CipherForce is a financially motivated ransomware and data-extortion operation active in 2026 and closely associated with the broader TeamPCP ecosystem. Reporting links CipherForce to TeamPCP’s transition from large-scale credential theft and software supply-chain compromise into downstream monetization through leak-site extortion and ransomware deployment. TeamPCP publicly indicated that CipherForce was a newer project intended to recruit affiliates and publish victim organizations, and multiple assessments describe CipherForce as either a TeamPCP-operated ransomware brand or a closely partnered affiliate operation. TeamPCP has also been associated with the aliases PCPcat, ShellForce, DeadCatx3, and UNC6780. CipherForce appears to have functioned as part of a broader criminal access-and-extortion pipeline. Stolen credentials harvested through compromises of developer tooling, CI/CD environments, cloud infrastructure, and software supply chains were assessed to feed ransomware and extortion activity involving CipherForce as well as other groups such as Vect. Some reporting assesses TeamPCP in part as an initial access broker that monetized harvested credentials by enabling or supporting ransomware affiliates, including CipherForce. Operationally, CipherForce has been observed using Tor-based leak infrastructure and victim shaming tactics typical of modern extortion groups. Publicly available reporting indicates a small number of listed victims in early 2026, with no broadly documented ransom notes, negotiation transcripts, or publicly confirmed intrusion-specific tradecraft unique to CipherForce itself. Available evidence instead suggests that its access and victimization pipeline was heavily dependent on TeamPCP’s upstream compromises and credential theft operations rather than on a separately well-documented intrusion set. CipherForce is notable less for independently distinctive malware tradecraft than for its role in TeamPCP’s monetization strategy. Before TeamPCP’s later partnership with Vect, CipherForce was described as TeamPCP’s proprietary ransomware operation and leak brand. In 2026, TeamPCP announced partnerships with CipherForce and Vect, signaling an expansion from credential theft and data theft into ransomware-as-a-service-style extortion. Subsequent reporting indicated that CipherForce’s leak infrastructure went offline for an extended period and that the brand may have been rebranded into a TeamPCP leak site, suggesting instability, restructuring, or absorption into the wider TeamPCP extortion apparatus. Overall, CipherForce is best understood as a ransomware and extortion brand embedded within the TeamPCP criminal ecosystem: a vehicle for monetizing stolen enterprise credentials and exfiltrated data obtained through supply-chain compromise, CI/CD intrusion, and cloud-focused credential theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware/extortion brand previously operated by TeamPCP before rebranding to a TeamPCP leak site.
Referenced as another TeamPCP-affiliated ransomware operator that had been inactive for roughly 70 days.
Named extortion/leak infrastructure referenced as part of the broader TeamPCP-affiliated monetization ecosystem. The content emphasizes that its infrastructure remained offline and no expected public dump occurred.
Named extortion/leak infrastructure associated in the reporting with TeamPCP's monetization ecosystem, noted here as offline and inactive during the period.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.