Breakglass Intelligence reported with high confidence that Lazarus Group operators deployed Medusa ransomware in a Hungarian intrusion, marking what it describes as the first concrete evidence of the DPRK-linked actor operating inside a ransomware-as-a-service affiliate ecosystem rather than using a bespoke encryptor. The case ties together a Lazarus-style loader, TSMSISrv.dll, and a Medusa ransomware payload, gaze.exe, submitted from the same incident. Researchers said the ransomware binary was built from a Medusa builder toolkit and contained an XOR-encoded configuration with Tor-based negotiation infrastructure, a victim ID, a Tox contact, an embedded RSA public key, and commands to disable security, backup, and recovery controls before encryption.
The intrusion chain showed a long dwell period, with the loader compiled in March 2025 and the ransomware compiled in October 2025, suggesting roughly seven months of persistence before extortion. The loader reportedly abused DLL sideloading through the Windows SessionEnv service, used a Windows 8 IME SDK sample as camouflage, and incorporated COM hijacking, custom AES routines, and dual TLS callback anti-analysis techniques consistent with Lazarus tradecraft. Breakglass said the combination of Lazarus-style tooling and standard Medusa infrastructure indicates the group likely acted as a Medusa affiliate for monetization, attribution camouflage, and possible sanctions evasion, underscoring how nation-state operators are converging with criminal ransomware ecosystems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On March 12, 2026, Breakglass Intelligence published analysis concluding with high confidence that Lazarus Group operators deployed Medusa ransomware as an affiliate in the Hungarian incident rather than using a bespoke ransomware family. The report described this as the first concrete evidence that Lazarus had entered the Medusa ransomware-as-a-service affiliate ecosystem.
A Medusa ransomware binary named gaze.exe was compiled in October 2025 and linked to the same Hungarian intrusion. Researchers assessed the roughly seven-month gap between the loader and ransomware builds as evidence of a long intrusion period before extortion.
A Lazarus-linked loader identified as TSMSISrv.dll was compiled in March 2025 and later tied to a Hungarian incident. Analysis says it used SessionEnv DLL sideloading, IME-themed camouflage, custom AES routines, COM hijacking, and dual TLS callback anti-analysis techniques to establish or maintain access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
intel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourcesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.