216.73.217.22

North Korean Lazarus Group Now Working With Medusa Ransomware

· Published 24/02/2026 12:40 · Modified 24/02/2026 20:54

Export JSON

Essential information

Published
24/02/2026 12:40
Modified
24/02/2026 20:54
Tags
2026-02-24 blindingcan chromestealer comebacker extortion healthcare infohook medusa mimikatz north korea ransomware rp_proxy stonefly
Related entities
52 observables, 1 intrusion sets (apt), 20 techniques (mitre), 13 others

Description

North Korean state-backed attackers are utilizing in their ongoing attacks against the U.S. sector. The Symantec and Carbon Black Threat Hunter Team discovered evidence of North Korean actors employing in an attack on a Middle Eastern target and an unsuccessful attempt on a U.S. organization. , launched in 2023, operates as a -as-a-service. The Lazarus sub-group has been a key player in North Korean attacks, using proceeds to fund espionage activities. Despite indictments and rewards, the attacks continue unabated. The current campaign employs various tools, including , , , and . While the attacks bear similarities to previous operations, the exact sub-group responsible remains unclear.

External references