Hackers Hijack .GH, .SL and .AS Domains to Obtain HTTPS Certificates for Google Properties
Hackers compromised third-party carriers and tampered with authoritative DNS records to obtain unauthorized HTTPS certificates for multiple Google domains. The attackers also hijacked domains under the country code top-level domains (ccTLDs) for Ghana (.GH), Sierra Leone (.SL), and American Samoa (.AS).
Google emphasized that the incident affected domains belonging to other organizations within the .GH, .SL, and .AS ccTLDs and did not involve a compromise of Google’s systems.
How DNS hijacking enabled certificate issuance
By gaining access to a domain’s DNS records, threat actors can request an HTTPS certificate from a certificate authority (CA) for a domain they do not own.
Certificate authorities typically verify domain ownership by requiring the requester to create a TXT record containing random values supplied by the CA. If attackers modify authoritative DNS records, they can point domains to infrastructure they control and complete the validation process.
This enabled the attackers to obtain valid TLS certificates for domains under the .GH, .SL, and .AS ccTLDs. With those certificates, an attacker can impersonate a legitimate brand and serve arbitrary content from an affected domain.
Google blocks unauthorized certificates
Google immediately blocked unauthorized certificates affecting its Chrome properties through CRLSet. The company also worked with certificate issuers to revoke the certificates and extended protections to other clients.
Google said its systems were not affected and that there was no reason to believe the issuing certificate authority acted improperly.
After examining Certificate Transparency (CT) logs, Google blocked additional certificates believed to be connected to the attack and notified affected organizations where possible.
“After initial mitigation efforts, Certificate Transparency (CT) log data revealed additional organizations believed to be affected by the same attack, including several major global brands and widely used online services,” Google explained.
“To keep users of these sites safe as quickly as possible, we actively blocked these certificates in Chrome.”
Chrome users are protected, but coverage is limited
CRLSet is a Chrome emergency mechanism designed to quickly block selected revoked or untrusted HTTPS certificates. Chrome users do not need to take any action to protect themselves from this incident.
However, Google warned that its current block list may not cover every potential threat because the company may not have identified all affected domains.
Google also reminded users that CRLSet protections apply only to Chrome users. People using other browsers may not be protected.
“Due to the complexity of DNS hijacking, we cannot guarantee that our analysis will identify all affected domains, nor will Chrome intervention reliably protect non-Chrome users,” Google said.
Google’s recommendations for domain owners
Google recommends that domain owners:
- Monitor Certificate Transparency logs across their entire domain portfolio, including parked domains.
- Publish restrictive Certificate Authority Authorization (CAA) records to limit certificate issuance to authorized ACME accounts and verification methods.
Google noted that CAA DNS records cannot stop certificate issuance during an active DNS hijacking attack. However, they can prevent attackers from using cached domain validation to obtain additional certificates after legitimate DNS control has been restored.
The announcement did not identify the attacker or disclose how many certificates were confirmed to have been hijacked.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



