Ransomware
March 12, 20261 min read211
North Korean Lazarus Group Hackers Linked to Medusa Ransomware Attacks
Security researchers link the Lazarus Group to Medusa Ransomware attacks specifically targeting healthcare providers in the United States.
By Titan Layer Editorial Team
Published on March 12, 2026
Source: —
Detailed forensic analysis connected the Lazarus Group — North Korea's most well-known cyber arm — to Medusa Ransomware attacks against hospitals and healthcare providers in the United States.
Medusa is a ransomware-as-a-service operating since 2023 using double extortion: encrypting systems AND threatening to publish stolen data. Researchers identified significant infrastructure overlap with previous Lazarus campaigns.
Healthcare is a strategic target: critical systems that can't go offline, extremely sensitive data, historically smaller security budgets, and legacy systems. For North Korea, ransomware is a significant revenue source for weapons programs — the FBI estimates Lazarus collected over $3 billion in cryptocurrencies in recent years.
Article information
Editorial author:Titan Layer Editorial Team
Original source:—
Original publisher:—
Original author:—
Original publication date:—
Reference link:—
Titan Layer publication date:March 12, 2026
Content type:Curated summary and editorial analysis
#lazarus#coreia do norte#ransomware#medusa#saúde
Share this article
Related Articles
Cyber Crime
Two Security Experts Sentenced for Aiding Ransomware Gang
Titan Layer
3d ago
Supply Chain Attacks
North Korean Actors Deploy Malicious NPM Packages to Steal Git Repositories
Titan Layer
3/14/2026