ForensicsS | Private Detective & Digital Forensics Investigation Experts
  • info@forensicss.com

    Send Email

  • 11400 West Olympic Blvd, Los Angeles, CA 90064

  • Home
  • About Us
  • Services
    • Domestic Investigation
      • Los Angeles Private Eye
      • Catch Cheater
      • Infidelity Investigations
      • Asset Investigations
      • Private Detective Orange County
      • Child Custody Investigations
      • Missing Person Locates
      • Wire Fraud
      • Corporate Security Investigations
      • Surveillance Operations
      • Financial Fraud Investigations
      • Bug Sweep TSCM Investigation
      • Workers Compensation Fraud Investigation
      • Asset and Hidden Finances Investigations
    • Cyber Security
      • DIGITAL EVIDENCE AUTHENTICATION
      • Cyber Bullying Online Investigation
      • Penetration Testing Service
      • Social Media Monitoring
      • Romance Scam Investigator
      • Cyber Stalking Investigation
      • Crypto Scam Investigation
      • Cyber Security Assessment
      • Cyber Harassment Online Investigator
      • Ransomware Attack Investigation
      • Social Media Investigator
      • Extortion Investigation services
      • Background Screening
      • Insurance Fraud Detective
      • Forensic Accounting
      • Online Identity Theft
      • Online Blackmail
      • Cell Phone Forensics
      • Automotive Forensics
      • Audio Video Forensics
      • E-Discovery
      • Assets Search 
      • Computer and Cell Phone Forensics
  • Closed Cases
    • Closed Cases
    • Case Details
  • News
  • Contact
310-270-0598

Confidentiality Guaranteed

310-270-0598

Confidentiality Guaranteed

Logo

Contact Info

  • 11400 West Olympic Blvd, Los Angeles, CA 90064
  • 310-270-0598
  • info@forensicss.com

    Blog Details

      ForensicsS | Private Detective & Digital Forensics Investigation Experts > News > Uncategorized > North Korean Lazarus team linked to Medusa ransomware assaults
    North Korean Lazarus team linked to Medusa ransomware assaults
    24
    Feb
    • ForensicsS
    • 0 Comments

    North Korean Lazarus team linked to Medusa ransomware assaults

    Private eye

    private eye North Korean Lazarus group linked to Medusa ransomware attacks

    North Korean instruct-backed hackers connected to the Lazarus threat team are targeting U.S. healthcare organizations in extortion assaults utilizing the Medusa ransomware.

    The Medusa ransomware-as-a-service (RaaS) operation emerged in January 2021, and by February 2025, it impacted over 300 organizations in assorted major infrastructure sectors. Since then, the team claimed at the least one other 80 victims.

    North Korean threat actors come by beforehand been linked to other ransomware lines equivalent to HolyGhost, PLAY, Maui, Qilin, as neatly as other malware households. On the opposite hand, here’s the foremost time safety researchers come by associated the actor with Medusa.

    private eye Wiz

    In a portray nowadays, enterprise cybersecurity firm Symantec says that a Lazarus subgroup, presumably Andariel/Stonefly, is now utilizing Medusa in financially-motivated cyberattacks targeting U.S. healthcare suppliers.

    In response to the researchers, the toolset weak in these assaults furthermore reveals some association with Diamond Sleet, one other North Korean team that typically targets media, defense, and IT industries.

    On the opposite hand, some of the utilities viewed in the Medusa ransomware assaults are commodity tools:

    • Comebacker – Diamond Sleet-linked backdoor/loader (viewed weak by Diamond Sleet)
    • Blindingcan – Some distance away receive loyal of entry to trojan
    • ChromeStealer – Chrome credential extractor
    • Infohook – Knowledge stealer
    • Mimikatz – Credential dumping tool
    • RP_Proxy – Custom proxy tool
    • Curl – Data switch tool

    The researchers commentary that no sectors are off-limits for North Korean hackers, who withhold becoming concerned with cybercrime for monetary derive.

    “Whereas some cybercrime outfits claim to lead chase of targeting healthcare organizations attributable to the reputational hurt it’ll blueprint, Lazaurs doesn’t seem to be in any formula constrained,” Symantec researchers explain.

    Medusa focused multiple healthcare and non-profit organizations in the U.S., because the team’s data leak residing lists four such victims for the explanation that starting of November 2025, among them an academic facility for autistic formative years.

    Now no longer all these Medusa assaults might per chance also be confidently attributed to Lazarus hackers, even supposing. Medusa can place a matter to ransoms as big as $15 million, however Symantec researchers explain that the frequent is around $260,000.

    Stolen funds are weak to present a lift to espionage operations towards entities in the defense, expertise, and authorities sectors in the U.S., Taiwan, and South Korea.

    Symantec has equipped a suite of indicators of compromise (IoCs) in its portray, which embody network infrastructure data and hashes for the malware weak in assaults.


    private eye tines

    Private eye The style forward for IT infrastructure is here

    Well-liked IT infrastructure strikes quicker than handbook workflows can tackle.

    In this unusual Tines book, learn the formula your crew can decrease hidden handbook delays, give a lift to reliability through computerized response, and blueprint and scale vivid workflows on high of tools you already exercise.

    Be taught More

    • Tags

    • cybercrime email-fraud forensics|digital-forensics Investigation Korean malware North online-scam private-detective scam|fraud private-eye cyber|cybersecurity private-eye phishing|phishing-attack private-investigator private-investigator hacking|hacker

    Recent Posts

    • ACMA presents green light to in-play making a bet machine
    • Thomas Massie Calls Out DOJ for No ‘Fees, Arrests or Investigations’ Over Epstein Files
    • “Aspects to that you just will be in a function to mediate of quilt-up”: DOJ withheld Trump-linked documents in Epstein recordsdata
    • Dems Recount DOJ ‘Illegally’ Buried Epstein Recordsdata Connected to Allegation In opposition to Trump
    • Oversight Dem Says DOJ ‘Looks to Hold Illegally Withheld FBI Interviews’ Round Trump Accusation

    Recent Comments

    No comments to show.

    Categories

    • cybersecurity
    • Investigations
    • Uncategorized

    Recent Posts

    ACMA presents green light to in-play making a bet machine
    February 25, 2026
    ACMA presents green light to in-play making a bet machine
    Thomas Massie Calls Out DOJ for No ‘Fees, Arrests or Investigations’ Over Epstein Files
    February 24, 2026
    Thomas Massie Calls Out DOJ for No ‘Fees, Arrests or Investigations’ Over Epstein Files
    “Aspects to that you just will be in a function to mediate of quilt-up”: DOJ withheld Trump-linked documents in Epstein recordsdata
    February 24, 2026
    “Aspects to that you just will be in a function to mediate of quilt-up”: DOJ withheld Trump-linked documents in Epstein recordsdata

    Popular Tags

    administration calls Crypto Cyber cybercrime cybercrimefraud cybercrimehacker cybercrimephishing-attack cybersecurity Department digital-forensics email-fraud Epstein FBI’s Files forensics|digital-forensics Former fraud hacker hackers Investigation investigationcybersecurity Justice Korean Launches malware malwarefraud malwarephishing-attack Microsoft Minnesota North online-scam online-scamphishing-attack Patel phishing-attack Police private-detective scam|fraud private-eye cyber|cybersecurity private-eye phishing|phishing-attack private-investigator private-investigator hacking|hacker probe Trump Trump’s warns

    Forensics – Trusted Experts in Surveillance, Cyber Security, Background Checks, and Digital Forensics across California.

    • 310-270-0598
    • info@forensicss.com
    • 11400 West Olympic Blvd, Los Angeles, CA 90064

    Explore

    • News
    • About
    • Our Services
    • Find A Person
    • Child Custody
    • Contact Us
    • Los Angeles
    • Orange County
    • San Diego

    Services

    • Cyber Security
    • Online Blackmail
    • Cell Phone Forensics
    • Domestic Investigation
    • Social Media Investigator
    • Crypto Scam Investigation

    Newsletter

    Sign up email to get our daily latest news & updates from us

    © Copyright 2021 by KRIGO