Storyline

Lazarus group targets healthcare with medusa ransomware

The Lazarus Group has begun using Medusa ransomware to target healthcare organizations in the US and the Middle East. This marks a new phase in their cyber operations, which also involve other malicious tools.

Current brief openSource links open
This current storyline is open here with summary, metadata, source links, continuity context, and full evidence. Paid is for compare-over-time, alerts, exports, and workflow.
No card needed for the free brief.
Evidence trail (top sources)
top sources (4 domains)domains are deduped. counts indicate coverage, not truth.
4 top sources shown
Lazarus Group Picks a New Poison: Medusa Ransomware
Dark Reading · News · darkreading.com · 2026-02-24 21:18 UTC
Overview

The Lazarus Group has begun using Medusa ransomware to target healthcare organizations in the US and the Middle East. This marks a new phase in their cyber operations, which also involve other malicious tools.

Score total
1.71
Momentum 24h
4
Posts
4
Origins
4
Source types
2
Duplicate ratio
0%
Why now
  • The rise in ransomware attacks on healthcare coincides with increased cyber vulnerabilities during the pandemic.
  • Lazarus Group's shift to Medusa ransomware reflects evolving strategies in cybercrime.
  • Timely awareness of these threats is crucial for enhancing cybersecurity measures in healthcare.
Why it matters
  • Healthcare organizations are critical infrastructure and vulnerable to cyberattacks.
  • The use of ransomware can lead to significant data breaches and operational disruptions.
  • Lazarus Group's tactics indicate a growing sophistication in cyber threats.
Continuity snapshot
  • Trend status: insufficient_history.
  • Continuity stage: broad_confirmed.
  • Current status: open.
  • 4 current source-linked posts are attached to this storyline.
All evidence
All evidence
Show filters & breakdown
Posts loaded: 0Publishers: 4Origin domains: -Duplicates: -
Showing 4 / 0
Top publishers (this list)
  • go.theregister.com (1)
  • scworld.com (1)
  • darkreading.com (1)
  • blueteamsec (1)
Top origin domains (this list)
  • Unknown (4)