Ransomware-as-a-Service (RaaS) Set's It's Sights on the Healthcare Industry
February 24th, 2026

❓What:
The North Korean-linked Lazarus Group (also tracked under aliases like Diamond Sleet or Andariel) has been observed deploying Medusa ransomware in extortion attacks against at least one organization in the Middle East and attempting, unsuccessfully, to breach a U.S. based healthcare entity.
Medusa, a ransomware-as-a-service (RaaS) strain operated by the cybercrime group Spearwing, has been used by affiliates in hundreds of attacks, but this is the first time Lazarus has been tied to it.
Spearwing has claimed responsibility for over 366 attacks to date.



