Menu
Browse

Cyber Incident Victim: w0rm

Date:

Oct 2016

Location:

United States of America

Summary

A black hat hacker known as Peace breached and defaced the website of rival w0rm, posting a threatening message alongside the victim's alleged personal details. The attack was motivated by w0rm's actions in reporting vulnerabilities that compromised Peace's access to certain websites, scamming associates, and republishing exclusive content from the private Hell Forum community. Peace further leaked the victim's site database, exposing user credentials, private communications, and the source code for the Hunter exploit kit—an active cybercrime tool. This incident followed prior doxing events targeting w0rm, whose platform previously hosted stolen data from other underground forums.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
2 actors Available to members Available to members

Description

On or around October 2, 2016, the website of the hacker known as w0rm was breached and defaced by a rival threat actor using the alias Peace (also identified as Peace_of_Mind). The attack occurred over a weekend, with visitors to w0rm's site encountering a defacement message on Sunday morning claiming responsibility from "Peace of Mind and prometheus" for "[expletive] with Hell Forum." The defacement included personal details purportedly belonging to w0rm, though the accuracy of this information could not be independently verified. This marked at least the third time w0rm had been doxed, following similar incidents in October 2014 and September 2015. Peace confirmed the attack to Softpedia, citing w0rm's actions in reporting vulnerabilities of websites Peace had compromised, which caused Peace to lose access to those systems. Additional motivations included allegations that w0rm had scammed associates of Peace and had stolen restricted content from Hell Forum—a private community for high-level hackers—by republishing it on his publicly accessible website.

Cyber Incident Image

The compromise extended beyond defacement, as Peace exfiltrated and leaked w0rm's entire website database. The dump contained forum user credentials, private messages, and account details. Notably, it also included the source code for Hunter, an active but lesser-known exploit kit operating in 2016. w0rm's site served as a repository for proof-of-concept vulnerability code and stolen database dumps from various cybercrime forums, a practice that had previously drawn retaliation. No response or containment actions from w0rm were documented in available sources following the breach. The incident exposed operational details of both actors' activities, including w0rm's forum community and Peace's retaliatory tactics within the competitive underground hacking ecosystem.

Sources
Sources available to members
1 source