
Google says attackers compromised third-party operators tied to the country-code top-level domains for Ghana (.GH), Sierra Leone (.SL) and American Samoa (.AS) and then modified authoritative DNS records. With control of the DNS, they could point domains at infrastructure they controlled and ask certificate authorities for valid HTTPS certificates, since a CA typically proves ownership by checking a TXT record the requester publishes. According to BleepingComputer and The Hacker News, the result was unauthorized certificates for several Google domains and hijacked domains of other organizations in those three registries, which would let an attacker impersonate legitimate brands and serve visitors arbitrary content.
Google stresses the attack “did not involve a compromise of Google’s systems” and that it has no reason to believe the issuing CAs acted improperly. It blocked the unauthorized certificates in Chrome through CRLSets, worked with the issuers to revoke them, and, after reviewing Certificate Transparency logs, blocked additional certificates linked to the attacks that covered “several leading global brands and widely used online services.” Google warns it may not have found every affected domain, and that CRLSets only protect Chrome users, so other browsers may not be covered. The announcement did not name the attackers or say how many certificates were involved.
How to check if you’re affected
Affected products are domains registered under .GH, .SL and .AS, plus any brand whose certificates were issued while those DNS records were hijacked. Chrome users need to take no action. If you own domains, Google recommends:
- Monitor Certificate Transparency logs for your entire domain portfolio, including parked domains, and look for certificates you did not request.
- Publish restrictive Certification Authority Authorization (CAA) records limiting issuance to your authorized ACME accounts and validation methods. CAA cannot stop issuance during an active DNS hijack, but it blocks obtaining further certificates from cached domain validation after you regain legitimate control of your DNS.
Sources
- Chrome’s response to recent ccTLD registry hijacks — Google Security Blog
- Chrome’s response to recent ccTLD registry hijacks — Let’s Encrypt community forum
- Hackers hijack Google domains after breaching ccTLD registries — BleepingComputer
- Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains — The Hacker News
