FILEMembers
FILE

Old Baixaki Typosquat Cluster Resurfaces via Unrelated 2026 CDN Certificate

A 2012-registered typosquat domain cluster mimicking Brazil's Baixaki download portal has reappeared in threat feeds alongside a shared GlobalSign wildcard certificate on Azion CDN infrastructure. Analysts warn the pairing is a decade-wide temporal mismatch, not evidence of a live campaign.

Jun 9, 2026, 16:21 (UTC+9)Last seenJul 2, 2026Severity100ByCTX TeamIOC13MITRE33RegionsBR

Three subdomains built around the name of Brazil's largest freeware portal, all registered on the same day in October 2012 through PDR Ltd. d/b/a PublicDomainRegistry.com, have re-entered current threat telemetry paired with an unrelated certificate observation on a commercial Brazilian CDN more than a decade later — a pairing that illustrates how stale infrastructure and fresh re-observation timestamps can be mistaken for a live campaign if analysts don't check the dates.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence