Symantec reported that North Korean state-backed operators linked to Lazarus (including a subgroup often tracked as Andariel/Stonefly) have been observed using Medusa ransomware in financially motivated extortion activity, including an attack on a target in the Middle East and an attempted/unsuccessful intrusion against a U.S. healthcare organization. The activity marks a shift from Lazarus’ previously observed ransomware usage (e.g., Maui and Play) toward leveraging a ransomware-as-a-service (RaaS) ecosystem; Medusa is assessed as a RaaS operated by the Spearwing cybercrime group, with hundreds of claimed victims and recent leak-site activity impacting U.S. healthcare and nonprofit organizations.
Reporting highlighted tooling associated with the Lazarus-linked activity, mixing commodity and North Korea-linked components, including Comebacker (Diamond Sleet-linked), Blindingcan (RAT), credential theft/dumping utilities (e.g., ChromeStealer, Mimikatz), and network/proxy tooling (e.g., curl, RP_Proxy). Separate items in the set covered unrelated ransomware and threat activity: Everest ransomware’s claimed theft of patient data via a third-party supplier affecting Vikor Scientific/Vanta Diagnostics, a disruptive ransomware incident at the University of Mississippi Medical Center, and broader commentary on ransomware geopolitics and sector targeting; these do not provide additional corroboration on the Lazarus–Medusa linkage itself.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Alongside its report, Symantec published indicators of compromise, malware hashes, network infrastructure details, and behavior-based detections related to the Lazarus-linked Medusa activity. The company also said its security products had been updated to detect and block the observed techniques.
On February 24, 2026, Symantec and the Carbon Black Threat Hunter Team published research assessing that North Korean Lazarus operators were using Medusa ransomware in financially motivated attacks. The report said this was the first time researchers had associated Lazarus with Medusa and noted attribution to a specific Lazarus subgroup remained uncertain.
The same reporting described an unsuccessful attempted intrusion against a U.S. healthcare organization in which Lazarus-linked actors tried to use Medusa ransomware for extortion. The case reinforced continued North Korean targeting of the U.S. healthcare sector.
Symantec and Carbon Black observed Lazarus-linked operators successfully deploy Medusa ransomware against an unnamed organization in the Middle East. The intrusion involved Lazarus-associated tooling such as Comebacker, Blindingcan, ChromeStealer, Mimikatz, Infohook, and RP_Proxy.
Since early November 2025, Medusa's leak site has listed at least four U.S. healthcare and nonprofit victims, including a mental health nonprofit and a school serving autistic children. Researchers cautioned that not all of these cases can be definitively attributed to Lazarus operators.
In July 2025, the U.S. Department of Justice unsealed charges against North Korean national Rim Jong Hyok for alleged involvement in ransomware attacks, including against U.S. healthcare entities. The action was accompanied by public allegations tying him to the Lazarus subgroup Stonefly/Andariel and a $10 million reward.
Palo Alto Networks Unit 42 reported in 2024 that a Lazarus subgroup associated with Andariel/Stonefly collaborated with the Play ransomware group. This was cited as prior evidence of North Korean actors working with established ransomware ecosystems.
Symantec said North Korean operators carried out financially motivated intrusions against three U.S. organizations in 2024, but ransomware was not deployed in those incidents. The activity was cited as part of Lazarus/Stonefly's broader shift toward revenue-generating operations.
Medusa began operating as a ransomware-as-a-service offering run by the Spearwing cybercrime group. Multiple sources describe it as emerging in 2023 and later being used by affiliates against hundreds of victims.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
hipaajournal.com
Open sourcesecurityaffairs.com
Open sourcehackread.com
Open sourceinfosecurity-magazine.com
Open sourcego.theregister.com
Open sourcedarkreading.com
Open sourcesecurity.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.