Attackers Hijack Three ccTLDs to Obtain Google Certificates

Written by

Attackers have compromised three country-code top-level domain (ccTLD) registries and obtained unauthorized HTTPS certificates covering several Google domains and sites belonging to other organizations.

The incidents affected the .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) namespaces, according to a post published by Google's Chrome Secure Web and Networking Team on October 6. The attackers modified authoritative Domain Name System (DNS) records during the hijacks, putting domains under the three ccTLDs at risk.

Google said the incidents did not involve a compromise of its own systems and that it had no reason to believe the certificate authorities (CAs) that issued the affected certificates had acted improperly.

Chrome Blocks Unauthorized Certificates

Chrome responded by blocking the unauthorized certificates for Google properties through CRLSets, the mechanism Chrome uses to quickly block certificates in emergencies.

Google also worked with the issuing CAs to revoke the certificates so that users of other clients would be protected. Certificate Transparency (CT) logs subsequently revealed additional organizations that Google believed had been affected, including several leading global brands and widely used online services.

Google proactively blocked those certificates in Chrome and said it contacted affected organizations where possible. The company did not identify the additional organizations or disclose how many certificates were obtained.

Google said browser-side blocking should not be relied on because its analysis may not have identified every affected domain and Chrome's interventions do not reliably protect non-Chrome users.

Read more on DNS hijacking: US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers

DNS Control Creates Certificate Risk

The incidents demonstrate how a compromise of DNS infrastructure can affect HTTPS trust without directly breaching a website's own systems. By controlling authoritative DNS records, attackers can interfere with the domain-control process used when certificates are issued.

Google recommended that domain owners continuously monitor CT logs across their entire domain portfolios, including parked and regional ccTLD properties. Organizations operating .gh, .sl or .as domains should review recent CT entries for unexpected certificate issuance.

Google also recommended restrictive Certification Authority Authorization (CAA) records with Automatic Certificate Management Environment (ACME) account bindings. While CAA cannot prevent certificate issuance during an active DNS hijack, the company said restoring a restrictive policy afterward stops attackers from reusing cached domain-control validation checks to obtain new certificates.

Google said it will continue working on broader HTTPS ecosystem changes, including reducing certificate validity periods and the reuse of domain-control validation.

What’s Hot on Infosecurity Magazine?