CipherForce is a ransomware operation associated with the financially motivated threat group TeamPCP. It emerged as TeamPCP’s proprietary ransomware brand and operated in parallel with the group’s separate relationship to the Vect ransomware ecosystem, indicating a dual-track monetization model in which TeamPCP both conducted its own extortion activity and enabled affiliate-driven ransomware deployments through partners. CipherForce was publicly linked to victim shaming activity in early 2026 and was later folded into broader TeamPCP branding.
TeamPCP has been tied to large-scale software supply-chain compromises and cloud credential theft, and CipherForce appears to represent the ransomware component of that broader intrusion and monetization pipeline. Reporting links TeamPCP’s harvested credential troves to downstream ransomware operations, with CipherForce positioned as the group’s direct-use locker rather than a third-party affiliate payload. TeamPCP also advertised CipherForce-branded tooling as capable of encrypting major enterprise database and cloud storage solutions, suggesting an emphasis on enterprise disruption and extortion against organizations with substantial cloud and data-platform footprints.
CipherForce has been associated with leak-site operations and extortion deadlines, consistent with double-extortion ransomware tradecraft. It has been discussed alongside TeamPCP aliases including PCPcat, ShellForce, DeadCatx3, and Persy_PCP, and is best understood not merely as a standalone malware family but as the ransomware brand within TeamPCP’s criminal ecosystem. Available information supports its role in enterprise-focused ransomware and extortion activity, but detailed technical characteristics of the locker itself remain limited in the currently available reporting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CERT-EU disclosed on April 2-3, 2026 that the European Commission's Europa web hosting platform on AWS was breached through the Trivy supply chain compromise (CVE-2026-33634). ... Entry vector: Supply chain via compromised Trivy (CVE-2026-33634) ... The CISA KEV remediation deadline for CVE-2026-33634 is now 5 days away (April 8, 2026).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Arctic Wolf Labs assessed the group may operate in part as an Initial Access Broker (IAB), selling harvested credentials to other threat actors including the CipherForce and Vect ransomware affiliates.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
TeamPCP's own Telegram channel states: "you may already know us as TeamPCP or Shellforce... CipherForce is a newer project we are starting to find affiliates."
CipherForce is a newer project we are starting to find affiliates... This means TeamPCP is running two parallel ransomware tracks simultaneously: their proprietary CipherForce program for direct operations, and the mass Vect affiliate program via BreachForums for distributed operations.
the Sportradar AG breach ... has been confirmed as a "systemic compromise" jointly operated by TeamPCP and Vect ransomware.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware/locker brand previously operated by TeamPCP before its formal partnership with Vect. TeamPCP stated it used its own CipherForce locker rather than Vect encryption tools.
A ransomware or extortion channel mentioned only as an inactive affiliated monetization path during the reporting period.
Ransomware-branded tooling associated with TeamPCP, designed to encrypt major enterprise database and cloud storage solutions; described as part of TeamPCP's proprietary ransomware program.
Referenced as a named ransomware family via its leak/blog site in the context of tracking the VECT-TeamPCP alliance.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.