Kaspersky reported the return of GpCode-like ransomware, reviving a file-encrypting extortion model associated with one of the early ransomware families. The malware locks victim data and demands payment for recovery, signaling that older criminal techniques continue to reappear in updated campaigns rather than disappearing from the threat landscape.
The report indicates that defenders should expect renewed use of classic ransomware tradecraft built around encryption, user coercion, and operational disruption. The resurfacing of a GpCode-like strain highlights the continued risk posed by recycled malware concepts that can be adapted for modern environments, particularly where organizations lack resilient backups, endpoint protections, and rapid containment procedures.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
A Securelist blog post stated that GpCode-like ransomware had reappeared, marking the observed return of this ransomware behavior or family. No additional incident dates or discrete prior events are provided in the reference.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.