Vendor
NameSilo
- First Reported
- May 5, 2026
- Latest Reported
- Sep 30, 2026
Reported Context (2)
- TA419 consistently uses Cloudflare’s content delivery network (CDN) to obscure the backend hosting IP address for its domains, which are typically registered via NameSilo. China-Aligned TA419 Uses Impersonation and AiTM Phishing to Target U.S. AI Policy Experts
- dubai-10.vaermb[.]com, registered in May 2025 using NameSilo. The naming pattern suggests additional infrastructure, which we'll return to later in this post. Investigation Details Intrusion Targeting 12 Omani Government Entities, With 26,000 Records Extracted
CVE (4)
Threat Actors (5)
MITRE ATT&CK (26)
Vendors (4)
Products (15)
Tools (6)
Industries (5)
Countries (7)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.