They are in effect the same address, so this is not possible. You could set up a Rule in the Mail page at icloud.com to move all messages to the @icloud.com address to the Trash, from where they will be automatically deleted after a week. Co to the Mail page, click on the cogwheel icon at bottom left and choose 'Rules'.
I assume that you've set up a strong password and two-factor authentication so that at least the miscreant cannot receive messages at that address - presumably he's been using it to set up accounts and the return email from the businesses are coming to you? That's the usual problem, where some idiot thinks he owns someone else's address (it sounds strange, but it happens quite a bit).