North Korea’s Lazarus Turns to RaaS, Uses Medusa Ransomware to Target U.S. Healthcare Sector
North Korean state-backed hacking group Lazarus has long raised funds by stealing crypto assets and financial intelligence. It is now also adopting ransomware-as-a-service, or RaaS, renting off-the-shelf tools such as Medusa to reduce malware development costs and targeting highly sensitive U.S. healthcare organizations for extortion.
The latest cybersecurity research indicates that Lazarus has used Medusa to attack the U.S. healthcare sector and targets in the Middle East, expanding its operations from outright theft to financial extortion. As of July 20, 2026, researchers had not disclosed the victims’ names, the exact dates of the attacks, ransom demands or actual losses.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.