Attackers Hijack ccTLDs to Impersonate Google Domains
Threat actors compromised .gh, .sl, and .as domain registries to obtain fraudulent HTTPS certificates for Google services. This highlights risks in third-party certificate issuance and registry security.
TL;DR
- Attackers gained control of .gh, .sl, and .as ccTLD registries
- Used hijacked registries to issue fake certs for Google domains
- No breach of Google systems—vulnerability was in external registries
- Enables HTTPS-encrypted phishing and man-in-the-middle attacks
- Highlights need for stricter certificate authority oversight
Security researchers have uncovered a sophisticated attack where threat actors compromised the administrative controls of three country-code top-level domain (ccTLD) registries. By gaining unauthorized access to the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) domain registries, attackers were able to issue legitimate-looking HTTPS certificates for Google-owned domains.
While Google confirmed that none of its internal systems were breached, the incident demonstrates how weaknesses in external certificate authorities and domain registry processes can be exploited to enable convincing impersonation attacks. These certificates would allow malicious actors to present fake websites as legitimate Google services while maintaining the appearance of secure, encrypted connections.
Certificate Authority Vulnerabilities
- Attackers leveraged compromised ccTLD registries to request certificates through legitimate channels
- Certificates appeared valid and enabled full HTTPS encryption for spoofed Google domains
- This method bypasses traditional domain validation warnings users might expect from fraudulent sites
- Exploits trust relationships between registries, registrars, and certificate authorities
Implications for Enterprise Security
- Organizations should audit their certificate issuance processes and trusted CA lists
- Highlights importance of monitoring for unauthorized certificates issued for corporate domains
- Emphasizes need for robust multi-factor authentication on all registry and DNS provider accounts
- Demonstrates value of Certificate Transparency logs for early detection of suspicious certificates
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.