sociopath

Record ID: ACT-0764
Handle(s): sociopath, Maze, edgy, recohere
Status: Active
First Observed: c. 2019 (Claimed) / 2026-05-08 (Documented)


Summary

sociopath is a Russian-speaking online cyber actor, self-described coder, and vulnerability researcher active within the “com” and Doxbin-adjacent communities. Emerging into the broader public view around 2022, sociopath specializes in OSINT (Open-Source Intelligence) and CSINT, frequently participating in targeted harassment, doxing, and counter-extortion campaigns.

He is best known for his self-reported involvement in unmasking extortionists (specifically tied to the “764” subculture) and participating in operations that allegedly led to real-world arrests (or “fedding”) of high-profile targets, sometimes alongside blockchain investigator ZachXBT. While he demonstrates competent reconnaissance skills and maintains a vast network of influential contacts within the doxing community, his reputation is heavily bolstered by his own enthusiastic self-promotion.


Aliases


Affiliations


Timeline



Evidence

Ref Source Date Notes
[1] Chat Logs 2026-05-09 Demonstrates reconnaissance capabilities by performing DNS enumeration (MX/TXT/NS records) on `comwiki.st` to locate Prequel's public Keybase profile and identify associated domains and crypto wallets.
[2] Chat Logs 2026-05-09 Clarifies his operational boundaries: “ion wanna associate with groups / but com and doxbin is fine / its major things”.
[3] Chat Logs 2026-05-09 Denies being Ukrainian after his Telegram account history shows the name “Святослав”; explains he “sniped” the account and is a Russian speaker residing in Switzerland.
[4] Chat Logs 2026-05-11 Forwards multiple messages from the `shield.sh` Telegram channel to verify his involvement in doxing campaigns against KNM, NWL, and other sub-groups.

Notes

static.comwiki.st_photo_2026-05-11_10-44-47.jpg

OSINT and Reconnaissance Capabilities sociopath demonstrates immediate, practical competence in open-source intelligence (OSINT) and infrastructure mapping. Upon engaging the ComWiki editor, he bypassed the site's front-end security by querying DNS records (MX, TXT, and NS) to identify a linked Keybase profile, successfully extracting email addresses, device names, and cryptocurrency wallets. He describes himself as a “coder” who mains in “OSINT/CSINT and webtesting,” and his methodical approach to digital footprinting supports this claim.

Anti-Extortion Campaigns and shield.sh A significant portion of sociopath’s documented legacy stems from his involvement with `shield.sh`, a group that actively targeted the “764” extortion subculture and rival online collectives. According to his provided logs and forwarded messages, operations conducted by sociopath and his associates (such as TuRk and paragon) resulted in the successful doxing of numerous extortionists (e.g., envy764, Revile764, crime764). More notably, he claims these campaigns exerted enough operational pressure to force entire collectives, specifically KNM and NWL, to disband.

High-Profile Interventions and Law Enforcement Unlike many actors in the doxing space who operate purely for intra-community clout, sociopath provides evidence of operations that crossed over into real-world legal consequences. He supplied screenshots corroborating his collaboration with prominent blockchain investigator ZachXBT, which allegedly culminated in the arrest of an individual known as “@John.” While he states he “indirectly worked with fbi,” this appears to refer to handing off intelligence to third-party investigators rather than acting as a formal informant.

Scope of Targeting sociopath’s operational scope is unusually broad, oscillating between dismantling serious cyber-extortion rings and terrorizing niche gaming circles. Using the same OSINT methodologies applied to 764 members, he orchestrated a wave of doxing against high-level Minecraft PvP players (including weqy, pafias, and vexaay) and members of the After Effects (AE) editing community. This dual focus highlights a capability to routinely compromise targets regardless of their threat level.

Analyst Observation on Evidence It is rare for an actor involved in illicit or gray-area cyber operations to voluntarily compile and submit a meticulously detailed dossier of their own network compromises, doxing campaigns, and forced disbandments to a public archivist. While his claims of dismantling groups and facilitating arrests are supported by forwarded screenshots and internal Telegram logs, the sheer volume of his operations makes independent verification of every claim difficult. Nevertheless, the provided evidence establishes him as a highly prolific and operationally effective actor within his distinct ecosystem.


Record created: 2026-05-11.