GPcode, also known as PGPCoder, is an early Windows ransomware family that helped define modern cryptoviral extortion. First observed in the mid-2000s, it encrypts victim files and demands payment in exchange for a decryptor or decryption key. Early variants used flawed or weaker implementations, but later versions were reported with substantially improved cryptography, including correctly implemented RSA-1024 in some campaigns, making practical brute-force recovery infeasible and shifting defender focus toward implementation flaws, backups, and file recovery.
GPcode targets Windows systems and encrypts files matching hard-coded extension lists that commonly include documents, archives, media, certificates, and databases. Some analyzed variants enumerate logical drives, recursively traverse directories, encrypt selected files through Windows CryptoAPI functions, and rename affected files with a new extension. Variants have also dropped ransom notes onto the desktop, changed the victim’s wallpaper, and removed themselves after execution through cleanup scripts. Reports indicate some versions deleted original files after creating encrypted copies, while others simply encrypted and renamed files.
Distribution has been associated with phishing emails, malicious links, and, in earlier reporting, e-mail and USENET postings. GPcode has been described as a Trojan-delivered ransomware threat rather than a self-propagating worm. Campaigns used multiple extortion workflows over time, including email-based negotiation, proof-of-decryption offers for a single file, and payment requests through then-popular digital payment systems or prepaid-card mechanisms. Reporting has linked some GPcode activity to Russian-speaking operators, although infrastructure and communications observed in certain cases suggested operational complexity beyond a single simple attribution.
GPcode is historically significant because it marked a transition from crude locker-style extortion toward file-encrypting ransomware using stronger public-key cryptography. Its evolution demonstrated that once ransomware operators adopted sound asymmetric encryption, victim recovery without backups, implementation mistakes, or attacker cooperation became far more difficult.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
In the first call, GpCode will load, and lock a resource... ResourceName = "cfg" ... In this call it will decrypt the data contained at 00175158
It creates a file called "ntfs_system.bat" ... del "C:\Documents and Settings\Administrateur\Bureau\1.exe" del %0
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware spread through malicious links and phishing emails that encrypted files on Windows systems using a custom algorithm.
Early ransomware family cited as a milestone in the evolution toward modern ransomware.
Mentioned only in a sidebar link title.
Ransomware that extorts victims for payment to restore access, in this case previously directing victims to pay via pre-paid credit card.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.