Attackers Seize Three Country-Code Domains
Google’s security team has reported a recent wave of registry hijacks. Attackers took over three top-level domains: .gh for Ghana, .sl for Sierra Leone, and .as for American Samoa.
The hackers struck at the registry level and gained control of many domains at once. Then they altered DNS records to request TLS certificates. Ultimately, they could use those certificates to hijack users.
How the Hijack Worked
Once in control, the attackers mainly changed DNS records to obtain TLS certificates. After a certificate was issued, they could point a domain to their own server. As a result, they could hijack traffic and decrypt it.
Google revealed that unauthorized TLS certificates appeared for the domains of several organizations, including Google itself.
No Breach at Google or the CAs
Google stressed that its internal systems were not compromised. It also sees no reason to think the certificate authorities (CAs) broke their rules.
Under current CA processes, a valid DNS record proves domain ownership. Therefore, the CAs could legitimately issue the certificates.
Chrome Blocks the Rogue Certificates
After spotting the incident, Google used the Chrome CRLSet mechanism to block a large number of identified unauthorized certificates. At the same time, it contacted the relevant CAs to revoke them. That step protects other browsers and clients.
Google then analyzed Certificate Transparency logs. It found that several global brands and popular online services may also be affected. Consequently, users who visit those sites may see Chrome’s warning screen.
What Google Did Not Disclose
Google did not name the affected companies or services, nor did it share the number of certificates. It said DNS hijacking is very complex, so it cannot guarantee it found every affected domain.
Moreover, browser-side blocking cannot reliably protect people who do not use Chrome. Domain owners should check their certificates and DNS records. If they find anything unusual, they should remove it promptly.
How to Monitor Certificate Issuance
Owners of .gh, .sl, and .as domains can visit crt.sh to look up certificates issued for their domains. If they find a certificate they did not request, they should contact the issuing CA quickly to revoke it. This stops attackers from using the certificate to hijack users.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!