Lazarus Group (Stonefly) Medusa Ransomware — DPRK State-Backed Actors Deploy Medusa RaaS Targeting U.S. Healthcare — Threadlinqs Intelligence
As of 2026-05-30, Lazarus Group (Stonefly) Medusa Ransomware — DPRK State-Backed Actors Deploy Medusa RaaS Targeting U.S. Healthcare is a critical-severity ransomware threat attributed to Lazarus Group (North Korea), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 19 indicators of compromise.
Threat ID: TL-2026-0172 · Severity: CRITICAL · CVSS: 9 · Status: ACTIVE · Category: RANSOMWARE
Attribution: Lazarus Group · North Korea · FINANCIAL
North Korean state-sponsored Lazarus Group, specifically the Stonefly/Andariel subgroup, has adopted Medusa ransomware-as-a-service for extortion campaigns targeting U.S. healthcare organizations,
Symantec and Carbon Black Threat Hunter Team published findings on February 24, 2026 documenting North Korean state-sponsored actors deploying Medusa ransomware in targeted extortion campaigns. The investigation revealed Lazarus Group operators successfully attacked an unnamed organization in the Middle East and mounted an unsuccessful attempt against a U.S. healthcare organization.
Medusa is a ransomware-as-a-service (RaaS) platform operated by the Spearwing cybercrime group since 2023. Affiliates deploy Medusa variants in exchange for a percentage of ransom payments. More than 366 attacks have been claimed by Medusa affiliates across its operational history, targeting critical sectors including healthcare, education, legal, insurance, technology, and manufacturing. A joint FBI/CISA advisory in March 2025 specifically warned about Medusa's impact on critical infrastructure.
The Lazarus Group is an umbrella designation for North Korean state-sponsored cyber operations. The Stonefly subgroup (also tracked as Andariel, Onyx Sleet, and Silent Chollima) operates under North Korea's Reconnaissance General Bureau (RGB) military intelligence. Stonefly has a documented history of ransomware use — previously deploying Maui ransomware against healthcare targets and collaborating with the Play ransomware group in October 2024.
Attribution to Lazarus was confirmed through the presence of the Comebacker backdoor, a custom malware family exclusively associated with Lazarus Group. Additional tooling included Blindingcan (AIRDRY/ZetaNile) RAT, ChromeStealer for browser credential theft, InfoHook information stealer, Mimikatz for credential dumping, RP_Proxy custom proxy utility, and standard tools like curl. The attackers also employed DLL sideloading techniques for initial payload execution.
Analysis of the Medusa leak site identified four U.S. healthcare and nonprofit victims since November 2025, including a mental health nonprofit and an educational facility for autistic children. Average ransom demands during this period were $260,000. The U.S. Justice Department previously indicted Rim Jong Hyok, an alleged Stonefly member linked to RGB, for ransomware attacks against U.S. hospitals. The indictment revealed that ransomware proceeds fund DPRK espionage operations against defense, technology, and government sectors in the U.S., Taiwan, and South Korea.
Another Lazarus-adjacent group, Moonstone Sleet, was separately identified using Qilin ransomware against South Korean financial firms, indicating a broader strategic shift among DPRK cyber actors toward established RaaS platforms rather than custom-developed ransomware. This pragmatic approach reduces development overhead while leveraging battle-tested encryption and extortion infrastructure.
The Symantec report included extensive file-based IOCs covering Medusa ransomware, Comebacker backdoor variants, loaders, SSH loaders, DLL sideloading components, RP_Proxy instances, Mimikatz, ChromeStealer, and numerous suspicious files. Network indicators included four C2 IP addresses in the 23.27.x.x range and eight attacker-controlled domains used for command-and-control communications.
Target sectors: healthcare, nonprofit, education, defense, technology, government, manufacturing
Target regions: United States, Middle East, South Korea, Taiwan
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 19 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, CRITICAL, threat intelligence, cybersecurity, T1583.001, T1190, T1078, T1059.001, T1569.002, T1547.001, T1053, T1574.002, T1036, T1090