Skip to main content
Mallory
1 malware family

cipherforce

Also known ascipherforce

CipherForce is a ransomware and data-extortion operation first observed on 2026-02-23. It operates Tor-based leak infrastructure, including the onion site o3ydbkayttkyg4iw2nc732jxmmex25bjeyqyvuuyngnxmpehdefjr3qd.onion, though reporting states its two known Tor leak sites were offline or unavailable during parts of April 2026 and that it had not posted new victims since 2026-02-23. Available leak-site profiling lists six alleged victims across multiple countries and sectors, but no ransom notes, exploited vulnerabilities, negotiation chats, or indicators of compromise were available in the cited content. The group is directly linked in the reporting to TeamPCP and ShellForce. One cited statement attributed to the operators says: "For those out of the loop, you may already know us as TeamPCP or Shellforce... CipherForce is a newer project we are starting to find affiliates and are hoping to begin publishing companies soon." Supporting reporting further states that TeamPCP launched a proprietary ransomware operation under the CipherForce name, and that TeamPCP partnered with CipherForce, alongside Vect and in some reporting Lapsus$, to leak data and extort victims. The content also states that CI/CD credential theft campaigns attributed to TeamPCP fed a broader monetization chain linked to CipherForce. Based on the provided content, CipherForce should be understood as a financially motivated ransomware/extortion brand associated with the broader TeamPCP/ShellForce ecosystem rather than a separately attributed nation-state actor. Known aliases directly supported by the content are CipherForce, with explicit linkage to TeamPCP and ShellForce as the broader actor/project context.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Transportation
  • Commercial & Professional Services
  • Software & Services

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States
  • 🇦🇪 United Arab Emirates
  • 🇻🇳 Vietnam
  • 🇮🇳 India
  • 🇨🇳 China
MITRE ATT&CK

Tradecraft

39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

13 of 15 tactics49 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
2 techniques
T1583
Acquire Infrastructure
T1586
Compromise Accounts
TA0001
Initial Access
2 techniques
T1078×2
Valid Accounts
T1078.004
Cloud Accounts
T1195×8
Supply Chain Compromise
T1195.001×3
Compromise Software Dependencies and Development Tools
T1195.002
Compromise Software Supply Chain
TA0002
Execution
3 techniques
T1059
Command and Scripting Interpreter
T1059.004
Unix Shell
T1072
Software Deployment Tools
T1574
Hijack Execution Flow
TA0003
Persistence
2 techniques
T1078×2
Valid Accounts
T1078.004
Cloud Accounts
T1546
Event Triggered Execution
TA0004
Privilege Escalation
3 techniques
T1078×2
Valid Accounts
T1078.004
Cloud Accounts
T1546
Event Triggered Execution
T1548
Abuse Elevation Control Mechanism
TA0005
Stealth
4 techniques
T1027
Obfuscated Files or Information
T1036
Masquerading
T1078×2
Valid Accounts
T1078.004
Cloud Accounts
T1574
Hijack Execution Flow
TA0006
Credential Access
5 techniques
T1003×2
OS Credential Dumping
T1528×2
Steal Application Access Token
T1552
Unsecured Credentials
T1552.001×2
Credentials In Files
T1555×2
Credentials from Password Stores
T1649×5
Steal or Forge Authentication Certificates
TA0007
Discovery
1 technique
T1526
Cloud Service Discovery
TA0008
Lateral Movement
2 techniques
T1072
Software Deployment Tools
T1210
Exploitation of Remote Services
TA0009
Collection
3 techniques
T1005
Data from Local System
T1213
Data from Information Repositories
T1560
Archive Collected Data
TA0011
Command and Control
2 techniques
T1008
Fallback Channels
T1090
Proxy
TA0010
Exfiltration
4 techniques
T1041×2
Exfiltration Over C2 Channel
T1048
Exfiltration Over Alternative Protocol
T1537×2
Transfer Data to Cloud Account
T1567×2
Exfiltration Over Web Service
T1567.001
Exfiltration to Code Repository
T1567.002×2
Exfiltration to Cloud Storage
TA0040
Impact
5 techniques
T1486×12
Data Encrypted for Impact
T1491
Defacement
T1496
Resource Hijacking
T1565
Data Manipulation
T1565.001
Stored Data Manipulation
T1657×5
Financial Theft
IOCS

Observables

1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

handlers diary fullNews
May 4, 2026
TeamPCP Weekly Analysis: 2026-W18 (2026-04-27 through 2026-05-03)

Referenced as another TeamPCP-affiliated ransomware operator that had been inactive for roughly 70 days.

Read more
handlers diary fullNews
Apr 27, 2026
TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns

Named extortion/leak infrastructure referenced as part of the broader TeamPCP-affiliated monetization ecosystem. The content emphasizes that its infrastructure remained offline and no expected public dump occurred.

Read more
handlers diary fullNews
Apr 27, 2026
TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns

Named extortion/leak infrastructure associated in the reporting with TeamPCP's monetization ecosystem, noted here as offline and inactive during the period.

Read more
handlers diary fullNews
Apr 27, 2026
TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns

Named extortion/leak infrastructure referenced as part of the broader TeamPCP-linked monetization ecosystem, noted here for inactivity and offline leak infrastructure.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping39

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables1

Domains, IPs, and hashes tied to this actor, refreshed continuously.