Lazarus turns to Medusa ransomware against Middle East and US healthcare
The North Korea-linked Lazarus Group has been observed using Medusa ransomware in attacks against an unnamed organisation in the Middle East and in an attempted intrusion at a US healthcare provider. Symantec and the Carbon Black Threat Hunter Team describe this as a shift from custom-built malware towards ransomware-as-a-service, likely to save time and resources. The group deployed a range of tools for credential theft, backdoor access and data exfiltration, consistent with the financially motivated activity that has characterised its operations.
What this means for your organisation
When state-linked groups use the same ransomware kits as criminals, the distinction between espionage and profit-driven crime becomes less useful to the defender. The attacker may be more patient and better trained than the average criminal, but the tooling and the sequence look alike. The consequence is the same either way: downtime, encrypted systems and stolen data. Healthcare and other critical operations are particularly exposed because downtime there has direct consequences for people.
Berigo recommends
- Verify that backups are immutable and separated, and that restoring an entire critical system has been tested in practice.
- Limit administrator rights and introduce tiered access so credential theft does not hand over the whole environment.
- Keep an incident plan that also covers stolen data and extortion, not just encryption and recovery.
- Rehearse the incident with the leadership team, including the decision on how you handle a ransom demand.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch