Lazarus Group Caught Running Medusa Ransomware: XOR-Decoded Config Exposes Tor C2, IME-Based Loader, and a 7-Month Intrusion Timeline

2026-03-12 Break Glass Intelligence

https://intel.breakglass.tech/post/lazarus-group-caught-running-medusa-ransomware-xor-decoded-config-exposes-tor-c2-ime-based-loader-and-a-7-month-intrusion-timeline

Thumbnail for Lazarus Group Caught Running Medusa Ransomware: XOR-Decoded Config Exposes Tor C2, IME-Based Loader, and a 7-Month Intrusion Timeline

Two samples submitted by the same Hungarian incident responder are presented as linking Lazarus Group to Medusa ransomware activity: gaze.exe, a Medusa encryptor, and TSMSISrv.dll, a Lazarus-detected DLL sideloading loader. The ransomware's XOR-decoded configuration contains four Tor .onion addresses, a victim-specific negotiation endpoint, a Tox chat ID, an RSA public key, shadow-copy deletion commands, and service kill lists targeting security, backup, and database tooling. The loader masquerades as a Windows 8 IME SDK component, runs through the SessionEnv service as SYSTEM, uses COM hijacking for persistence, and includes TLS callbacks plus custom AES tables for anti-analysis and encrypted communications. A seven-month gap between the March 2025 loader build and October 2025 ransomware build supports a patient access-then-extortion chain, with the PDB path suggesting Medusa builder output rather than in-house ransomware development.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 82a8292007e682f1a127ba8dcebfae96 2026-03-12 2026-03-17
HASH 655221b6bcad7b5b0b9766142cbc257a 2026-03-12 2026-03-17
HASH 60aaafce354ae5e0b8115729464a8b24 2026-03-12 2026-03-17
HASH 28978e987bc59e75ca22562924eab93… 2026-03-12 2026-03-17
HASH 00b4f860f1798b62b3531f1b4e8bb6e0 2026-03-12 2026-03-17
HASH 447557d5236f1b97be0314b317ca9fff 2026-03-12 2026-03-17
HASH 3be2401da21dfed104c9aa52bb620344 2026-03-12 2026-03-17
HASH aea72dfcf492037a6d15755a74645c7d 2026-03-12 2026-03-17
HASH c8040dd3ff2f4afd042efd4ebe1a43c6 2026-03-12 2026-03-17
HASH aeebcd8c8b15645d7e71b68ac05e21e… 2026-03-12 2026-03-17
HASH 53948d9596ebab5c4cf2ac04e7fb70c… 2026-03-12 2026-03-17
URL http://uyku4o2yg34ekvjtszg6gu7c… 2026-03-12 2026-03-17
URL http://7aqabivkwmpvjkyefonf3gpy… 2026-03-12 2026-03-17
URL http://xfv4jzckytb4g3ckwemcny3i… 2026-03-12 2026-03-17
URL http://s7lmmhlt3iwnwirxvgjidl6o… 2026-03-12 2026-03-17
URL https://utox.org/uTox_win64.exe 2026-03-12 2026-03-17
DOMAIN xfv4jzckytb4g3ckwemcny3ihv4i5p4… 2026-03-12 2026-03-17
DOMAIN uyku4o2yg34ekvjtszg6gu7cvjzm6hy… 2026-03-12 2026-03-17
DOMAIN utox.org 2026-03-12 2026-03-17
DOMAIN s7lmmhlt3iwnwirxvgjidl6omcblvw2… 2026-03-12 2026-03-17
DOMAIN 7aqabivkwmpvjkyefonf3gpy5gsubop… 2026-03-12 2026-03-17
HASH 15208030eda48b3786f7d85d756d2bd… 2026-02-24 2026-03-17
YARA Lazarus_Medusa_Campaign_Config 2026-03-12 2026-03-12
YARA Lazarus_TSMSISrv_IME_Loader 2026-03-12 2026-03-12
YARA Lazarus_Medusa_Gaze_Ransomware 2026-03-12 2026-03-12

Related Actors

Related Reports

« Back