Mark RadarMARK RADAR
EN
Event File FINTECH Financial Cybersecurity

North Korea’s Lazarus Turns to RaaS, Uses Medusa Ransomware to Target U.S. Healthcare Sector

1 reports · First detected 2026-02-25 · Last active 2026-02-25

North Korean state-backed hacking group Lazarus has long raised funds by stealing crypto assets and financial intelligence. It is now also adopting ransomware-as-a-service, or RaaS, renting off-the-shelf tools such as Medusa to reduce malware development costs and targeting highly sensitive U.S. healthcare organizations for extortion.

The latest cybersecurity research indicates that Lazarus has used Medusa to attack the U.S. healthcare sector and targets in the Middle East, expanding its operations from outright theft to financial extortion. As of July 20, 2026, researchers had not disclosed the victims’ names, the exact dates of the attacks, ransom demands or actual losses.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)