
Old Baixaki Typosquat Cluster Resurfaces via Unrelated 2026 CDN Certificate
A 2012-registered typosquat domain cluster mimicking Brazil's Baixaki download portal has reappeared in threat feeds alongside a shared GlobalSign wildcard certificate on Azion CDN infrastructure. Analysts warn the pairing is a decade-wide temporal mismatch, not evidence of a live campaign.
Three subdomains built around the name of Brazil's largest freeware portal, all registered on the same day in October 2012 through PDR Ltd. d/b/a PublicDomainRegistry.com, have re-entered current threat telemetry paired with an unrelated certificate observation on a commercial Brazilian CDN more than a decade later — a pairing that illustrates how stale infrastructure and fresh re-observation timestamps can be mistaken for a live campaign if analysts don't check the dates.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read