CipherForce is a ransomware and data-extortion brand linked to the financially motivated threat actor TeamPCP, also known as PCPcat, ShellForce, and DeadCatx3. Available reporting indicates CipherForce emerged in early 2026 as either a TeamPCP-operated ransomware project or a closely aligned affiliate brand used to monetize access and data stolen during TeamPCP’s broader software supply-chain and credential-theft campaigns. CipherForce has been associated with leak-site operations and victim shaming rather than extensively documented malware tradecraft. Reporting indicates the brand listed a small number of victims in February 2026 and later appeared to be folded into or rebranded as TeamPCP leak infrastructure by May 2026. TeamPCP publicly described CipherForce as a newer project intended to recruit affiliates and begin publishing victim organizations, supporting the assessment that it functioned as an affiliate-facing extortion initiative within the TeamPCP ecosystem. The group’s role in the broader intrusion chain appears to center on post-compromise monetization. TeamPCP’s upstream activity has been characterized by compromises of developer tooling and CI/CD environments, large-scale credential harvesting, theft of cloud and source-code secrets, and reuse of stolen credentials across downstream victims. CipherForce is assessed to have benefited from that access, either as TeamPCP’s own ransomware label or as a partner operation receiving harvested credentials and stolen data for extortion and possible ransomware deployment. CipherForce has also been discussed alongside Vect as part of TeamPCP’s partnerships with ransomware and extortion actors. Some reporting states TeamPCP operated under the CipherForce brand before shifting or expanding to cooperation with Vect, while other reporting describes CipherForce and Vect as separate ransomware groups partnered with TeamPCP. Across these accounts, the consistent high-confidence picture is that CipherForce belongs to the financially motivated criminal ecosystem surrounding TeamPCP and is tied to data-leak and ransomware monetization of supply-chain-derived access. Publicly available information on CipherForce’s independent tooling, encryption mechanisms, victim negotiation practices, and intrusion procedures remains limited. No high-confidence evidence in the available reporting supports attribution to a nation-state actor. CipherForce is best characterized as a criminal ransomware/extortion operation or brand operating within the TeamPCP access-and-monetization network.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware/extortion brand previously operated by TeamPCP before rebranding to a TeamPCP leak site.
Referenced as another TeamPCP-affiliated ransomware operator that had been inactive for roughly 70 days.
Named extortion/leak infrastructure referenced as part of the broader TeamPCP-affiliated monetization ecosystem. The content emphasizes that its infrastructure remained offline and no expected public dump occurred.
Named extortion/leak infrastructure associated in the reporting with TeamPCP's monetization ecosystem, noted here as offline and inactive during the period.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.