EDA2 is an open-source ransomware project written for educational purposes that became widely repurposed by criminal operators and spawned multiple real-world ransomware variants, including Magic and later heavily modified strains such as Surprise. It is associated with Windows environments and has been observed both as a directly deployed ransomware payload and as code reused inside custom loaders and derivative families.
Operationally, EDA2-derived ransomware encrypts victim files and coordinates key material with a remote command-and-control service. Reported variants transmit host information to obtain or construct encryption material, generate symmetric keys for file encryption, and return protected key data to attacker-controlled infrastructure. Observed descendants have scanned local fixed disks for targeted files, appended custom extensions to encrypted content, dropped ransom notes, and deleted Shadow Volume Copies to hinder recovery. Some samples have also been executed directly from memory by a preceding loader to reduce static detection opportunities.
EDA2 has been delivered through multiple intrusion paths depending on the actor and campaign. Document-based exploitation using CVE-2012-0158 has been used to deliver EDA2 ransomware in phishing campaigns, including lures themed around urgent events. Other EDA2-based incidents involved abuse of remote-access software through compromised or reused credentials, with attackers manually transferring and launching payloads. The project’s public availability on GitHub contributed to its adoption by less sophisticated threat actors and to the proliferation of offshoots targeting enterprises, healthcare organizations, research institutions, and individual users.
EDA2 is notable less as a single stable criminal family than as a foundational ransomware codebase whose publication materially lowered the barrier to entry for ransomware development. Its history is frequently cited alongside Hidden Tear as an example of educational or openly released ransomware code being operationalized in real attacks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"...attempted to deliver EDA2 ransomware by exploiting a known buffer overflow vulnerability (CVE-2012-0158) in Microsoft's ListView / TreeView ActiveX controls in MSCOMCTL.OCX library."
3 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
EDA2 is referenced as ransomware source code or a ransomware family variant lineage used as the basis for Magic Ransomware.
Ransomware delivered via coronavirus-themed phishing lures; contacts a C2 server, downloads an image used as the ransom note/notification, transmits host details to generate a custom encryption key, encrypts files (noted with a ".locked20" extension), and sends the (AES-encrypted) decryption key to the C2 via HTTP POST.
An open-source ransomware project mentioned as an example of prior GitHub misuse.
An open-source ransomware family/framework referenced here as the underlying codebase heavily modified and executed in memory by Surprise.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.