On 7 September 2023 the US Treasury added Maksim Galochkin to the sanctions list as a member of the Trickbot group, and the entry printed three monikers and four email addresses next to his name. Run those identifiers through an email lookup and a username search today and the handle "volhvb" leads to a Medium profile that displays that name in Cyrillic and a LiveJournal blog registered in 2010. That is the whole finding.
Nothing in this post unmasks anyone. The government did the naming and journalists reported it. What follows is the public footprint around identifiers the record already published.
The record: a sanctions entry, three indictments and one news report
The OFAC action of 7 September 2023 lists the entry as GALOCHKIN, Maksim, also known as BENTLEY, CRYPT and VOLHVB, of Abakan, Russia, born 19 May 1982, with four email addresses: [email protected], [email protected], [email protected] and [email protected]. The Treasury press release that accompanied the designation says he "led a group of testers, with responsibilities for development, supervision, and implementation of tests." Eleven people were designated that day in a joint action with the United Kingdom. The UK's own announcement lists the same eleven names and notes that paying a ransom to any of them, in cryptoassets or otherwise, is prohibited.
The same day the Department of Justice announced indictments against nine people. Galochkin appears in three of them: a Northern District of Ohio indictment for the Trickbot conspiracy, a Middle District of Tennessee indictment for Conti, where the release describes him as a "crypter" who modified the ransomware to evade antivirus, and a Southern District of California indictment over the May 2021 Conti attack on Scripps Health. An indictment is an allegation and every defendant is presumed innocent, as the release says. He is sanctioned and reported indicted. No public document reports him in custody, and none explains how investigators attributed the monikers to him.
Lawrence Abrams at BleepingComputer covered the sanctions the day they landed, with the full roster of roles and monikers. Reporting like that makes this exercise possible without guessing.
The email lookup: four mailboxes, one string
An email lookup checks whether an address is registered on roughly 175 services and, on a handful of them, returns the public handle attached to the account. We ran all four sanctioned mailboxes.
[email protected] is the busy one. About a dozen platforms answered, including a productivity suite, a design portfolio site, an online course provider, a creative software vendor, a browser account service and a blogging platform. [email protected] returned about nine, with a similar mix plus a game launcher. The Yandex address returned a handful and the mail.ru address barely anything, as you expect from provider-local mailboxes: the provider confirms the mailbox exists and little else does.
Two services attached to [email protected] also returned a public handle, and both returned the same one: "trader17". That is the only identity-bearing output from the email side. More on that below.
The pattern across the four addresses is what matters. A single six-letter string, used verbatim as the local part on four providers, is the same string the sanctions entry lists as a moniker. That reuse is why a lookup on any one of them reaches the rest. Why those four addresses are on the list is not something the record explains.
The username search: 11 exact matches for volhvb
A username search sweeps a handle across about 760 platforms and returns profile data where the account is public. "volhvb" is not a word in any language we know, so collisions should be rare. The result bears that out: 11 exact matches and no near misses.
| Platform | Display name | Created | What it adds |
|---|---|---|---|
| Medium | Максим Галочкин | not returned | Real name in Cyrillic, Russian bio, links to an X account under the same handle |
| LiveJournal | volhvb | 9 Feb 2010 | 11 posts, self-reported location Minusinsk, last activity Nov 2022 |
| Parler | Volhvb | 28 Jun 2020 | Presence only |
| Internet Archive | volhvb | 4 Aug 2020 | Empty profile |
| Open Library | volhvb | 4 Aug 2020 | Same day as the Archive account |
| GOG | volhvb | 11 Dec 2020 | Game store account |
| Volhv BF | not returned | 38 pins | |
| Telegram | lab | not returned | Public channel handle, one subscriber |
| GitHub, Replit, Fragment | none | not returned | Presence only |
The Medium profile is the finding. It is a username-exact account whose display name is "Максим Галочкин", the Cyrillic spelling of the name on the sanctions list, with a bio in Russian and a linked X account under the same handle. The LiveJournal account is the second finding: registered in February 2010, eleven posts, and a location field reading "Минусинск, RU". Minusinsk is a town a short drive from Abakan, the city named in the OFAC entry. That location is self-reported, so it corroborates rather than proves.
Presence on a platform is never proof of ownership. Any of these accounts could belong to someone else who liked the word, and any created after September 2023 would deserve a squatter or impersonator hedge. None of the dated accounts were created after the designation.
The chain

Read left to right: the sanctions entry supplies four mailboxes and a moniker. The email lookup confirms all four are live and shows the same string on each. The moniker, run as a username, lands on Medium with the real name and on LiveJournal with a 2010 registration and a plausible location. Every link in that chain is either a government document or a public profile page. The investigation view stacks the pivots in that order, so anyone reviewing the export can see which identifier produced which result.
Then there is the branch that goes nowhere. The two email-anchored services returned "trader17" as the handle on [email protected]. That link is real: it is what those two services report for that mailbox. But "trader17" run as a username search returns about 50 accounts, and reading them makes the problem obvious. The display names are ordinary personal names belonging to people with no connection to this case, so we do not print them; the locations run from the United States to Turkey to India, and the bios are about options tips, investing newsletters and Minecraft. An X account under that name dates from 2009 and an eBay account from 2008. This is a generic finance handle claimed by dozens of unrelated people. The only two "trader17" nodes that belong in the chain are the two the email lookup returned, and they show only that a sanctioned mailbox once registered a blog account under a common word. We did not chase it further.

What the dates say
The indictments say the Trickbot conspiracy began in November 2015 and the Conti conspiracy ran from 2020 to June 2022. The LiveJournal blog predates both by more than five years. A 2010 personal blog under a handle that later appears on a sanctions list survives because nobody thinks to delete it, and it is consistent with the handle being personal long before the designation.
The 2020 cluster also matters. Parler in June, the Internet Archive and Open Library on the same August day, GOG in December: four accounts in six months, all under the same handle, all during the period the Tennessee indictment covers. That says nothing about what the accounts were for. It says the person using the handle was still registering it on consumer services in 2020, which is a habit, and habits are what these searches find.
The last LiveJournal activity is November 2022, ten months before the designation. After that the dated record goes quiet. We make no claim about what any of these accounts have done since, and none of them is presented as live.
What it teaches
The first lesson is about the mononym. A distinctive string used as a mailbox local part, a forum moniker and a social handle is a single key to the whole footprint. A generic string like "trader17" opens fifty doors, and almost all of them are other people's. Before you sweep a handle, ask how many people would plausibly choose it.
The second: the oldest account is often the most useful. Profiles from 2010 were filled in before anyone cared about operational security, and location fields, bios and linked accounts from that era are rarely revisited. Creation dates let you order the evidence and put a personal-use period before an operational one.
The third: the government record is the anchor and the search is the illustration. The Medium display name means something only because a sanctions list already ties the handle to the name. On a handle that appears nowhere in the public record, a matching display name is a lead, not a conclusion.
How to run this yourself
Start from an identifier that a public document already prints, such as a sanctions entry, an indictment or a court filing. Run the email lookup on each address and note which ones return a handle. Run the username search on every moniker in the document and on any handle the email side returned. Use the cross search to pivot from a returned handle without leaving the investigation, so each hop is recorded under the one that produced it. Sort the results by creation date, mark anything created after the public action as a possible impersonator, and export the set with a note on which links you consider corroborated and which you are parking. Plan details are on the pricing page.
Limits
Everything above is presence and profile data. It shows that accounts under a given handle exist and what their public fields say. It does not show who typed them, and a location entered into a blog profile sixteen years ago is a claim by that person, not a fact about them. We ran no breach lookups for this piece and report none. Treasury and the Department of Justice named the person and printed the identifiers, the United Kingdom confirmed the list, and BleepingComputer explained it to everyone else. A search adds the shape of the footprint around those identifiers, and nothing more.



