Analysis healthcareeducation
Medusa Ransomware: The 500-Victim Operation Using a CrowdStrike Lookalike to Kill EDR
Medusa is a ransomware-as-a-service operation with more than 500 confirmed victims across healthcare, education, manufacturing, and legal. Its ABYSSWORKER kernel driver — signed with stolen Chinese certificates and disguised to mimic a CrowdStrike component — disables endpoint defences before encryption. North Korea's Lazarus Group has now been confirmed deploying Medusa in targeted campaigns, blurring the line between criminal RaaS and nation-state operations.