Therecord.Media
North Korean Lazarus Group Targets US Healthcare with Medusa Ransomware
First seen 24 Feb 2026, 12:10 UTC
•



+15
•48.7
Export
Article Content
Browse articles
Cybersecurity researchers have identified attacks utilizing Medusa ransomware, attributed to the Lazarus group, a North Korean state-backed hacking operation. These attacks are primarily targeting U.S. healthcare organizations, with the ransomware-as-a-service operation impacting over 300 organizations since its emergence in January 2021, and claiming at least 80 additional victims by February 2025.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2021-01-01
Medusa ransomware-as-a-service operation emerged
2025-02-01
Medusa ransomware impacted over 300 organizations
2025-02-01
Lazarus group claimed at least 80 additional victims
2026-02-24
Current attacks on US healthcare organizations reported
More articles in this cluster
Continue Reading
Storm-1175 Deploys New StormEncryptor Ransomware Targeting N-central Systems
Fire Ant Threat Actor Targets Trusted Infrastructure in 2026
Coordinated Cyberattack Disrupts Water Utilities in Minnesota
Perseus Android Malware Targets User Notes for Sensitive Data Theft
Chronus Group Breach Exposes 36 Million Mexican Citizens' Data
The Gentlemen Ransomware Group Expands Operations with New Tools