Threat Actor Attribution With OSINT: From Alias to Name, With Evidence Grades

A username match is not an attribution. Using aliases and email addresses already printed in sanctions entries, court filings and named reporting, this guide grades each kind of OSINT evidence on a six-rung ladder, from common-word collisions like "mango" (439 exact-match results) to email-anchored accounts and display names that reproduce a published identification. It also covers what never counts and how to verify a "hacker's email" before you pivot.

Patrick Saif9 min read

ShareXLinkedInHacker News
Dark editorial cover with a block of ASCII dither glyphs beside the words Threat actor attribution with OSINT
Dark editorial cover with a block of ASCII dither glyphs beside the words Threat actor attribution with OSINT

An alias match is not an attribution. We ran strings printed in US sanctions entries through a username search. The alias "mango" came back with 439 exact-match results. "Sinner4iter", the local part of a sanctioned Gmail address, came back with 4. The first result is noise and the second is a lead, and neither one names a person. At the person level, threat actor attribution with OSINT means grading each link in a chain and saying out loud which rung it reached.

This guide sets out that ladder using only people who have been charged, convicted or sanctioned, and identifiers already printed in court filings, Treasury entries or named reporting. Charged people are presumed innocent.

Threat actor attribution: group level vs person level

Most attribution writing is about groups, judged from tooling, infrastructure and tradecraft. The Unit 42 attribution framework is a well-built example. Person-level attribution asks whether the human behind a handle is a named individual. That answer lives in an affidavit, an indictment, a sanctions entry, or reporting that shows its method.

The TeamPCP case is a clean worked example. KrebsOnSecurity reported that the forum personas EllisD25/LSD, BulkDMT and Express "all advertised the same Tox ID and/or Session ID" as contact handles. Citing Intel 471, the article reports that Express registered on BreachForums with [email protected]. It also says that in June 2025 someone using the name Ruben Thomson registered on HackerOne under the username Deadcatx3, a nickname security firms tie to TeamPCP, and that he had incorporated or served as an official in a company called OPSEC Express. The links are independent, which is why the chain holds. Thomson was arrested in Australia in August 2026 and indicted in the Northern District of California. He is presumed innocent. Our TeamPCP footprint post covers the case in full.

The evidence ladder

Here is the scale we use when reading results against the record.

RungEvidencePublic-case exampleWhat it supports
0Exact username match on a common word"mango": 439 exact-match resultsNothing
1Exact match on a coined handle"sinner4iter": 4 of 4 exactThe string is in use; a lead
2Profile whose era, language or location fits the recordA 2013 profile displaying the sanctioned first name on the handle of an OFAC-listed addressConsistency, not identity
3Account anchored to a published email[email protected] resolves to a GitHub account named for the NeroWolfe persona Krebs tied to KhoroshevThe address holder controls that account
4Anchored or alias account whose display name matches the charged nameHackerOne deadcatx3 displays "ruben thomson"Strong corroboration of a published attribution
5Primary record with a stated methodAffidavit, indictment, SDN entry, named reportingAttribution

Open-source searching can climb to rung 4 on its own. Rung 5 belongs to documents written by people with subpoenas, sanctions authority or a published method.

Rung by rung: what the searches showed

Common words are camouflage

Treasury's 7 September 2023 Trickbot action (see our guide to OFAC SDN email addresses) lists Andrey Zhuykov as "DEFENDER" and "DIF" and Mikhail Tsarev as "MANGO". A username search across about 760 platforms returned 317 exact-match results for defender, 222 for dif and 439 of 442 for mango. Other public aliases did the same: express (the TeamPCP case) 316, omnipotent (the RaidForums case) 250, tylerb 242, pompompurin 223 and bestbuy 198. None can be attributed from the search result alone. A hit is a starting point, not an answer.

Horizontal bar chart of exact-match username results for common or borrowed aliases such as mango (439) and defender (317) versus coined aliases such as lockbitsupp (22) and sinner4iter (4)
Exact-match username results per alias printed in public records. Common or borrowed strings return hundreds of strangers.

Coined handles are leads, not names

Ivan Kondratyev was designated in Treasury's 20 February 2024 action, titled "United States Sanctions Affiliates of Russia-Based LockBit Ransomware Group". His entry lists aliases including "@SINNER911", "@SINNER6546" and "BASSTERLORD", plus the address [email protected]. An email lookup on that address found 13 platform registrations, and the Gravatar profile behind it displays "Sinner 1". A username search on the local part returned 4 exact-match results: two display "Sinner 1", the same name as the address's Gravatar, and one is dated 2022. That is a tidy cluster, and still only rung 1 or 2: one consistent user, nothing beyond what the SDN entry states. Coined handles collect strangers too: sinner911, another alias in the same entry, returned 37 results, and about a quarter display other people's names.

Anchors tie an account to an address, not a handle to a person

Rung 3 is where OSINT starts to carry weight. An email lookup on [email protected] returned a GitHub account named nerowolfe. Krebs, citing Intel 471, reported that this address registered more than a dozen accounts for NeroWolfe, a persona he tied to Dmitry Khoroshev. Khoroshev is indicted, not convicted, and presumed innocent; our LockBitSupp post has the detail. [email protected], which Krebs printed in his 2018 Satori story, returned a GitHub account named NexusZeta. Both reproduce what the record already said.

The trap is to treat an anchored account as proof that every account on the same handle belongs to that person. Zhuykov's OFAC address [email protected] resolves to a GitHub account displaying "Andrey", which matches his first name. A username search on megaprof returned 44 exact-match results. Two profiles on the handle display the same first name, in Latin and Cyrillic, and were created in 2013 and 2014, which fits the record. Others show unrelated names and locations on other continents. One anchor verified one account; every other result has to earn its place separately.

Display names that match the record

Rung 4 is a display name that matches the charged or sanctioned name, on an account that is itself anchored or tied to a public alias. Maksim Rudenskiy's OFAC address [email protected] resolves to a GitHub account displaying "Max Rudensky", a common transliteration of the same surname. The HackerOne profile at deadcatx3 displays "ruben thomson", which reproduces the Krebs finding.

A display name is still self-typed. A GitHub account reached from one public address displays the literal string {{7*7}} #{7*7}, a template-injection test. Treat display names as claims, not facts.

What does not count as attribution evidence

  • Accounts older than the alias could have existed. A Steam profile on lockbitsupp, located in Europe, was created in 2004, years before the LockBit brand. Old accounts that fit the record can be the most revealing, as the volhvb case shows; the test is whether the alias was even possible then.
  • Accounts created after the name went public. Khoroshev's indictment was unsealed and he was designated on 7 May 2024. On lockbitsupp, a Codeforces account appeared on 2024-05-12, a TikTok account on 2025-12-21 and a Twitch account on 2025-12-22. Treat each one as a possible squatter or impersonator unless something else shows otherwise.
  • Creation dates used as naming dates. A lockbitsupp YouTube channel was created 2023-09-15 and showed a display name rendering Khoroshev's name when we searched it. Display names can be edited at any time, so the name may have been set after the May 2024 naming by a squatter or impersonator.
  • Fictional and surname handles. nerowolfe returned 113 exact-match results. Nero Wolfe is Rex Stout's fictional detective, a natural pick for anyone. A handle equal to one defendant's surname returned 123, many of them namesakes.

Verify the "hacker's email" before you pivot

  1. Find it in a primary source. Addresses repeated online for well-known defendants, including [email protected], [email protected] and [email protected], appear in no filing or article we checked. The complaint against Kai West uses the placeholder "West Email Account-1" instead of printing his address.
  2. Match the spelling letter by letter. Krebs printed [email protected] in 2018 and [email protected] in his 2019 guilty-plea story, both describing the same control-server registration. An email lookup found 2 registrations for the z-spelling and returned no results for the c-spelling. The RaidForums article quotes the affidavit's [email protected] in its body, while its tag list has [email protected].
  3. Watch PDF extraction. In a 2025 federal complaint, an address wraps across two lines. A plain text extract yields a shorter address that is not the one in the filing and may belong to an unrelated person.
  4. Note the source's own confidence. The 2018 Satori story says researchers noted that the name in a domain's registration record "could be a pseudonym". Krebs's XSS forum piece presents its identification as "my take" and discusses a domain registered to a different name as possible misdirection. Carry that uncertainty forward.

Write it up so someone else can check it

For each identifier, record the source document and date, the exact string searched, the result, the rung and why, and any contradiction. The username verification checklist has a worksheet for the comparison step, and our guide to export formats covers when to hand over CSV, JSON or PDF.

OSINTsearch returns display names, bios, linked accounts, locations and creation dates for each hit across about 760 username platforms and 175 email platforms. Those fields move a row from rung 1 to rung 2 or 4. For a group-scale version of this method, see the Scattered Spider handle map. For how charging documents break cases, see how hackers get caught.

FAQ

Is a matching username enough to attribute a threat actor?

No. A match shows the string is registered. Common-word aliases return hundreds of unrelated results, and a match stays at rung 0 or 1 until something ties it to a published address or a record-consistent profile.

Can OSINT alone attribute a threat actor to a real person?

OSINT can reproduce and corroborate one, as with the HackerOne profile and the developer accounts anchored to sanctioned addresses. Naming the person behind a persona should rest on a primary record.

How do I tell an actor's account from a squatter's?

Compare the creation date with the public timeline. Accounts created after an arrest, unsealing or designation are possible squatters or impersonators by default. Accounts that predate the alias itself usually belong to someone else, while old accounts that fit the record can be the most revealing, as in the volhvb case.

Through reuse. The sources are court filings and sanctions entries, forum-registration and breach data reported by named firms such as Intel 471, and username and email lookups that test those leads against live platforms.

To see which rung your own lead reaches, run a free search on OSINTsearch for the handle or the published address, and grade each result before you write a name down.

ShareXLinkedInHacker News
All articles

News9 min

LockBitSupp on the Record: What Khoroshev's Emails and Alias Show Now

LockBitSupp is the persona US, UK and Australian authorities tied to Dmitry Khoroshev in May 2024. We ran the eight email addresses OFAC and KrebsOnSecurity published, and the alias itself, through a live search. One mailbox still reaches a GitHub account, opened in 2011, on the NeroWolfe persona Krebs tied to him. The alias returns 22 exact-handle results, and the YouTube channel that shows his name is very probably a fan's.

News9 min

TeamPCP Arrests: Charges, Aliases and What the Public Emails Return

Two Perth men were arrested in the TeamPCP supply chain case in August 2026, and Ruben Ian Thomson is also indicted in California. Here is the case status, how public reporting tied the Deadcatx3 and Express aliases to a name, and what the seven published email addresses return in a live lookup: 24 results on one, none found for the BreachForums registration address.

Try it

Run a live search on any username.

Free preview, no account needed. Sign up to view available profile details.

For other identifiers, try reverse email lookup or phone number lookup.