Researchers at Symantec and Carbon Black (both under Broadcom) have linked the North Korean hacking group Lazarus — also known as Diamond Sleet or Pompilus — to attacks using Medusa ransomware. One confirmed attack hit an organization in the Middle East, and a second attempted attack on a U.S. healthcare organization was caught before it succeeded.
What is Medusa?
Medusa is a “ransomware-as-a-service” (RaaS) operation, meaning it’s a criminal platform that rents out ransomware tools to paying members. It launched in 2023 and has claimed over 366 attacks to date. Since November 2025, at least four U.S. healthcare and non-profit organizations have appeared on Medusa’s victim list — including a mental health non-profit and a school for autistic children. Average ransom demands during this period were around $260,000.
It’s worth noting that not all of these attacks were necessarily carried out by North Korean operators specifically — other Medusa affiliates may have been responsible for some.
North Korea’s History With Ransomware
This isn’t new territory for North Korea. As far back as 2021, a Lazarus sub-group called Andariel was running ransomware attacks against targets in South Korea, Japan, and the U.S., using homegrown tools like SHATTEREDGLASS, Maui, and H0lyGh0st.
The shift away from custom tools started becoming clear in October 2024, when the group was tied to attacks using Play ransomware — a well-established criminal product they didn’t build themselves. Another North Korean group, Moonstone Sleet, made a similar move, switching from their own ransomware called FakePenny to a third-party tool called Qilin.
Why the Change in Approach?
The pattern is clear: North Korean hackers are increasingly choosing to work as affiliates within existing criminal ransomware networks rather than building their own tools from scratch. The practical reasons make sense — it’s cheaper, faster, and these platforms already come with encryption tools, data leak sites, and extortion workflows built in.
Tools Used in the Medusa Campaign
The attackers used a mix of their own custom tools and widely available hacking utilities:
- RP_Proxy – a custom-built proxy tool
- Mimikatz – a well-known credential theft tool
- Comebacker – a Lazarus backdoor
- InfoHook – an info-stealing tool often paired with Comebacker
- BLINDINGCAN – a remote access trojan (also called AIRDRY or ZetaNile)
- ChromeStealer – extracts saved passwords from Google Chrome
Researchers haven’t pinned this campaign to a specific Lazarus sub-group yet, though the methods strongly resemble previous Andariel operations.
The Bigger Picture
North Korean cyber operations have long blended state-level espionage with outright financial crime, and ransomware is a key part of that revenue strategy. What stands out here is the willingness to target hospitals, mental health organizations, and schools for children with disabilities — sectors that many criminal ransomware groups claim to avoid.
This tells us that Lazarus-linked actors are largely opportunistic and revenue-driven, with little regard for who gets hurt. Their move toward commercialized criminal infrastructure makes them more scalable and harder to track — a concerning evolution for defenders across every sector.