Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

GitHub RadarBlue team tool

phishdestroy/namesilo-evidence

NameSilo (IANA #1479) registrar abuse investigation. 5.27M domains scanned · 87.3% dead/parked · 183k malicious behind their own privacy shield · Filed with ICANN Mar 2026. Primary language: HTML. 137 stars.

HTML137 stars32 forkspushed Jul 27, 2026MIT

Project links:Open GitHub projectBack to radar

README Preview

Fetched from GitHub

<div align="center"> <img src="https://raw.githubusercontent.com/phishdestroy/namesilo-evidence/main/docs/assets/banner.gif" width="100%"/> </div>

<!-- NameSilo, LLC (IANA #1479) — Registrar Abuse Investigation Keywords: namesilo, xmrwallet, monero-drainer, crypto-scam, registrar-abuse, icann-compliance, phishdestroy -->

<h3 align="center">You made this investigation necessary.<br/>Now you cannot make it disappear.</h3>

<p align="center"> <b>NameSilo (NASDAQ: URL)</b> — a publicly traded registrar with a 32.2% dead domain rate,<br/> a ten-year fraud under active protection, and a documented pattern of suppressing<br/> the researchers who exposed it.<br/> Every takedown. Every lawyer. Every deleted tweet.<br/> All of it is in the record. All of it makes this louder.<br/> <b>PhishDestroy is a Hydra. You already pulled the first head.</b><br/> <b>Pedigreeless Russian dogs can write reviews about themselves and buy articles about themselves in the third person.</b> </p>

<div align="center"> <details> <summary>Spoiler</summary> <p> <img src="Woof-woof.png" alt="Woof-woof" /> <br/> <b>It is quite baffling that the 'fastest-growing registrar in the world' appears entirely unaware of Section 3.18 of the ICANN Registrar Accreditation Agreement (RAA) and its explicit requirements. There is no need to lie. Previously, you claimed to have conducted an investigation and inexplicably offered to help clear VirusTotal detections for the operator. Now you are either distorting the facts, or you have finally realized that managing malware detections is entirely outside your jurisdiction. Either way, you are missing the point. I assure you, I fully understand the legal rights of users and the strict obligations of registrars. A service provider like NameSilo is obligated to take actionable steps against abuse—not to shield perpetrators, ignore reports, or mislead the public. This is not 2018, and this is no longer just an appeal to ICANN. Based on the factual evidence, I am now calling upon US law enforcement and regulatory authorities to investigate the individuals involved here, as the facts indicate direct complicity in organizing scams and other illicit activities within the United States.</b> </p> </details> </div>

</div>

---

<!-- LIVE_STATS:START -->

🔴 LIVE INVESTIGATION FEED &middot; Auto-updated &middot; Last fetch 2026-07-28

<table><tr> <td align="center"><b>📦 Domains tracked</b><br/><sub><code>5,285,286</code></sub></td> <td align="center"><b>💰 Est. revenue</b><br/><sub><code>$37,615,341</code></sub></td> <td align="center"><b>📡 Deployed</b><br/><sub><code>59.3%</code></sub></td> <td align="center"><b>✅ Confirmed phishing</b><br/><sub><code>0.1%</code> (4,429)</sub></td> <td align="center"><b>⚡ Fresh (≤7d)</b><br/><sub><code>0.4%</code></sub></td> <td align="center"><b>🕵️ Serial regs</b><br/><sub><code>1,295</code></sub></td> </tr></table>

🏷️ Top TLD Zones

| TLD | Count | Avg Reg Period | Est. Revenue | |:--|--:|--:|--:| | .com | 2,305,928 | 1,898d | $20,730,293 | | .sbs | 376,034 | 628d | $1,876,410 | | .xyz | 367,638 | 780d | $547,781 | | .net | 255,344 | 1,572d | $2,550,887 | | .info | 237,436 | 676d | $947,370 | | .org | 230,391 | 1,532d | $2,301,606 | | .cfd | 229,555 | 665d | $1,145,479 | | .click | 94,527 | 519d | $377,163 | | .link | 68,694 | 658d | $274,089 | | .vip | 68,067 | 615d | $339,654 |

🌍 Top Hosting Countries
US  ██████████████████  1,022,603 (49.2%)
DE  █████████░░░░░░░░░    514,353 (24.7%)
SG  █░░░░░░░░░░░░░░░░░     75,289 (3.6%)
HK  █░░░░░░░░░░░░░░░░░     69,416 (3.3%)
CA  ░░░░░░░░░░░░░░░░░░     56,116 (2.7%)
NL  ░░░░░░░░░░░░░░░░░░     54,589 (2.6%)
GB  ░░░░░░░░░░░░░░░░░░     41,750 (2.0%)
BG  ░░░░░░░░░░░░░░░░░░     22,153 (1.1%)
📈 Registration Burst Days

| Date | Domains | × Average | |:--|--:|--:| | 2025-07-19 | 16,692 | 35.8× 🚨 | | 2025-12-01 | 14,250 | 30.6× 🚨 | | 2026-06-30 | 13,427 | 28.8× 🚨 | | 2026-07-01 | 12,763 | 27.4× 🚨 | | 2026-06-09 | 12,384 | 26.6× 🚨 |

🎯 Top Targeted Brands & Keywords

login (11,670) &middot; support (6,493) &middot; crypto (6,110) &middot; secure (6,051) &middot; trust (5,841) &middot; connect (5,829) &middot; account (4,078) &middot; official (4,015) &middot; farm (3,460) &middot; claim (3,257) &middot; bridge (3,199) &middot; update (3,143) &middot; vault (2,393) &middot; wallet (2,139) &middot; token (1,985)

🕵️ Top Serial Registrants — 50 emails with ≥5 domains

| # | Registrant Email (redacted) | Domains | |--:|:--|--:| | 1 | chi***@mail.com | 10,485 | | 2 | diz***@992fun.com | 8,921 | | 3 | ser***@atom.com | 4,831 | | 4 | inf***@brandbucket.com | 2,314 | | 5 | sal***@brandbucket.com | 2,314 | | 6 | 992***@gmail.com | 1,692 | | 7 | diz***@91jqx.com | 1,673 | | 8 | shu***@outlook.com | 1,471 | | 9 | pri***@gmail.com | 927 | | 10 | jac***@greensock.com | 903 |

📥 Download Threat Intelligence

| File | Format | Description | |:--|:--:|:--| | `data/all.txt` | TXT | All tracked domains | | `data/index.json` | JSON | Full analytics snapshot | | `data/ioc/serial_registrants.json` | JSON | Repeat registrants + their domains | | `data/ioc/shared_ips.json` | JSON | Bulletproof hosting clusters | | `data/ioc/brand_domains.json` | JSON | Domains by targeted brand | | `data/ioc/stix-bundle.json` | STIX 2.1 | MISP/OpenCTI ready bundle | | `data/ioc/serial_emails.txt` | TXT | grep-friendly: email⇥count | | `data/ioc/shared_ips.txt` | TXT | grep-friendly: ip⇥count⇥country |

📊 Live web dashboard: see Pages link at top · Updated daily 02:00 UTC

<!-- LIVE_STATS:END -->

---

![🔴 LIVE SITE](https://phishdestroy.eth.limo/) ![Evidence Portal](https://phishdestroy.github.io/namesilo-evidence/) ![ICANN Filed](https://www.icann.org/compliance) ![MIT License](LICENSE)

<br/>

Image: README asset Image: README asset Image: README asset Image: README asset Image: README asset Image: README asset

</div>

---

<img src="https://user-images.githubusercontent.com/74038190/212284100-561aa473-3905-4a80-b561-0d28506553ee.gif" width="100%">

🕸️ Network of Complicit Registrars

This investigation is part of a series documenting ICANN-accredited registrars that systematically obstruct anti-phishing enforcement or directly profit from fraud infrastructure.

| # | Registrar | IANA | Zone | Confirmed Malicious | Russian Connection | Investigation | |--|--|--|--|--|--|--| | 1 | NICENIC INTERNATIONAL GROUP | #3765 | 349,376 | 18,927 (50% of alive) | 🇷🇺 #2 hosting country (8.5%) | nicenic-evidence · Live Report | | 2 | Trustname.com / Fewmoretaps ÖÜ | #4318 | 9,343 | 1,114 HIGH (86% alive) | 🇷🇺 Russian-operated, Estonian shell | trustname-evidence · Live Report | | 3 | NameSilo, LLC (this) | #1479 | 5,251,494 | 183,419 | 🇷🇺 Russian team members, suppression campaign | namesilo-evidence · Live Report |

---

🇷🇺 Russian Connection & Complicity Record

Russian Presence — The Team Behind the "American" Registrar

NameSilo LLC is registered in Phoenix, Arizona. NameSilo Technologies Corp is listed on the Canadian Securities Exchange (CSE: BZI via Brisio Innovations). But the actual engineering team is a Russian/CIS outsourcing operation spread across Russia, Belarus, Ukraine, Serbia, Argentina, and Latvia. At least 13+ Russian-speaking employees have been identified in the current and recent team:

| Person | Role | Location | Previous Employment | |--|--|--|--| | 🚨 Mikhail Chudinov | DevOps — full infrastructure access | Argentina (crypto relocation) | Head of IT at SuperKopilka (Russian financial pyramid, collapsed 2017, ~10 years tenure); COO at AtomX.online (crypto); Poker Club Manager | | 🇷🇺 Ivan Borzenkov | PHP Backend Developer | Bryansk, Russia (+7 920 602-0…) | TrafficStars (adult/affiliate ad network, grey adtech, Latvia); Skyeng; AdMe.ru | | 🇷🇺 Vladimir Voskov | Project Development Manager | Moscow, Russia | Zyfra Company (Russian industrial automation, state contracts); АНО Ассоциация участников технологических кружков | | 🇷🇸 Tatiana Labutina | Senior Project Manager | Belgrade, Serbia (post-2022 Russian relocation hub) | ForexClub Libertex (Russian forex broker, regulatory scandals); Social Quantum (Russian gamedev, St. Petersburg); Avatarico | | 🇧🇾 Aleksey Podashevskiy | Frontend Developer | Belarus (sanctioned jurisdiction) | Working for a US registrar from a sanctioned country raises OFAC compliance questions | | 🇷🇺 Konstantin Gorokhov | Backend Developer | Miami, FL (relocated from Russia) | CS Specialist at NameSilo 2019–2021, promoted to backend | | 🇺🇦 Volodymyr Pohodaiev | Software Engineer | New York (relocated) | Adsimilate Marketing (affiliate marketing, grey area); FinditQuick.com |

The DevOps engineer who holds keys to all NameSilo infrastructure built IT systems for a Russian financial pyramid for 10 years. The PHP developer came from an adult ad network. Project managers sit in Moscow and Belgrade. The frontend developer works from sanctioned Belarus. This is not an American technology company. This is a CIS outsourcing operation with a US mailing address.

This explains everything:

  • Why abuse reports are ignored — the team doing the ignoring shares the operator's language and culture
  • Why the suppression playbook matches Russian cybercrime patterns
  • Why a DMCA takedown request targeting coverage of xmrwallet was filed from Russia
  • Why 20+ complaints from international victims and security researchers produced zero action

When you staff your "American registrar" with people whose previous jobs include financial pyramids, adult ad networks, and Russian state-connected companies — you get exactly the kind of registrar that protects a $100M+ phishing operation and calls it "customer service."

NameSilo's PrivacyGuardian privacy-shield service covers hundreds of thousands of domains. Analysis of PrivacyGuardian-shielded domains reveals systematic use by Russian-speaking fraud networks, crypto-drainer operators, and carding infrastructure.

Documented Obstruction
  • Offered to clear VirusTotal detections for xmrwallet[.]com operator instead of suspending the domain — direct operational assistance to an active fraud campaign.
  • Blacklisted researchers who filed abuse reports, cutting off future reporting channels.
  • Suppressed media coverage — coordinated deletion of tweets, articles, and references documenti