[THREAT INTEL]HIGH

Lazarus Group Deploys New Ransomware Variant Targeting Healthcare

DPRK-linked threat actor pivots to healthcare sector with custom loader and encrypted C2 channels.

T. Nakamura· APT Analyst
7 min read

HIGH SEVERITY — Review your environment and apply mitigations as soon as possible.

The Lazarus Group, a North Korean state-sponsored threat actor, has been observed deploying a new ransomware variant — dubbed 'MedLock' — against healthcare organizations across the US and EU.

The campaign uses spear-phishing emails targeting medical billing staff, followed by a custom loader that evades EDR solutions before deploying the ransomware payload.

// RELATED THREAT INTEL

[THREAT INTEL]HIGH

APT-41 Campaign Targets Financial Sector Infrastructure

Chinese state-sponsored group APT-41 has launched a new campaign targeting SWIFT infrastructure and trading platforms.

J. Alvarez·10 min read

// NAVIGATION

JATeck Insights

Real-time threat intelligence, CVE tracking, and security research for practitioners.

// RECENT CVEs

CRITICALCVE-2026-34821
RCE in OpenSSH 9.x
HIGHCVE-2026-29104
Privilege escalation in Linux kernel
HIGHCVE-2026-27733
Auth bypass in Apache HTTP Server
MEDIUMCVE-2026-25501
XSS in popular CMS framework
LOWCVE-2026-22890
Info disclosure in Node.js runtime

// COMMUNITY

Join the network. Share intel. Stay ahead of the threat landscape.

$ subscribe --newsletter

© 2026 JATeck Insights — All rights reserved[SYSTEM ONLINE] — THREAT LEVEL: ELEVATED