Attackers successfully hijacked several country-code top-level domains (ccTLDs) and subsequently minted fraudulent HTTPS certificates for various Google domains and those of other entities. Google confirmed it became aware of these incidents last week, specifically impacting the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) namespaces.
During these attacks, the perpetrators modified authoritative DNS records, which allowed them to obtain unauthorized HTTPS certificates. Google stated that its own systems were not compromised in the process. While Google did not specify which particular domains or organizations beyond itself were affected, it emphasized the potential for such attacks to enable impersonation without triggering standard browser security warnings.
The nature of these attacks means that an attacker could control traffic routing via DNS and possess the private key for the unauthorized certificate. This capability could allow them to intercept or modify user data intended for the legitimate site, or to leverage the trusted brand for distributing malware or conducting phishing campaigns.
Google's Chrome browser quickly implemented measures to block suspected counterfeit certificates across the affected ccTLDs, providing protection for Chrome users. However, Google cautioned domain owners against relying solely on browser-side interventions, noting that such measures might not reliably protect users of other browsers. The company also clarified that it found no indication of wrongdoing by the Certificate Authorities (CAs) that issued the impacted certificates, attributing the issue to the DNS hijacking itself.
To mitigate risks from similar attacks, Google recommends that organizations continuously monitor Certificate Transparency (CT) logs for all their domains, including parked or regional ccTLD properties. This practice provides near real-time alerts when a certificate is issued for a domain. Organizations operating domains within the .gh, .sl, or .as ccTLDs were specifically advised to review recent CT log entries for any unexpected certificates.
Additionally, Google suggests publishing restrictive Certification Authority Authorization (CAA) DNS records. These records allow domain owners to specify which CAs are authorized to issue certificates for their domains. While CAA records may not prevent certificate issuance during an active DNS hijacking, they can help secure domains once DNS control is restored. Google recommends CAA policies that limit issuance to specific authorized accounts and validation methods, thereby preventing attackers from exploiting cached validation states to mint new certificates after a hijacking concludes.






