When Nation-States Become Ransomware Affiliates: Lazarus Group Deploys Medusa via a Custom IME-Based Loader

2026-03-17 Break Glass Intelligence

https://intel.breakglass.tech/post/when-nation-states-become-ransomware-affiliates-lazarus-group-deploys-medusa-via-a-custom-ime-based-loader

Thumbnail for When Nation-States Become Ransomware Affiliates: Lazarus Group Deploys Medusa via a Custom IME-Based Loader

Breakglass analyzed two samples from a Hungarian incident as evidence that Lazarus Group operated as a Medusa ransomware-as-a-service affiliate rather than only deploying DPRK-built ransomware. The TSMSISrv.dll loader is attributed to Lazarus-linked tradecraft through detections and TTP matches, using Windows 8 IME SDK camouflage, SessionEnv DLL sideloading, COM hijacking persistence, dual TLS anti-analysis callbacks, and a custom AES implementation. The separate gaze.exe ransomware binary carries Medusa builder indicators, including a G:\Medusa\Release\gaze.pdb path, VS2019 x86 build characteristics, XOR-encoded configuration, Tor negotiation infrastructure, service-kill routines, and RSA/AES file encryption. Compilation timestamps place the loader in March 2025 and the ransomware in October 2025, supporting a patient intrusion followed by later extortion deployment. The finding matters because it suggests DPRK operators may bring their own access and persistence tooling into third-party ransomware ecosystems, complicating attribution and incident response.

Indicators of Compromise

Type Value First Seen Last Seen
YARA Lazarus_Medusa_Campaign_XOR_Con… 2026-03-17 2026-03-17
YARA Lazarus_TSMSISrv_IME_Loader 2026-03-17 2026-03-17
YARA Lazarus_Medusa_Gaze_Ransomware 2026-03-17 2026-03-17
HASH 82a8292007e682f1a127ba8dcebfae96 2026-03-12 2026-03-17
HASH 655221b6bcad7b5b0b9766142cbc257a 2026-03-12 2026-03-17
HASH 60aaafce354ae5e0b8115729464a8b24 2026-03-12 2026-03-17
HASH 28978e987bc59e75ca22562924eab93… 2026-03-12 2026-03-17
HASH 00b4f860f1798b62b3531f1b4e8bb6e0 2026-03-12 2026-03-17
HASH 447557d5236f1b97be0314b317ca9fff 2026-03-12 2026-03-17
HASH 3be2401da21dfed104c9aa52bb620344 2026-03-12 2026-03-17
HASH aea72dfcf492037a6d15755a74645c7d 2026-03-12 2026-03-17
HASH c8040dd3ff2f4afd042efd4ebe1a43c6 2026-03-12 2026-03-17
HASH aeebcd8c8b15645d7e71b68ac05e21e… 2026-03-12 2026-03-17
HASH 53948d9596ebab5c4cf2ac04e7fb70c… 2026-03-12 2026-03-17
URL http://uyku4o2yg34ekvjtszg6gu7c… 2026-03-12 2026-03-17
URL http://7aqabivkwmpvjkyefonf3gpy… 2026-03-12 2026-03-17
URL http://xfv4jzckytb4g3ckwemcny3i… 2026-03-12 2026-03-17
URL http://s7lmmhlt3iwnwirxvgjidl6o… 2026-03-12 2026-03-17
URL https://utox.org/uTox_win64.exe 2026-03-12 2026-03-17
DOMAIN xfv4jzckytb4g3ckwemcny3ihv4i5p4… 2026-03-12 2026-03-17
DOMAIN uyku4o2yg34ekvjtszg6gu7cvjzm6hy… 2026-03-12 2026-03-17
DOMAIN utox.org 2026-03-12 2026-03-17
DOMAIN s7lmmhlt3iwnwirxvgjidl6omcblvw2… 2026-03-12 2026-03-17
DOMAIN 7aqabivkwmpvjkyefonf3gpy5gsubop… 2026-03-12 2026-03-17
HASH 15208030eda48b3786f7d85d756d2bd… 2026-02-24 2026-03-17

Related Actors

Related Reports

« Back