CipherForce : marque ransomware interne du groupe.
CipherForce
CipherForce is a ransomware operation associated with the financially motivated threat group TeamPCP.
Profile source: Mallory opens in a new tabCipherForce
Family profile
CipherForce is a ransomware operation associated with the financially motivated threat group TeamPCP. It is assessed to be TeamPCP’s in-house ransomware brand, distinct from the group’s separate partnership with the Vect ransomware ecosystem, and was used as one of multiple monetization channels following TeamPCP’s large-scale credential theft and software supply-chain compromises in 2026. Reporting indicates TeamPCP operated CipherForce in parallel with affiliate-oriented ransomware activity, using stolen enterprise access and harvested secrets to support direct extortion operations.
CipherForce has been described as proprietary TeamPCP tooling and branding rather than merely a leak persona. TeamPCP promoted CipherForce-branded capabilities designed to encrypt major enterprise database and cloud storage solutions, indicating an enterprise-focused ransomware model aimed at high-value environments. Publicly observed leak-site activity tied to CipherForce showed a limited number of named victims in early 2026 before the infrastructure later went offline and was subsequently rebranded toward TeamPCP branding.
The broader TeamPCP ecosystem that supported CipherForce was heavily tied to post-compromise credential theft, cloud and SaaS access abuse, data exfiltration, and downstream extortion. TeamPCP’s supply-chain intrusions against developer and security tooling were used to harvest credentials at scale, after which the group and aligned actors exploited stolen access for cloud discovery, lateral movement, data theft, and ransomware deployment. CipherForce therefore appears to fit into a broader intrusion-to-extortion pipeline in which compromised credentials and enterprise access were converted into ransomware operations against downstream victims.
CipherForce is linked to Windows and enterprise cloud or storage environments through TeamPCP’s advertised encryption focus, but detailed technical analysis of the locker itself remains limited in the available information. High-confidence reporting supports classification of CipherForce as ransomware associated with TeamPCP and used for direct operations separate from Vect.
Capabilities
- Exfiltration
- Extortion
Operational record
Reported operators
Threat actors
2 named in public reportingA note on CipherForce ransomware blog, March 2026
Exploited software
Vulnerabilities linked to CipherForce
1 CVEsMITRE ATT&CK