Hackers hijack Google domains after compromising ccTLD operators

· Original article ↗

Summary

Attackers compromised third-party operators for the .GH, .SL, and .AS domains, altered DNS records, and obtained unauthorized HTTPS certificates. Google blocked certificates in Chrome and says its systems were not compromised.

Key points

  • Attackers compromised third-party operators for Ghana’s .GH, Sierra Leone’s .SL, and American Samoa’s .AS domains, then modified authoritative DNS records.
  • The DNS changes enabled unauthorized HTTPS certificates and allowed attackers to direct affected domains to infrastructure they controlled.
  • Google says its systems were not compromised; affected domains included Google properties and other organizations.
  • Google blocked certificates in Chrome using CRLSets and worked with certificate issuers to revoke them; it also identified and blocked additional potentially related certificates.
  • Google says it may not have identified every affected domain, and Chrome’s protections may not cover users of other browsers.
  • Google recommends domain owners monitor Certificate Transparency logs and publish restrictive CAA records.

Article Details

Victim Organization
Third-party operators of the .GH, .SL, and .AS ccTLDs; affected domain owners included Google
Incident Type
Third-party operator compromise, authoritative DNS hijacking, and unauthorized HTTPS certificate issuance
Operational Impact
Attackers modified authoritative DNS records to direct affected domains to attacker-controlled infrastructure and obtain valid certificates. Google blocked unauthorized certificates for its properties and additional certificates linked to the attacks in Chrome. Google said its systems were not compromised and warned that not every affected domain may have been identified.
Claim Status
confirmed

Vendors

Products

Countries

Related Articles