The MedusaLocker (.friends) Ransomware: A Definitive Forensic Recovery Guide
In our recovery lab today at Lockbit Decryptor, we isolated the MedusaLocker ransomware strain, identified by the variable .friends extension (e.g., .friends24, .friends50, .friends60) and the How_to_back_files.html note. Our forensic analysis confirms this is a sophisticated, enterprise-targeting ransomware operation. This strain employs a robust hybrid cryptosystem. Critically, our analysis indicates that this variant correctly implements…
