The MedusaLocker (“.bear”) Variants: A Definitive Forensic Recovery Guide
In our recovery lab today at Lockbit Decryptor, we isolated multiple ransomware strains from the MedusaLocker family, collectively identified by the .bearXX extension pattern (where XX varies, e.g., .bear10, .bear20, .bear26, .bear35, .bear50, .bear60). These variants represent ongoing development cycles within the same criminal operation. Despite minor differences, they all employ a robust RSA-2048 and…


