2026-06-06 is live. RBL, certificate, and uptime monitoring — now in public beta.

News

Lazarus Group Deploys Medusa Ransomware in Attacks on Middle East Target and U.S. Healthcare


Broadcom’s Symantec and Carbon Black Threat Hunter Team has attributed the use of Medusa ransomware to the North Korea-linked Lazarus Group-tracked by some analysts as Diamond Sleet and Pompilus-after observing an intrusion against an unnamed organization in the Middle East.

The same Broadcom threat intelligence unit also reported that the group attempted, but failed, to carry out a ransomware assault against a healthcare provider in the United States.

Medusa is a ransomware-as-a-service (RaaS) platform that was put into operation by a cybercrime ring called Spearwing in 2023. According to public claims tied to the service, more than 366 incidents have been posted on the group’s leak site so far.

Analysis of entries on the Medusa data leak portal indicates that since the start of November 2025 there have been at least four incidents involving U.S. healthcare and non-profit organizations, the report states. Identified victims during that window include a mental health non-profit and a school for children on the autism spectrum. It remains unclear whether North Korean operators were responsible for every listed victim or if other Medusa affiliates carried out some of those attacks. During that period, the typical ransom demand averaged about $260,000.

Using ransomware is not new for DPRK-linked crews. Back in 2021, a Lazarus subgroup known as Andariel (also tracked as Stonefly) deployed bespoke ransomware families-including SHATTEREDGLASS, Maui, and H0lyGh0st-against targets in South Korea, Japan and the U.S. In October 2024 the group was also connected to an attack using the Play ransomware, marking a shift toward commercially available ransomware builders.

This move away from in-house cryptors is not unique to Andariel. Last year Bitdefender reported that another North Korean-associated actor, Moonstone Sleet, which had previously used a custom family called FakePenny, likely targeted several South Korean financial institutions with Qilin ransomware-again favoring an off-the-shelf tool.

Broadcom’s investigators say these patterns may reflect a broader operational change among DPRK hacking cadres: instead of writing bespoke ransomware, they appear to be acting as affiliates for established RaaS operations, outsourcing the encryption component to third-party services.

According to the report, the Lazarus-linked Medusa campaign has employed a mix of tools and malware, including a bespoke proxy utility called RP_Proxy; Mimikatz for credential dumping; a custom backdoor dubbed Comebacker that the group appears to use exclusively; an information-stealing component called InfoHook that has been observed operating alongside Comebacker; the remote access trojan BLINDINGCAN (also referenced as AIRDRY or ZetaNile); and a Chrome password-extraction utility known as ChromeStealer.

Investigators have not definitively tied this recent activity to any single Lazarus sub-group, even though the extortion techniques resemble prior Andariel operations.

Broadcom’s advisory emphasizes that the adoption of Medusa underscores North Korea’s ongoing and unabated involvement in financially motivated cybercrime, noting that its operators show little restraint when targeting organizations in the United States. While some criminal groups publicly claim they avoid hitting healthcare providers because of the negative publicity it can generate, Lazarus does not appear to observe such limits.

First published on February 25, 2026.
Last updated on April 24, 2026.