North Korea-linked Lazarus Group (aka Diamond Sleet) has been reported using Medusa ransomware in at least one intrusion targeting an unnamed organization in the Middle East, with an additional, reportedly unsuccessful attempt against a U.S. healthcare organization. The activity was attributed by Broadcom’s Symantec/Carbon Black threat research, which noted Medusa is a ransomware-as-a-service (RaaS) operation launched in 2023 by a cybercrime group known as Spearwing; analysis of Medusa’s leak site also indicates numerous recent U.S. healthcare/non-profit victims, though it is unclear which were directly targeted by North Korean operators versus other Medusa affiliates. The reporting frames this as part of a broader trend of North Korean operators shifting from bespoke ransomware to leveraging “off-the-shelf” ransomware ecosystems.
Separately, Lazarus was also linked to a social-engineering operation targeting the CEO of security firm AllSecure via a fake LinkedIn recruiting workflow that led to a staged “technical interview.” The lure attempted to convince the target to download and open a code project in VS Code, which AllSecure’s analysis said contained multiple infection paths and delivered BeaverTail malware; the victim avoided compromise by refusing to run the files on their primary system and instead detonating them in an isolated environment. While both reports attribute activity to Lazarus, they describe distinct operations (ransomware deployment vs. recruiter/interview malware delivery) rather than a single unified incident.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Public reporting linked the social-engineering and malware activity to North Korea's Lazarus Group based on tooling, code patterns, and infrastructure associated with prior North Korean operations. This attribution was published as details of the attempted compromise became public.
After identifying that the malware was running in a professional data center environment rather than a home machine, the operators allegedly activated a kill switch to delete their progress. The campaign's apparent goal was theft of credentials and secrets including crypto wallets, browser passwords, SSH keys, and environment variables.
As part of the fake interview, the target was pressured to open a code folder in VS Code, but instead examined it in an isolated virtual machine. Analysis reportedly found three infection paths and BeaverTail malware that executed on folder open, fingerprinted the host, and beaconed to a command server every five seconds.
Chris Papathanasiou, CEO of AllSecure, was approached on LinkedIn by an attacker posing as a recruiter and drawn into a fake job interview process. During a video call, the supposed hiring manager briefly appeared using a face matching a real LinkedIn profile, suggesting possible identity theft or real-time deepfake use.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.