State-backed hackers from North Korea, linked to the notorious Lazarus, are reportedly behind a new wave of ransomware attacks against healthcare organizations in the U.S. According to a recent report from Symantec, the attacks are leveraging Medusa ransomware, heightening concerns about the growing convergence of state espionage operations and purely financially motivated cybercrime.

The use of Medusa marks a new phase for North Korean threat actors, who have previously been linked to ransomware families such as HolyGhost, PLAY, Maui, and Qilin. However, this is the first time researchers have directly linked this state-owned infrastructure to Medusa.
The rise of Medusa as a RaaS platform
The Medusa operation has been operating as a ransomware-as-a-service (RaaS) since January 2021. By February 2025, it had affected more than 300 organizations on critical infrastructure, with at least 80 new victims added since then. The RaaS model allows different “partners” to leverage the same malware infrastructure, paying a percentage of the ransom to the platform administrators.
See also: UAE repels AI terrorist cyberattacks on critical infrastructure
In practice, this means a lower technical barrier to entry for attackers and a greater scale of attacks. Ransom amounts can reach up to $15 million, although according to Symantec the average is around $260,000. While not all Medusa attacks are attributed to Lazarus, the involvement of state-linked actors dramatically changes the threat landscape.
Subgroups and Connections: Andariel and Diamond Sleet
The Symantec report suggests that a possible Lazarus subgroup known as Andariel or Stonefly is behind the recent attacks. The toolkit used bears similarities to activities of the Diamond Sleet group, another North Korean entity that traditionally targets the media, defense, and IT industries.

This intersection of techniques and tools suggests either shared infrastructure or knowledge sharing between state groups. The phenomenon is not new, but the adoption of commercially available tools alongside custom malware makes attribution significantly more difficult.
See also: The rise of agile hackers in 2025
The arsenal of attacks
The Medusa attacks attributed to the North Koreans include a combination of custom and commercial tools. These include backdoors and loaders such as Comebacker, trojans remote access such as Blindingcan, credential stealers such as ChromeStealer , and tools such as Mimikatz to extract credentials from system memory.
At the same time, proxy tools, data transfer utilities such as Curl, and custom infrastructures are used to hide traffic. This multi-layered approach allows attackers to infiltrate, move laterally through networks, and ultimately encrypt critical systems, increasing the pressure on victims.
Health in the spotlight – without "red lines"
Unlike some criminal groups, which claim to avoid the healthcare sector for “ethical” or reputational reasons, Lazarus does not appear to place such restrictions. The Medusa data leak website lists several healthcare organizations and non-profits as recent victims, including an educational facility for children with autism.
Attacks on hospitals and healthcare providers have particularly serious consequences: disruption of services, delays in medical procedures, and potential risk to human life. The pressure to restore operations immediately makes these organizations more likely to pay ransoms.
See also: Operation Olalampo: MuddyWater targets organizations with new malware

Financing espionage through cybercrime
The stolen funds are not limited to bolstering criminal networks. According to the researchers, they are being used to finance espionage operations against defense, technology, and government targets in the US, Taiwan, and South Korea. In this way, ransomware acts as a mechanism to raise funds for state strategic pursuits.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Symantec has released indicators of compromise (IoCs), including malware hashes and network infrastructure elements, to help organizations strengthen their defenses. The message is clear: no domain is off-limits, and the line between cyberwarfare and cybercrime is becoming increasingly blurred.
Source: www.bleepingcomputer.com
