomware group in October 2024.

Attribution to Lazarus was confirmed through the presence of the Comebacker backdoor, a custom malware family exclusively associated with Lazarus Group. Additional tooling included Blindingcan (AIRDRY/ZetaNile) RAT, ChromeStealer for browser credential theft, InfoHook information stealer, Mimikatz for credential dumping, RP_Proxy custom proxy utility, and standard tools like curl. The attackers also employed DLL sideloading techniques for initial payload execution.

Analysis of the Medusa leak site identified four U.S. healthcare and nonprofit victims since November 2025, including a mental health nonprofit and an educational facility for autistic children. Average ransom demands during this period were $260,000. The U.S. Justice Department previously indicted Rim Jong Hyok, an alleged Stonefly member linked to RGB, for ransomware attacks against U.S. hospitals. The indictment revealed that ransomware proceeds fund DPRK espionage operations against defense, technology, and government sectors in the U.S., Taiwan, and South Korea.

Another Lazarus-adjacent group, Moonstone Sleet, was separately identified using Qilin ransomware against South Korean financial firms, indicating a broader strategic shift among DPRK cyber actors toward established RaaS platforms rather than custom-developed ransomware. This pragmatic approach reduces development overhead while leveraging battle-tested encryption and extortion infrastructure.

The Symantec report included extensive file-based IOCs covering Medusa ransomware, Comebacker backdoor variants, loaders, SSH loaders, DLL sideloading components, RP_Proxy instances, Mimikatz, ChromeStealer, and numerous suspicious files. Network indicators included four C2 IP addresses in the 23.27.x.x range and eight attacker-controlled domains used for command-and-control communications.

MITRE ATT&CK techniques used in TL-2026-0172

credential-access

T1003 OS Credential Dumping; T1555 Credentials from Password Stores

discovery

T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery

lateral-movement

T1021 Remote Services

defense-evasion

T1036 Masquerading; T1078 Valid Accounts

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1053 Scheduled Task/Job; T1059.001 PowerShell; T1569.002 Service Execution

command-and-control

T1071.001 Web Protocols; T1090 Proxy; T1105 Ingress Tool Transfer

initial-access

T1190 Exploit Public-Facing Application

impact

T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery

persistence

T1547.001 Registry Run Keys / Startup Folder; T1574.001 DLL

collection

T1560 Archive Collected Data

resource-development

T1583.001 Domains

Timeline of Lazarus Group (Stonefly) Medusa Ransomware

  • Lazarus/Andariel begins deploying custom Maui ransomware against healthcare targets.
  • Medusa RaaS platform launched by Spearwing cybercrime group.
  • Stonefly collaboration with Play ransomware group reported by Unit 42.
  • FBI/CISA publish joint advisory AA25-071A warning about Medusa ransomware.
  • DOJ indicts Rim Jong Hyok for ransomware attacks on U.S. hospitals. $10M reward.
  • Medusa leak site lists U.S. healthcare/nonprofit victims. Avg ransom $260K.
  • Lazarus deploys Medusa against Middle Eastern org. Comebacker confirms attribution.
  • Symantec/Carbon Black publishes findings on Lazarus adoption of Medusa RaaS.
  • As of 2026-05-29, this threat remains ACTIVE: Symantec/Carbon Black confirmed Lazarus (Stonefly) deploying Medusa RaaS against US healthcare/nonprofits, with 366 claimed Medusa victims and attacks ongoing since Nov 2025. No takedown reported; indictments and a $10M reward have not deterred continued DPRK operations.

Sources cited for Lazarus Group (Stonefly) Medusa Ransomware

Threats related to Lazarus Group (Stonefly) Medusa Ransomware

Detection coverage for TL-2026-0172

As of 2026-03-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0172 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats