Google says attackers abused .gh, .sl and .as domains to obtain certificates for its sites
According to Google, attackers who altered DNS records under the country-code domains of Ghana, Sierra Leone and American Samoa got TLS certificates for several Google domains. Chrome now blocks them; Google has not said who was behind it or how the domains were compromised.
Key points
- 1Google says attackers changed DNS records under the .gh, .sl and .as country-code domains and obtained certificates for several Google domains.
- 2Chrome blocks the certificates via CRLSets; Google says its systems were not breached and it has no reason to think the issuing CAs acted improperly.
- 3The Hacker News counted at least 12 certificates for Google and YouTube names, logged 22 to 27 September and all revoked by 7 October.
- 4Google believes other large brands and online services were hit as well, but has not named any of them.
- 5Unconfirmed: who the attackers are, how the domains were compromised, and whether any certificate was used against users.
Full story
Google said on 6 October that attackers targeted three country-code top-level domains, .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa), and changed authoritative DNS records for selected domains under them. Controlling those records let the attackers pass the automated ownership checks that certificate authorities (CAs) run before issuing a certificate, and they obtained HTTPS certificates for several Google domains. This account is based on reports by Ars Technica, BleepingComputer and The Hacker News describing Google's post; ittechwire has not reviewed the post itself.
According to those reports, Google says its own systems were not compromised, and it sees no reason to suspect the issuing CAs of acting improperly. Chrome blocked the certificates for Google's domains through CRLSets, an emergency mechanism for distrusting specific certificates quickly, and Google worked with the CAs to revoke them so that other browsers and apps are covered too. Google says Certificate Transparency (CT) logs then revealed more organizations that, in its view, the same campaign also struck, including "several leading global brands and widely used online services". It blocked those certificates in Chrome as well and notified the owners where possible, but it has named neither them nor its own affected domains.
The Hacker News says it searched CT logs on 7 October and found at least 12 certificates issued between 22 and 27 September covering Google and YouTube names on the three domains, among them google.com.gh, google.sl and google.as. By its count they cover seven domains; Let's Encrypt issued 11 and ZeroSSL one. They were logged one country domain at a time: .gh on 22 September, .sl on 25 September and .as on 27 September. The outlet reports that all 12 had been revoked by 7 October, the two .gh certificates and the ZeroSSL one on 26 September and the remaining nine on 1 October. It looked at only a small set of names, so the real number may be higher. The outlet also cites a Let's Encrypt staff member who confirmed on that CA's community forum that certificates for Google and YouTube had been issued and later revoked.
Much is still unconfirmed. According to The Hacker News, Google's post does not identify the attackers, does not explain how the country-code domains were compromised or whether they are now secure, and does not say whether any certificate was actually used to impersonate a site or capture user data. Here the reports differ: BleepingComputer writes, without attributing it to Google, that the altered records let the attacker point the domains at its own infrastructure, impersonate legitimate brands and serve visitors content of its choosing, while The Hacker News notes that Google's post is silent on any actual misuse. Ars Technica says it is not clear how many unauthorized certificates exist or whether all those for other organizations are blocked. The outlets also word the entry point differently: BleepingComputer says third-party operators were compromised, Ars Technica speaks of a compromise of three domain registries. Google itself cautions: "we cannot guarantee that our analysis identified every affected domain".
Google says Chrome users need not take any action, but it tells domain owners not to depend on browser-side blocking. It advises them to monitor CT logs for every domain they hold, parked ones included, and to publish a restrictive Certification Authority Authorization (CAA) record. Such a record cannot prevent issuance during an active DNS hijack, Google notes, but it can stop an attacker from reusing an earlier successful domain check to get more certificates once the owner has regained control. The Hacker News adds that CA rules currently allow such reuse for up to 200 days, a window scheduled to shrink to 100 days from March 2027 and 10 days from March 2029, and that anyone can report an unrequested certificate to the CA that issued it.
Why it matters
A valid certificate lets an attacker pose as a real site over an encrypted connection. According to Google, its own systems were not breached and it has no reason to think the CAs did anything wrong; control of DNS records under a country-code domain was enough to pass the standard ownership checks. Chrome's block does not reliably protect people using other browsers, and Google says its analysis may have missed domains, so CT monitoring and strict CAA records fall to domain owners. Ars Technica recalls the 2011 DigiNotar breach, when forged certificates for Google and other sites were turned against at least 300,000 people linked to Iran.
Timeline
· Published
Topics#Google#TLS certificates#DNS hijacking#Chrome#Certificate Transparency#ccTLD
Sources
This story draws on the following sources. Read them for full context.
- 1Ars Technica · News reportHackers obtain counterfeit TLS certificates for Google and other large servicesarstechnica.com
- 2BleepingComputer · News reportHackers hijack Google domains after breaching ccTLD registrieswww.bleepingcomputer.com
- 3The Hacker News · News reportAttackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domainsthehackernews.com
