CipherForce is a ransomware operation associated with the financially motivated threat group TeamPCP. It is described as TeamPCP’s proprietary ransomware track, distinct from the group’s separate partnership with the Vect ransomware ecosystem, and appears to have been used for direct extortion operations while TeamPCP simultaneously monetized access through other channels. The brand was active by early 2026, listed multiple victims on a Tor-based leak site, and was later folded into broader TeamPCP leak infrastructure. TeamPCP has also advertised CipherForce-branded tooling as capable of encrypting major enterprise database and cloud storage platforms, indicating an enterprise-focused extortion model.
Available reporting supports classifying CipherForce as ransomware rather than a general access or credential-theft tool. It has been linked to TeamPCP’s broader post-compromise monetization pipeline, in which credentials harvested during large-scale software supply-chain intrusions were allegedly sold or reused for downstream ransomware and extortion activity. TeamPCP has been associated with compromises affecting developer and CI/CD ecosystems, and some assessments indicate the group may also function in part as an initial access broker, supplying harvested credentials to ransomware operators including CipherForce affiliates.
CipherForce has been discussed alongside TeamPCP aliases including PCPcat, ShellForce, DeadCatx3, and Persy_PCP. Reporting indicates TeamPCP previously created and promoted multiple ransomware brands, including Black Witch and CipherForce, and later sought affiliates for CipherForce while maintaining a separate relationship with Vect. No high-confidence technical details about CipherForce’s internal encryption routine, propagation logic, or supported operating systems are available from the supplied facts, so platform-specific and lower-level behavioral claims remain unconfirmed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CERT-EU disclosed on April 2-3, 2026 that the European Commission's Europa web hosting platform on AWS was breached through the Trivy supply chain compromise (CVE-2026-33634). ... Entry vector: Supply chain via compromised Trivy (CVE-2026-33634) ... The CISA KEV remediation deadline for CVE-2026-33634 is now 5 days away (April 8, 2026).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CipherForce's two known Tor-based leak sites remain unavailable... If the deadline passes without publication, it may signal meaningful disruption to TeamPCP's ransomware operations.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
TeamPCP's own Telegram channel states: "you may already know us as TeamPCP or Shellforce... CipherForce is a newer project we are starting to find affiliates."
CipherForce is a newer project we are starting to find affiliates... This means TeamPCP is running two parallel ransomware tracks simultaneously: their proprietary CipherForce program for direct operations, and the mass Vect affiliate program via BreachForums for distributed operations.
the Sportradar AG breach ... has been confirmed as a "systemic compromise" jointly operated by TeamPCP and Vect ransomware.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware/locker brand previously operated by TeamPCP before its formal partnership with Vect. TeamPCP stated it used its own CipherForce locker rather than Vect encryption tools.
A ransomware or extortion channel mentioned only as an inactive affiliated monetization path during the reporting period.
Ransomware-branded tooling associated with TeamPCP, designed to encrypt major enterprise database and cloud storage solutions; described as part of TeamPCP's proprietary ransomware program.
Referenced as a named ransomware family via its leak/blog site in the context of tracking the VECT-TeamPCP alliance.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.