The Lazarus Group, a North Korean state-sponsored threat actor, has been observed deploying a new ransomware variant — dubbed 'MedLock' — against healthcare organizations across the US and EU.
The campaign uses spear-phishing emails targeting medical billing staff, followed by a custom loader that evades EDR solutions before deploying the ransomware payload.
