cipherforce
8 incidentes
5 paises
3 sectores
threat-actor VN Ultimo: 2026-06-29
CipherForce is the proprietary ransomware operation of TeamPCP, a financially motivated cybercrime collective first observed in late 2025. This group officially emerged around February 2026, distinguishing itself through a dual-track monetization model that includes its own ransomware campaigns and partnerships with other ransomware-as-a-service groups like Vect. TeamPCP, which operates CipherForce, is notable for pioneering sophisticated supply chain attacks, particularly targeting open-source security tooling and continuous integration/continuous deployment (CI/CD) pipelines to harvest credentials at scale. The collective describes itself as a loose-knit group of individuals who couldn't find conventional employment, operating under multiple aliases including PCPcat, ShellForce, DeadCatx3, and Persy_PCP, and is tracked by Google's Threat Intelligence Group as UNC6780. Their unique approach involves weaponizing security tools to gain initial access, feeding a broader credential moneti
Canales, DLS e infraestructura asociada
Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.
Paises objetivo (OSINT)
United Arab Emirates
Australia
Canada
Switzerland
China
Germany
IndiaIran, Islamic Republic ofKorea, Republic of
Netherlands
Sectores atacados
Technology (4)
Transportation/Logistics (1)
Business Services (1)
Sectores objetivo (OSINT)
Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersManufacturingConstructionPublic AdministrationEducational ServicesData Processing ServicesInternet Publishing
URLs nuevas detectadas en IntelTracker
Victimas (6)