The CipherForce ransomware operation has listed Biaodianyun Group Ltd and hiringsteps[.]com as victims, indicating two additional organizations have been added to the group’s public leak infrastructure. The postings were surfaced by RedPacket Security, which tracked separate victim entries naming both entities.
The disclosures suggest CipherForce is continuing to publicize alleged compromises across different sectors, using victim-name announcements as part of its extortion strategy. While the available references do not provide technical details on intrusion methods, encryption activity, or data volume, the victim listings indicate claimed ransomware-related breaches affecting both Biaodianyun Group Ltd and HiringSteps.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
A RedPacket Security reference indicates that the CipherForce ransomware operation claimed Zip24 / ShipOx as a victim. No additional incident details or timing beyond the publication context were provided.
A RedPacket Security reference indicates that the CipherForce ransomware operation claimed tektreeinc.com as a victim. No additional incident details or timing beyond the publication context were provided.
A RedPacket Security reference indicates that the CipherForce ransomware operation claimed Biaodianyun Group Ltd as a victim. No additional incident details or timing beyond the publication context were provided.
A RedPacket Security reference indicates that the CipherForce ransomware operation claimed hiringsteps.com as a victim. No additional incident details or timing beyond the publication context were provided.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
redpacketsecurity.com
Open sourceredpacketsecurity.com
Open sourceredpacketsecurity.com
Open sourceredpacketsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.