Back to News
Ransomware
March 12, 20261 min read211

North Korean Lazarus Group Hackers Linked to Medusa Ransomware Attacks

Security researchers link the Lazarus Group to Medusa Ransomware attacks specifically targeting healthcare providers in the United States.

By Titan Layer Editorial Team

Published on March 12, 2026

Source: —

Detailed forensic analysis connected the Lazarus Group — North Korea's most well-known cyber arm — to Medusa Ransomware attacks against hospitals and healthcare providers in the United States. Medusa is a ransomware-as-a-service operating since 2023 using double extortion: encrypting systems AND threatening to publish stolen data. Researchers identified significant infrastructure overlap with previous Lazarus campaigns. Healthcare is a strategic target: critical systems that can't go offline, extremely sensitive data, historically smaller security budgets, and legacy systems. For North Korea, ransomware is a significant revenue source for weapons programs — the FBI estimates Lazarus collected over $3 billion in cryptocurrencies in recent years.

Article information

Editorial author:Titan Layer Editorial Team
Original source:
Original publisher:
Original author:
Original publication date:
Reference link:
Titan Layer publication date:March 12, 2026
Content type:Curated summary and editorial analysis
#lazarus#coreia do norte#ransomware#medusa#saúde

Share this article

Related Articles

Cyber Crime

Two Security Experts Sentenced for Aiding Ransomware Gang

Titan Layer
3d ago
Supply Chain Attacks

North Korean Actors Deploy Malicious NPM Packages to Steal Git Repositories

Titan Layer
3/14/2026