p13x13t: What the Term Actually Means and Where It Came From

Admin
12 Min Read

p13x13t is not a recognised technology, AI framework, encryption standard, or documented “13×13” digital system. The strongest traceable evidence connects the string to the online identity surrounding the Apophis Squad cybercrime group in 2018, including a ransomware note that explicitly displayed the credit “Maker: P13x13t.”

The spelling also provides an important clue. In common leetspeak, 1 can replace the letter “l” and 3 can replace “e.” Read that way, p13x13t becomes “plexlet.” That is strikingly close to “Pl3xl3t,” an alias independently documented by cybersecurity journalist Brian Krebs as one of the online names associated with George Duke-Cohan, a member of Apophis Squad.

That does not prove every appearance of p13x13t belongs to the same person, nor does the available official court material explicitly define the exact string. But it gives the term a much firmer historical context than recent web pages that present it as an abstract grid, creative identifier, AI concept, or emerging technical framework.

What is p13x13t?

The most defensible description is:

p13x13t is a stylised alphanumeric handle or maker signature associated with the online ecosystem around Apophis Squad, rather than the name of an established technology.

One concrete example appears in documentation of Apophis ransomware, a malicious program reported in 2018. Security write-ups reproduce its ransom message, which identified the attackers as Apophis Squad and included the line “Maker: P13x13t.” The malware appended a .fun extension to affected files and demanded payment in Bitcoin.

This matters because several newer articles approach the keyword in the opposite direction: they begin with its unusual appearance and then speculate about what it could represent. One 2026 article, for example, describes p13x13t as a conceptual 13×13 pattern framework for workflows, digital art and modular systems. Another describes it simply as a flexible creative keyword without a fixed meaning. Neither supplies primary technical documentation establishing such a system.

A hypothetical use is not the same thing as a documented origin.

The spelling is probably leetspeak, not “13 by 13”

The middle of p13x13t can easily be mistaken for the mathematical expression 13 × 13, which equals 169. That visual coincidence has encouraged explanations involving 13×13 grids, matrices, modules or pattern systems.

There is a simpler interpretation.

Leetspeak is an internet writing convention in which letters are deliberately replaced with numbers or other characters. Cambridge Dictionary defines it as a form of online writing where normal letters are replaced by numbers or different characters, while teaching material from the University of Washington gives common substitutions including l → 1 and e → 3.

Applying those substitutions:

p13x13t

becomes:

p l e x l e t

or “plexlet.”

That interpretation becomes more significant when compared with the alias Pl3xl3t:

P l 3 x l 3 t

which also resolves to “Plexlet.”

KrebsOnSecurity reported in February 2019 that George Duke-Cohan was known by several handles, including “opt1cz,” “7R1D3n7,” and “Pl3xl3t.”

This does not justify stating categorically that p13x13t and Pl3xl3t were always interchangeable. Usernames can be copied, varied and reused. It does, however, provide a plausible explanation for the otherwise unusual sequence of characters without inventing an undocumented 13×13 technology.

Where Apophis Squad fits into the story

Apophis Squad was not merely a name attached to malware. Court and government records connect the group to serious cyberattacks and hoax threats during 2018.

The U.S. Department of Justice described Apophis Squad in February 2019 as a worldwide collective of hackers and “swatters” accused of using threatening calls, false reports of school attacks and distributed denial-of-service attacks to cause disruption. Federal prosecutors charged Timothy Dalton Vaughn and George Duke-Cohan in connection with the group’s activities.

The DOJ said the alleged conspiracy covered the first eight months of 2018 and involved threats against schools, website defacement, spoofed email addresses and DDoS attacks. Its press release identified Duke-Cohan as using handles including “DigitalCrimes” and “7R1D3N7.”

Separately, official sentencing remarks from the Crown Court at Luton establish Duke-Cohan’s direct connection to Apophis Squad. He pleaded guilty to three offences involving false bomb information. The court recorded that his phone activity included use of Twitter under the “Apophis Squad” name, that later threatening emails came from an Apophis Squad email address, and that investigators found him using the aliases “geor,” “Trident” and “Plexit” in a Discord discussion.

The same judgment states that more than 1,700 schools and educational establishments received threatening emails during one March 2018 campaign. Duke-Cohan was later responsible for a false hijacking report involving United Airlines Flight 949 from London to San Francisco, which had 295 passengers and 16 crew members.

He was sentenced on 7 December 2018 after pleading guilty to the UK bomb-hoax offences. Contemporary reporting recorded a three-year prison sentence.

What the evidence does — and does not — establish

Claim about p13x13tEvidence
It appeared as a maker name in ransomwareDirectly supported. Apophis ransomware documentation reproduces “Maker: P13x13t.”
It resembles a leetspeak usernameStrongly supported. Standard substitutions convert it to “plexlet.”
It is related to the alias Pl3xl3tPlausible and strongly suggestive. Pl3xl3t is independently associated with George Duke-Cohan, and both strings resolve to the same letters.
It is an official 13×13 frameworkNo authoritative documentation located. Recent pages proposing this interpretation provide descriptions rather than an identifiable standard, developer or specification.
It is an AI, blockchain or encryption platformNo reliable evidence located. Pages making broad technological associations acknowledge that no official definition exists.
Its exact intended meaning has been publicly explained by its creatorNot established by the sources examined.

Why search results give such different answers

p13x13t is almost perfectly shaped for web speculation. It looks technical, contains repeated numbers, has no obvious dictionary definition and has relatively little authoritative documentation indexed under the exact spelling.

That creates an information gap.

A recent ArticleWorld page says the term has no fixed meaning but proposes possible uses as a username, project name, game label or creative concept. Another article goes further and treats “13×13” as an organising principle involving 169 cells or modules.

Those ideas are possible applications of an arbitrary string, but possibility is weak evidence of meaning. Almost any sequence of characters could theoretically become a project name, database identifier, game seed or artistic concept.

The historical material works differently. It provides an observable use of the exact string: “Maker: P13x13t” in material attributed to Apophis ransomware. It also places highly similar spellings such as Pl3xl3t and Plexit within the documented alias history surrounding Apophis Squad.

That evidence should carry more weight than interpretations constructed years later from the appearance of the keyword itself.

Is p13x13t a virus?

Not by itself.

p13x13t is a string of text. Searching for it, reading it or typing it does not execute malware.

The cybersecurity connection comes from the fact that the name appeared as a maker attribution inside an Apophis ransomware message. Calling the keyword itself a virus would therefore be inaccurate.

A different question is whether someone should download a program advertised today under that name. Because there is no established legitimate software platform or recognised technical product corresponding to the keyword in the sources examined, an unfamiliar executable, browser extension or script using the name should be judged on its actual developer, code-signing information, distribution source and security reputation—not on speculative articles describing p13x13t as a new technology.

Is there really a p13x13t 13×13 grid?

There is no reliable evidence that the historical term was created to describe a grid containing 13 rows and 13 columns.

The interpretation seems to arise from reading the substring 13x13 literally as “13 × 13.” A 2026 guide builds an entire conceptual framework around that reading, describing a structure of 169 cells, repeating cycles and modular checks. Yet the page itself says p13x13t is not a standardised protocol or software product.

The leetspeak reading is better supported by context because 1 → l and 3 → e transforms the word into the same underlying spelling as the independently documented handle Pl3xl3t.

Until an original source demonstrates otherwise, a 13×13-grid definition should be presented as a later interpretation, not as the established meaning of p13x13t.

The clearest answer

The available evidence points away from the idea that p13x13t is a mysterious new technology.

Its clearest documented appearance is as “P13x13t,” a maker name shown in an Apophis ransomware message. Its spelling can be read through ordinary leetspeak substitutions as “Plexlet,” closely matching Pl3xl3t, one of the online names independently connected with George Duke-Cohan and the Apophis Squad ecosystem. Official UK court records separately establish Duke-Cohan’s use of the similar alias Plexit and his involvement with Apophis Squad.

What cannot responsibly be claimed is that p13x13t has an officially defined technological meaning, represents a recognised 13×13 architecture, or functions as an established AI, blockchain or encryption platform.

That distinction explains much of the confusion surrounding the keyword: its historical use is comparatively concrete, while many of its modern “definitions” are speculative.

Sources

  • U.S. Department of Justice — “Members of Hacker Collective Face Federal Charges for Attacking Computer Systems, Emailing Mass Hoax Bomb and Shooting Threats,” 12 February 2019. U.S. Department of Justice source
  • Judiciary of England and Wales — “R v George Duke-Cohan: Sentencing Remarks of HHJ Richard Foster,” 7 December 2018. Official sentencing remarks PDF
  • KrebsOnSecurity — “Bomb Threat Hoaxer Exposed by Hacked Gaming Site,” 14 February 2019. KrebsOnSecurity article
  • The Guardian — “Teenager jailed for school and airport bomb hoaxes,” 7 December 2018. The Guardian report
  • EnigmaSoftware — “Apophis Ransomware Removal Report.” The page reproduces the ransomware message containing “Maker: P13x13t”; no clear publication date was displayed on the page examined. EnigmaSoftware Apophis ransomware report
  • Cambridge Dictionary — “leet.” Definition of leet/leetspeak as deliberate replacement of ordinary letters with numbers or other characters. Cambridge Dictionary definition
Share This Article
Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *