An alias match is not an attribution. We ran strings printed in US sanctions entries through a username search. The alias "mango" came back with 439 exact-match results. "Sinner4iter", the local part of a sanctioned Gmail address, came back with 4. The first result is noise and the second is a lead, and neither one names a person. At the person level, threat actor attribution with OSINT means grading each link in a chain and saying out loud which rung it reached.
This guide sets out that ladder using only people who have been charged, convicted or sanctioned, and identifiers already printed in court filings, Treasury entries or named reporting. Charged people are presumed innocent.
Threat actor attribution: group level vs person level
Most attribution writing is about groups, judged from tooling, infrastructure and tradecraft. The Unit 42 attribution framework is a well-built example. Person-level attribution asks whether the human behind a handle is a named individual. That answer lives in an affidavit, an indictment, a sanctions entry, or reporting that shows its method.
The TeamPCP case is a clean worked example. KrebsOnSecurity reported that the forum personas EllisD25/LSD, BulkDMT and Express "all advertised the same Tox ID and/or Session ID" as contact handles. Citing Intel 471, the article reports that Express registered on BreachForums with [email protected]. It also says that in June 2025 someone using the name Ruben Thomson registered on HackerOne under the username Deadcatx3, a nickname security firms tie to TeamPCP, and that he had incorporated or served as an official in a company called OPSEC Express. The links are independent, which is why the chain holds. Thomson was arrested in Australia in August 2026 and indicted in the Northern District of California. He is presumed innocent. Our TeamPCP footprint post covers the case in full.
The evidence ladder
Here is the scale we use when reading results against the record.
| Rung | Evidence | Public-case example | What it supports |
|---|---|---|---|
| 0 | Exact username match on a common word | "mango": 439 exact-match results | Nothing |
| 1 | Exact match on a coined handle | "sinner4iter": 4 of 4 exact | The string is in use; a lead |
| 2 | Profile whose era, language or location fits the record | A 2013 profile displaying the sanctioned first name on the handle of an OFAC-listed address | Consistency, not identity |
| 3 | Account anchored to a published email | [email protected] resolves to a GitHub account named for the NeroWolfe persona Krebs tied to Khoroshev | The address holder controls that account |
| 4 | Anchored or alias account whose display name matches the charged name | HackerOne deadcatx3 displays "ruben thomson" | Strong corroboration of a published attribution |
| 5 | Primary record with a stated method | Affidavit, indictment, SDN entry, named reporting | Attribution |
Open-source searching can climb to rung 4 on its own. Rung 5 belongs to documents written by people with subpoenas, sanctions authority or a published method.
Rung by rung: what the searches showed
Common words are camouflage
Treasury's 7 September 2023 Trickbot action (see our guide to OFAC SDN email addresses) lists Andrey Zhuykov as "DEFENDER" and "DIF" and Mikhail Tsarev as "MANGO". A username search across about 760 platforms returned 317 exact-match results for defender, 222 for dif and 439 of 442 for mango. Other public aliases did the same: express (the TeamPCP case) 316, omnipotent (the RaidForums case) 250, tylerb 242, pompompurin 223 and bestbuy 198. None can be attributed from the search result alone. A hit is a starting point, not an answer.

Coined handles are leads, not names
Ivan Kondratyev was designated in Treasury's 20 February 2024 action, titled "United States Sanctions Affiliates of Russia-Based LockBit Ransomware Group". His entry lists aliases including "@SINNER911", "@SINNER6546" and "BASSTERLORD", plus the address [email protected]. An email lookup on that address found 13 platform registrations, and the Gravatar profile behind it displays "Sinner 1". A username search on the local part returned 4 exact-match results: two display "Sinner 1", the same name as the address's Gravatar, and one is dated 2022. That is a tidy cluster, and still only rung 1 or 2: one consistent user, nothing beyond what the SDN entry states. Coined handles collect strangers too: sinner911, another alias in the same entry, returned 37 results, and about a quarter display other people's names.
Anchors tie an account to an address, not a handle to a person
Rung 3 is where OSINT starts to carry weight. An email lookup on [email protected] returned a GitHub account named nerowolfe. Krebs, citing Intel 471, reported that this address registered more than a dozen accounts for NeroWolfe, a persona he tied to Dmitry Khoroshev. Khoroshev is indicted, not convicted, and presumed innocent; our LockBitSupp post has the detail. [email protected], which Krebs printed in his 2018 Satori story, returned a GitHub account named NexusZeta. Both reproduce what the record already said.
The trap is to treat an anchored account as proof that every account on the same handle belongs to that person. Zhuykov's OFAC address [email protected] resolves to a GitHub account displaying "Andrey", which matches his first name. A username search on megaprof returned 44 exact-match results. Two profiles on the handle display the same first name, in Latin and Cyrillic, and were created in 2013 and 2014, which fits the record. Others show unrelated names and locations on other continents. One anchor verified one account; every other result has to earn its place separately.
Display names that match the record
Rung 4 is a display name that matches the charged or sanctioned name, on an account that is itself anchored or tied to a public alias. Maksim Rudenskiy's OFAC address [email protected] resolves to a GitHub account displaying "Max Rudensky", a common transliteration of the same surname. The HackerOne profile at deadcatx3 displays "ruben thomson", which reproduces the Krebs finding.
A display name is still self-typed. A GitHub account reached from one public address displays the literal string {{7*7}} #{7*7}, a template-injection test. Treat display names as claims, not facts.
What does not count as attribution evidence
- Accounts older than the alias could have existed. A Steam profile on lockbitsupp, located in Europe, was created in 2004, years before the LockBit brand. Old accounts that fit the record can be the most revealing, as the volhvb case shows; the test is whether the alias was even possible then.
- Accounts created after the name went public. Khoroshev's indictment was unsealed and he was designated on 7 May 2024. On lockbitsupp, a Codeforces account appeared on 2024-05-12, a TikTok account on 2025-12-21 and a Twitch account on 2025-12-22. Treat each one as a possible squatter or impersonator unless something else shows otherwise.
- Creation dates used as naming dates. A lockbitsupp YouTube channel was created 2023-09-15 and showed a display name rendering Khoroshev's name when we searched it. Display names can be edited at any time, so the name may have been set after the May 2024 naming by a squatter or impersonator.
- Fictional and surname handles. nerowolfe returned 113 exact-match results. Nero Wolfe is Rex Stout's fictional detective, a natural pick for anyone. A handle equal to one defendant's surname returned 123, many of them namesakes.
Verify the "hacker's email" before you pivot
- Find it in a primary source. Addresses repeated online for well-known defendants, including [email protected], [email protected] and [email protected], appear in no filing or article we checked. The complaint against Kai West uses the placeholder "West Email Account-1" instead of printing his address.
- Match the spelling letter by letter. Krebs printed
[email protected]in 2018 and[email protected]in his 2019 guilty-plea story, both describing the same control-server registration. An email lookup found 2 registrations for the z-spelling and returned no results for the c-spelling. The RaidForums article quotes the affidavit's[email protected]in its body, while its tag list has[email protected]. - Watch PDF extraction. In a 2025 federal complaint, an address wraps across two lines. A plain text extract yields a shorter address that is not the one in the filing and may belong to an unrelated person.
- Note the source's own confidence. The 2018 Satori story says researchers noted that the name in a domain's registration record "could be a pseudonym". Krebs's XSS forum piece presents its identification as "my take" and discusses a domain registered to a different name as possible misdirection. Carry that uncertainty forward.
Write it up so someone else can check it
For each identifier, record the source document and date, the exact string searched, the result, the rung and why, and any contradiction. The username verification checklist has a worksheet for the comparison step, and our guide to export formats covers when to hand over CSV, JSON or PDF.
OSINTsearch returns display names, bios, linked accounts, locations and creation dates for each hit across about 760 username platforms and 175 email platforms. Those fields move a row from rung 1 to rung 2 or 4. For a group-scale version of this method, see the Scattered Spider handle map. For how charging documents break cases, see how hackers get caught.
FAQ
Is a matching username enough to attribute a threat actor?
No. A match shows the string is registered. Common-word aliases return hundreds of unrelated results, and a match stays at rung 0 or 1 until something ties it to a published address or a record-consistent profile.
Can OSINT alone attribute a threat actor to a real person?
OSINT can reproduce and corroborate one, as with the HackerOne profile and the developer accounts anchored to sanctioned addresses. Naming the person behind a persona should rest on a primary record.
How do I tell an actor's account from a squatter's?
Compare the creation date with the public timeline. Accounts created after an arrest, unsealing or designation are possible squatters or impersonators by default. Accounts that predate the alias itself usually belong to someone else, while old accounts that fit the record can be the most revealing, as in the volhvb case.
How do analysts link a dark web alias to a real name?
Through reuse. The sources are court filings and sanctions entries, forum-registration and breach data reported by named firms such as Intel 471, and username and email lookups that test those leads against live platforms.
To see which rung your own lead reaches, run a free search on OSINTsearch for the handle or the published address, and grade each result before you write a name down.



