Google domains at risk in global ccTLD registry hijacks

Attackers who compromised the country-code top-level domain registries for Ghana (.gh), Sierra Leone (.sl) and American Samoa (.as) recently used that access to mint unauthorized HTTPS certificates for several Google domains and sites run by other organizations[3][1][8]. Google says its internal infrastructure was not breached, but any domain ending in .gh, .sl or .as was temporarily at risk of being redirected to attacker-controlled servers and presented with seemingly valid TLS certificates[3][5][14]. The incident, which Google disclosed publicly this week, highlights how weaknesses at the registry level can ripple directly into the web’s trust ecosystem, even when major providers maintain strong security on their own systems[3][1][4].

According to Google’s Chrome Secure Web and Networking team, the hijacks were discovered last week and traced back to compromises of third-party operators responsible for the three ccTLDs, rather than Google or individual registrants[3][1]. Reviews of Certificate Transparency logs have identified at least a dozen unauthorized certificates issued between September 22 and 27 for Google and YouTube hostnames such as google.com.gh, google.sl and google.as[7][11][12]. Investigators report that the certificates were issued by mainstream certificate authorities including Let’s Encrypt and ZeroSSL after the attackers altered authoritative DNS records to satisfy automated domain control checks[11][5][4].

Immediately after learning of the incident, Google blocked the counterfeit certificates for its own properties in Chrome by adding them to CRLSets and coordinated with the issuing certificate authorities to revoke them globally[3][1][10]. Security advisories note that all identified unauthorized certificates covering Google domains have now been revoked, reducing the window in which attackers could have used them for man-in-the-middle attacks or phishing[12][11][6]. Multiple reports emphasise that while certificate issuance and DNS manipulation have been confirmed, there is currently no public evidence tying the hijacks to specific threat actors or documenting large-scale abuse of the forged certificates against end users[4][5][14].

Google and independent researchers describe the incident as a registry-level compromise in which attackers gained control over the systems that manage DNS for the affected ccTLDs, then changed name server records for selected domains to point at infrastructure they controlled[3][5][8]. Because most certificate authorities rely on DNS-based domain validation, that control allowed the hijackers to pass standard checks and obtain trusted certificates without the knowledge or consent of the legitimate domain owners[11][4][15]. None of the public write-ups or advisories reference CVE identifiers or product-specific security flaws, underscoring that the weakness exploited here lies in operational controls at registry operators and in the broader PKI trust model rather than in a single software bug[3][1][5].

In its guidance, Google urges owners of domains under .gh, .sl and .as to review Certificate Transparency logs for unexpected certificate issuance on their namespaces and to continue monitoring for suspicious entries over time[3][1][6]. The company also recommends publishing restrictive Certification Authority Authorization (CAA) DNS records to limit which certificate authorities can issue for a domain and to provide an additional safeguard if DNS control is ever regained by attackers or misconfigured[3][11]. Beyond the affected ccTLDs, security teams are advising organizations to treat registry access and DNS configuration as critical assets, enforce strong authentication for registrar and registry accounts, and deploy DNSSEC where available to reduce the risk of similar attacks in other country-code or generic TLDs[5][14][8].

References

  1. Google Domains Impacted by Recent ccTLD Hijacks
  2. Chrome’s Response to Recent ccTLD Registry Hijacks
  3. Attackers Hijack .gh, .sl, and .as Registries to Obtain …
  4. Hackers hijack three country-code domain registries, …
  5. Hackers Impersonate Google and Other Large Services …
  6. Google: attackers hijacked the .gh, .sl and .as country-code domain registries, changed DNS for selected domains and obtained unauthorised HTTPS certificates for several Google domains and other major brands; Chrome blocked them via CRLSets
  7. Hackers hijack Google domains after breaching ccTLD …
  8. Hackers Used Hijacked Country Domains to Forge Real Google …
  9. ccTLD hijack: unauthorised certificates for Google domains
  10. Attackers Hijack Three Country-Code Registries to Obtain Unauthorized Google Certificates
  11. Attackers Hijack Three ccTLDs to Obtain Google Certificates
  12. DNS Hijacks at .gh, .sl and .as Minted Trusted Google …

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply