ForensicsS | Private Detective & Digital Forensics Investigation Experts
  • info@forensicss.com

    Send Email

  • 11400 West Olympic Blvd, Los Angeles, CA 90064

  • Home
  • About Us
  • Services
    • Domestic Investigation
      • Los Angeles Private Eye
      • Catch Cheater
      • Infidelity Investigations
      • Asset Investigations
      • Private Detective Orange County
      • Child Custody Investigations
      • Missing Person Locates
      • Wire Fraud
      • Corporate Security Investigations
      • Surveillance Operations
      • Financial Fraud Investigations
      • Bug Sweep TSCM Investigation
      • Workers Compensation Fraud Investigation
      • Asset and Hidden Finances Investigations
    • Cyber Security
      • DIGITAL EVIDENCE AUTHENTICATION
      • Cyber Bullying Online Investigation
      • Penetration Testing Service
      • Social Media Monitoring
      • Romance Scam Investigator
      • Cyber Stalking Investigation
      • Crypto Scam Investigation
      • Cyber Security Assessment
      • Cyber Harassment Online Investigator
      • Ransomware Attack Investigation
      • Social Media Investigator
      • Extortion Investigation services
      • Background Screening
      • Insurance Fraud Detective
      • Forensic Accounting
      • Online Identity Theft
      • Online Blackmail
      • Cell Phone Forensics
      • Automotive Forensics
      • Audio Video Forensics
      • E-Discovery
      • Assets Search 
      • Computer and Cell Phone Forensics
  • Closed Cases
    • Closed Cases
    • Case Details
  • News
  • Contact
310-270-0598

Confidentiality Guaranteed

310-270-0598

Confidentiality Guaranteed

Logo

Contact Info

  • 11400 West Olympic Blvd, Los Angeles, CA 90064
  • 310-270-0598
  • info@forensicss.com

    Blog Details

      ForensicsS | Private Detective & Digital Forensics Investigation Experts > News > Uncategorized > North Korean Lazarus team linked to Medusa ransomware assaults
    North Korean Lazarus team linked to Medusa ransomware assaults
    24
    Feb
    • ForensicsS
    • 0 Comments

    North Korean Lazarus team linked to Medusa ransomware assaults

    Private eye

    private eye North Korean Lazarus group linked to Medusa ransomware attacks

    North Korean instruct-backed hackers connected to the Lazarus threat team are targeting U.S. healthcare organizations in extortion assaults utilizing the Medusa ransomware.

    The Medusa ransomware-as-a-service (RaaS) operation emerged in January 2021, and by February 2025, it impacted over 300 organizations in assorted major infrastructure sectors. Since then, the team claimed at the least one other 80 victims.

    North Korean threat actors come by beforehand been linked to other ransomware lines equivalent to HolyGhost, PLAY, Maui, Qilin, as neatly as other malware households. On the opposite hand, here’s the foremost time safety researchers come by associated the actor with Medusa.

    private eye Wiz

    In a portray nowadays, enterprise cybersecurity firm Symantec says that a Lazarus subgroup, presumably Andariel/Stonefly, is now utilizing Medusa in financially-motivated cyberattacks targeting U.S. healthcare suppliers.

    In response to the researchers, the toolset weak in these assaults furthermore reveals some association with Diamond Sleet, one other North Korean team that typically targets media, defense, and IT industries.

    On the opposite hand, some of the utilities viewed in the Medusa ransomware assaults are commodity tools:

    • Comebacker – Diamond Sleet-linked backdoor/loader (viewed weak by Diamond Sleet)
    • Blindingcan – Some distance away receive loyal of entry to trojan
    • ChromeStealer – Chrome credential extractor
    • Infohook – Knowledge stealer
    • Mimikatz – Credential dumping tool
    • RP_Proxy – Custom proxy tool
    • Curl – Data switch tool

    The researchers commentary that no sectors are off-limits for North Korean hackers, who withhold becoming concerned with cybercrime for monetary derive.

    “Whereas some cybercrime outfits claim to lead chase of targeting healthcare organizations attributable to the reputational hurt it’ll blueprint, Lazaurs doesn’t seem to be in any formula constrained,” Symantec researchers explain.

    Medusa focused multiple healthcare and non-profit organizations in the U.S., because the team’s data leak residing lists four such victims for the explanation that starting of November 2025, among them an academic facility for autistic formative years.

    Now no longer all these Medusa assaults might per chance also be confidently attributed to Lazarus hackers, even supposing. Medusa can place a matter to ransoms as big as $15 million, however Symantec researchers explain that the frequent is around $260,000.

    Stolen funds are weak to present a lift to espionage operations towards entities in the defense, expertise, and authorities sectors in the U.S., Taiwan, and South Korea.

    Symantec has equipped a suite of indicators of compromise (IoCs) in its portray, which embody network infrastructure data and hashes for the malware weak in assaults.


    private eye tines

    Private eye The style forward for IT infrastructure is here

    Well-liked IT infrastructure strikes quicker than handbook workflows can tackle.

    In this unusual Tines book, learn the formula your crew can decrease hidden handbook delays, give a lift to reliability through computerized response, and blueprint and scale vivid workflows on high of tools you already exercise.

    Be taught More

    • Tags

    • cybercrime email-fraud forensics|digital-forensics Investigation Korean malware North online-scam private-detective scam|fraud private-eye cyber|cybersecurity private-eye phishing|phishing-attack private-investigator private-investigator hacking|hacker

    Recent Posts

    • Swalwell staffers stand with accusers as Ny DA confirms investigation – The Washington Post
    • Hackers meet their match: New DNA encryption protects engineered cells from within
    • DOJ launches antitrust probe into NFL over TV offers
    • GTA 6 Dev Confirms Yet one more Data Breach, Hackers Inquire Ransom
    • GTA 6 Dev Rockstar Confirms ‘A Restricted Quantity of Non-Enviornment matter Company Knowledge Used to be Accessed’ in Third-Celebration Data Breach, as Hackers Yelp of affairs Ultimatum: ‘Pay or Leak’

    Recent Comments

    No comments to show.

    Categories

    • cybersecurity
    • Investigations
    • Uncategorized

    Recent Posts

    Swalwell staffers stand with accusers as Ny DA confirms investigation – The Washington Post
    April 11, 2026
    Swalwell staffers stand with accusers as Ny DA confirms investigation – The Washington Post
    Hackers meet their match: New DNA encryption protects engineered cells from within
    April 11, 2026
    Hackers meet their match: New DNA encryption protects engineered cells from within
    DOJ launches antitrust probe into NFL over TV offers
    April 11, 2026
    DOJ launches antitrust probe into NFL over TV offers

    Popular Tags

    administration agents Crypto cybercrime cybercrimefraud cybercrimehacker cybercrimephishing-attack cybersecurity Department digital-forensics email-fraud Epstein Faces forensics|digital-forensics Former fraud hacker hackers House investigating Investigation investigationcybersecurity Judge Justice Korean Launches malware malwarefraud malwarephishing-attack Microsoft Minnesota North online-scam online-scamphishing-attack Patel phishing-attack Police private-detective scam|fraud private-eye cyber|cybersecurity private-eye phishing|phishing-attack private-investigator private-investigator hacking|hacker probe Trump warns

    Forensics – Trusted Experts in Surveillance, Cyber Security, Background Checks, and Digital Forensics across California.

    • 310-270-0598
    • info@forensicss.com
    • 11400 West Olympic Blvd, Los Angeles, CA 90064

    Explore

    • News
    • About
    • Our Services
    • Find A Person
    • Child Custody
    • Contact Us
    • Los Angeles
    • Orange County
    • San Diego

    Services

    • Cyber Security
    • Online Blackmail
    • Cell Phone Forensics
    • Domestic Investigation
    • Social Media Investigator
    • Crypto Scam Investigation

    Newsletter

    Sign up email to get our daily latest news & updates from us

    © Copyright 2021 by KRIGO