Menu
Browse

Cyber Threat Actor: Peace

Aliases: 2 aliases
Actor Type Location Known Incidents
 Icon
Criminal
5 incidents
Profile

The threat actor known as Peace_Of_Mind, operating under aliases including Peace, Peace AKA Peace_Of_Mind, and Peace_of_Mind, has been linked to multiple high-impact data breaches and cybercriminal activities between 2015 and 2016. This actor gained notoriety for compromising major online platforms, exfiltrating sensitive user data, and monetizing stolen information through dark web marketplaces such as The Real Deal. Peace_Of_Mind’s operations targeted diverse sectors, including technology companies, social media platforms, adult entertainment services, and open-source software projects. The actor demonstrated a consistent pattern of exploiting vulnerabilities in web infrastructure, leveraging stolen credentials, and repackaging legitimate software with malicious payloads to establish unauthorized access.

Notable incidents attributed to Peace_Of_Mind include the 2016 breach of Adult FriendFinder, where the actor claimed to have exfiltrated a database of 73 million users by exploiting a previously disclosed backdoor. The same year, Peace_Of_Mind advertised the sale of 200 million alleged Yahoo user credentials from a 2012 breach, though Yahoo did not confirm the incident’s validity. The actor also sold data stolen from Tumblr’s 2013 breach, which affected 65 million accounts, emphasizing the monetization of aged but high-value datasets. In a separate campaign targeting the Linux Mint project, Peace_Of_Mind compromised the distribution servers to replace legitimate ISO files with backdoored versions containing the Tsunami malware, enabling botnet control over infected systems. The actor additionally exfiltrated and leaked the Linux Mint forums’ user database, exposing 71,000 accounts. Peace_Of_Mind’s activities extended to intra-community conflicts within the hacking underground, including the defacement of rival hacker w0rm’s website and the leak of its forum database alongside the Hunter exploit kit’s source code.

Technical patterns in Peace_Of_Mind’s operations include the use of credential-stuffing attacks, web server compromises to manipulate file checksums, and the distribution of repackaged software with embedded backdoors. The actor frequently utilized public platforms like Twitter and Telegram for claims of responsibility and extortion attempts, while relying on dark web forums for data sales and communications. No conclusive evidence links Peace_Of_Mind to state-sponsored groups or criminal syndicates, with activities suggesting independent financial motivation through data brokerage and disruptive attacks. The actor’s focus on high-profile targets with large user bases underscores a strategic emphasis on maximizing the economic return from stolen data, often prioritizing quantity over precision in targeting. Peace_Of_Mind’s operations diminished in visibility after 2016, though historical breaches attributed to the actor continue to impact affected organizations and users.

Incidents
Attributed incidents available to members
5 incidents
Sources
Sources available to members
19 sources