Back to News
Ransomware
March 12, 20261 min read211

North Korean Lazarus Group Hackers Linked to Medusa Ransomware Attacks

Security researchers link the Lazarus Group to Medusa Ransomware attacks specifically targeting healthcare providers in the United States.

By Titan Layer Editorial Team

Published on March 12, 2026

Source: —

Detailed forensic analysis connected the Lazarus Group — North Korea's most well-known cyber arm — to Medusa Ransomware attacks against hospitals and healthcare providers in the United States. Medusa is a ransomware-as-a-service operating since 2023 using double extortion: encrypting systems AND threatening to publish stolen data. Researchers identified significant infrastructure overlap with previous Lazarus campaigns. Healthcare is a strategic target: critical systems that can't go offline, extremely sensitive data, historically smaller security budgets, and legacy systems. For North Korea, ransomware is a significant revenue source for weapons programs — the FBI estimates Lazarus collected over $3 billion in cryptocurrencies in recent years.

Article information

Editorial author:Titan Layer Editorial Team
Original source:
Original publisher:
Original author:
Original publication date:
Reference link:
Titan Layer publication date:March 12, 2026
Content type:Curated summary and editorial analysis
#lazarus#coreia do norte#ransomware#medusa#saúde

Share this article

Related Articles

Cyber Crime

Police Dismantle VPN Service Used in Ransomware Attacks

Titan Layer
3d ago
Infrastructure Security

Hackers Bypass SonicWall VPN MFA Due to Incomplete Patching

Titan Layer
4d ago
Cyber Crime

7-Eleven Data Breach Confirmed After ShinyHunters Ransom Demand

Titan Layer
5/18/2026