Record ID: ACT-0009
Handle(s): Cusher, @cushbush
Status: Active
First Observed: 2025-08-06
Cusher (also NOT known as Ducky) is the creator of IntelX, an online cyber actor active within Telegram-based database and OSINT (Open Source Intelligence) communities. He is primarily known for his role as an instigator of targeted social engineering and harassment campaigns, as well as his engagement with credential and database sharing forums.
The available evidence paints Cusher as a highly volatile but socially influential influencer within his niche. And only his niche. He demonstrates a working knowledge of basic cyber operations—such as phishing, opsex, domain spoofing, and OSINT lookup tools—but his primary skillset appears to be psychological manipulation and “ragebaiting.” Cusher's communication style is deeply entrenched in the shock-value culture of underground Telegram, characterized by the casual use of racial slurs, absurd shitposting, and highly sexualized trolling. While he frequently postures as a formidable hacker, his technical discipline is inconsistent, highlighted by occasional lapses in operational security.
Cusher — Primary handle used across multiple Telegram channels.Ducky — His betrothed.2025-08-06 — First documented activity in the logs, initiating contact in a repository chat.2025-08-07 — Cusher discusses registering spoofed U.S. government domains (e.g., `government.airforce`) for social engineering purposes.2025-08-08 — Cusher launches a sustained harassment and gaslighting campaign against a user known as “Emmet” or “Roadrage.”2025-08-09 — Accidentally leaks his own IntelX API key into a public chat.2026-01-10 — Last known activity, observed utilizing the “JUBA Search” OSINT bot.| Ref | Source | Date | Notes |
|---|---|---|---|
| [1] | B F R e p o V 3 C h a t | 2025-08-07 | Discusses registering misspelled government domains (`goverment.airforce`) to trick targets. |
| [2] | B F R e p o V 3 C h a t | 2025-08-08 | Claims to have successfully sent a “fake cp link” to log an adversary's IP. |
| [3] | REPOLENA'S IMAGE BOARD | 2025-08-09 | Successfully drives a target to “ragequit” through aggressive gaslighting regarding “IPv9.” |
| [4] | Database World ROC | 2025-08-09 | Accidentally posts a live IntelX API key into the public channel. |
| [5] | J U B A v1 / JUBA Search 1.5 | 2025-10-22 | Observed using OSINT tools to look up IPs and phone numbers. |
Tactics and Technical Competence Cusher’s actual technical ability is difficult to accurately assess, as it is heavily obscured by layers of irony, trolling, and performative posturing. He claims to be a “pro haxxor” who has “hacked in cia” using “IPv9”—an assertion best understood as deliberate shitposting rather than a confession to a federal crime. However, he demonstrates practical competence in lower-level mechanics: he discusses purchasing spoofed top-level domains for phishing, successfully deploys IP loggers, and regularly utilizes specialized OSINT bots (such as JUBA Search) for reconnaissance.
His operational security, however, leaves room for improvement. During a fast-paced chat in August 2025, he accidentally pasted a live API key into a public channel, subsequently realizing his mistake with a brief “Oops.” As demonstrations of tactical restraint go, this was not one of the stronger specimens.
The Emmet/Roadrage Campaign The most heavily documented event in the logs is Cusher's sustained psychological assault on a user known as “Emmet” or “Roadrage.” Cusher repeatedly accuses this individual of being an elderly predator with an extensive criminal record. Whether these allegations are factual or merely a convenient angle of attack cannot be verified from the chat logs alone.
Regardless of the target's guilt, Cusher displays a ruthless talent for social engineering. He orchestrates a multi-day campaign of targeted harassment, utilizing highly sexualized insults, fake links, and bizarre gaslighting (convincing the target that a fictional protocol called “IPv9” is real). Cusher successfully breaks the target's composure, celebrating when the user begins to spam the chat, “goes ballistic,” and ultimately ragequits. Cusher later remarks, “I deadass ruined him.” The incident highlights Cusher's primary strength: he is highly observant of psychological vulnerabilities and persistent in exploiting them.
Behavior and Conduct Cusher’s communication is highly abrasive. He frequently uses racial slurs, expresses aggressive prejudices, and relies heavily on juvenile, shock-value humor. Paradoxically, much of his aggressive posturing toward other users involves extreme, homoerotic threats (e.g., threatening to put his anatomy in their mouths), a common hallmark of edgelord internet subcultures.
While he is undeniably chaotic and often cruel, he commands a level of charismatic authority within his circle. Other users frequently follow his lead during trolling campaigns, and he views himself as an elite member of a “niche group,” expressing disdain for outsiders or “larpers” who lack his specific brand of internet knowledge.
Cusher presents the classic profile of a talented but undisciplined threat actor. He is capable of effective reconnaissance and social engineering but is easily distracted by his own need to perform for an audience. His reliance on extreme rhetoric and public bullying suggests that social dominance is as important to him as actual cyber operations.
Record created: 2026-05-08.