The Zollo (.zollo6, .zollo10, .zollo15) Variant of MedusaLocker Decryption and Recovery
In our recovery lab today at Lockbit Decryptor, we isolated the Zollo ransomware strain, a confirmed variant of the MedusaLocker family. This variant appends the .zollo6 extension (with a variable number) and employs a double-extortion model, threatening to leak stolen data. Our forensic analysis indicates that despite their claims of strong RSA+AES encryption, the underlying…









