APTMembers
APT

A Shopify Wildcard Certificate Is Serving DarkSide's Command Channel

A domain registered in February 2026, baroquetees.com, is flagged by a high-severity IDS rule as DarkSide ransomware C2 — but its TLS certificate carries Shopify's own wildcard namespace and an issuance date over a year before the domain existed. CTX Team treats the timeline break as an open finding, not a resolved one.

Sep 5, 2026, 14:28 (UTC+9)Last seenSep 5, 2026Severity82ByCTX TeamActorDarksideGold WaterfallIOC4MITRE35RegionsRO

The freshest piece of this investigation is not the ransomware payload — it is the domain answering for it. baroquetees.com, registered on 2026-02-19 through TUCOWS.COM, CO., resolves to a single IP address, 23.227.38.71, behind Google Cloud DNS name servers (ns-cloud-a1 through ns-cloud-a4.googledomains.com). Its most recently observed TLS certificate, issued by Cloudflare TLS Issuing ECC CA 1, does not carry baroquetees.com in its subject or SAN fields at all.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence