INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

North Korea's Lazarus Group targets healthcare orgs with Medusa ransomware

| 2026-02-24 18:25 CRITICAL LOW
Executive Summary AI-generated
North Korea's Lazarus Group has begun using Medusa ransomware in extortion attacks targeting at least one US healthcare organization and an unnamed victim in the Middle East, according to Symantec and Carbon Black threat hunters. The group's use of this malware is a significant escalation from previous attempts, which failed to hit any targets. This latest development marks another chapter in North Korea's ongoing cybercrime spree, with many victims operating in critical sectors such as healthcare, education, and technology.
Technical Mitigations AI-generated
* Implement regular security updates and patches for all systems, including operating systems, applications, and software to ensure that known vulnerabilities are addressed. * Use a secure file system and encryption methods to protect sensitive data both at rest and in transit. * Conduct regular network traffic analysis and monitoring to detect potential suspicious activity or anomalies. * Educate users on phishing attacks, social engineering tactics, and other types of cyber threats to prevent them from falling victim to these types of attacks. * Use a reputable antivirus solution that can detect and remove malware, including ransomware like Medusa.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Moonstone SleetMoonstone SleetAndarielAndarielLazarus GroupLazarus Group Medusa RansomwareMedusa RansomwareQilinQilinWannaCryWannaCryBLINDINGCANBLINDINGCANCarbonCarbon
Target & Sectors
DPRK DPRK MIDDLE_EAST MIDDLE_EAST NORTH_AMERICA NORTH_AMERICA technologytechnology defensedefense healthhealth legallegal manufacturingmanufacturing healthcarehealthcare educationeducation
Incident Timeline
July 2024
North Korea's Lazarus Group used Medusa ransomware to target healthcare organizations.
industry Healthcare
tactic Ransomware
target_region DPRK
source_region United States
threat_actor Andariel
industry Defense
organisation the US Justice Department
organisation NASA
target_region China
organisation Comebacker
October 2024
North Korea's Lazarus Group used Medusa ransomware to target healthcare organizations.
tactic Ransomware
2025-02-24
North Korea's Lazarus Group used Qilin ransomware to target several South Korean healthcare organizations on February 24, 2025.
tactic Ransomware
source_region DPRK
target_region Korea, Republic of
threat_actor Moonstone Sleet
organisation FakePenny
malware Qilin
March 2025
North Korea's Lazarus Group used Medusa ransomware to target healthcare organizations, including those in critical sectors such as medical and education.
source_region United States
industry Education
industry Legal
industry Technology
industry Manufacturing
attribution FBI
threat_actor Andariel
organisation Sony Pictures
organisation Maui
threat_actor Lazarus Group
organisation the Treasury Department
November 2025
North Korean operatives used Medusa ransomware to target four healthcare and nonprofit organizations in the US.
industry Healthcare
target_region United States
industry Health
victims 30 victim organizations
organisation The Hacker News
organisation Spearwing
organisation Affiliates
financial $260,000 period
Feb 24, 2026
Threat actors used Lazarus Group's Medusa ransomware to target major healthcare organizations in the United States.
2026-02-24
North Korea's Lazarus Group targets healthcare orgs with Medusa ransomware.
threat_actor Lazarus Group
organisation U.S. Healthcare Attacks
organisation Lazaurs
organisation North Korean
threat_actor Andariel
organisation Comebacker
organisation ChromeStealer
financial $260,000 period
Tactical Metrics
Metrics
victims
30
Victim Organizations
Metrics
financial
260,000
Period