Skip to content

CipherForce

CipherForce is a ransomware operation associated with the financially motivated threat group TeamPCP.

Profile source: Mallory opens in a new tab

CipherForce

Family profile

CipherForce is a ransomware operation associated with the financially motivated threat group TeamPCP. It is assessed to be TeamPCP’s in-house ransomware brand, distinct from the group’s separate partnership with the Vect ransomware ecosystem, and was used as one of multiple monetization channels following TeamPCP’s large-scale credential theft and software supply-chain compromises in 2026. Reporting indicates TeamPCP operated CipherForce in parallel with affiliate-oriented ransomware activity, using stolen enterprise access and harvested secrets to support direct extortion operations.

CipherForce has been described as proprietary TeamPCP tooling and branding rather than merely a leak persona. TeamPCP promoted CipherForce-branded capabilities designed to encrypt major enterprise database and cloud storage solutions, indicating an enterprise-focused ransomware model aimed at high-value environments. Publicly observed leak-site activity tied to CipherForce showed a limited number of named victims in early 2026 before the infrastructure later went offline and was subsequently rebranded toward TeamPCP branding.

The broader TeamPCP ecosystem that supported CipherForce was heavily tied to post-compromise credential theft, cloud and SaaS access abuse, data exfiltration, and downstream extortion. TeamPCP’s supply-chain intrusions against developer and security tooling were used to harvest credentials at scale, after which the group and aligned actors exploited stolen access for cloud discovery, lateral movement, data theft, and ransomware deployment. CipherForce therefore appears to fit into a broader intrusion-to-extortion pipeline in which compromised credentials and enterprise access were converted into ransomware operations against downstream victims.

CipherForce is linked to Windows and enterprise cloud or storage environments through TeamPCP’s advertised encryption focus, but detailed technical analysis of the locker itself remains limited in the available information. High-confidence reporting supports classification of CipherForce as ransomware associated with TeamPCP and used for direct operations separate from Vect.

Capabilities

  • Exfiltration
  • Extortion

Operational record

1
YARA rules
1
Leak sites
0 available

Reported operators

Threat actors

2 named in public reporting
TeamPCP

CipherForce : marque ransomware interne du groupe.

Vect

A note on CipherForce ransomware blog, March 2026

Exploited software

Vulnerabilities linked to CipherForce

1 CVEs

MITRE ATT&CK

CipherForce in ATT&CK

12 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.