Known malicious kithighother
ShadowPad-style self-signed certificate claiming a major brand (tripwire)
family: bluemoon-shadowpad-2026-09
Generalizing tripwire, not an IoC: ShadowPad C2 servers in this campaign present SELF-SIGNED TLS certificates whose subject organization impersonates a major brand. This catches infrastructure we have no indicator for yet. Indicators from Proofpoint's "Once in a BlueMoon" report (2026-09) and MISP event 22904. SMQL hunts are DETECTORS, not verdict rules: match_tier 'smql' is excluded from both engines' verdict paths by design, so this collects sightings and shows a banner. Flooring for these indicators comes from the MISP feed via ioc-matcher.
Anchors
SMQL queryrun
cert_self_signed:true AND cert_org:"Google LLC"Provenance
Added: 2026-09-12 10:36
Measured before creation: 530,253 certificates stored, 137,912 with a subject organization, 1,140 self-signed, 750 self-signed WITH an organization - so the field is populated and this can fire. The top self-signed orgs are junk defaults (Acme Co, Internet Widgits Pty Ltd, MyOrg); no brand names, so a brand-claiming self-signed cert is anomalous by construction. 0 matches at creation - it is a forward-looking tripwire.
Sightings (0)
No sightings recorded yet.