Attackers hijack .gh, .sl and .as registries to get certificates for Google domains

Google says attackers took over the operators of three country-code domains and obtained unauthorized HTTPS certificates for Google, YouTube and other organizations' domains.

Attackers hijack .gh, .sl and .as registries to get certificates for Google domains

At a glance

  • Attackers compromised third-party operators of the .gh, .sl and .as country-code domains and altered authoritative DNS records.
  • The Hacker News found 12 unauthorized certificates for seven Google and YouTube domains, 11 from Let's Encrypt and one from ZeroSSL, all now revoked.
  • Chrome blocked the certificates via CRLSets, but Google warns this does not reliably protect users of other browsers.
  • Domain owners are urged to monitor Certificate Transparency logs and publish strict CAA records.

Attackers took control of the registries behind three country-code top-level domains, Ghana's .gh, Sierra Leone's .sl and American Samoa's .as, and used that access to obtain unauthorized HTTPS certificates for Google domains and those of other large organizations, Google disclosed on October 6. According to Help Net Security, the attackers compromised the third-party operators of the registries and changed authoritative DNS records, which put every domain under those endings at risk.

What happened

Google said it learned of the hijacks the week before its disclosure and that the incidents "did not involve a compromise of Google's systems." The company also said it has no reason to believe the certificate authorities that issued the certificates did anything wrong: once the attackers controlled DNS, they could pass standard domain-control validation.

Google did not say how the registries were compromised, who was behind the attacks, or whether any certificate was actually used to impersonate a site or intercept traffic, both outlets noted.

Technical details

By checking Certificate Transparency (CT) logs, The Hacker News identified 12 domain-validated certificates covering seven domains: youtube.com.gh, google.com.gh, google.sl, google.com.sl, youtube.sl, google.as and youtube.as. Let's Encrypt issued 11 of them and ZeroSSL one. According to the publication, the certificates were logged between September 22 and 27, with .gh names appearing first, .sl on September 25 and .as on September 27. Three were revoked on September 26 and the remaining nine on October 1.

Google said the true total may be higher and that CT data revealed other affected organizations, including several large global brands and popular online services, which it did not name.

Who is affected

Chrome blocked the unauthorized certificates through CRLSets, the revocation list it downloads in the background, and Google said Chrome users do not need to take action. However, the company cautioned that Chrome's interventions do not reliably protect users of other browsers and that it "cannot guarantee" its analysis found every affected domain.

What to do

Organizations with domains under .gh, .sl or .as should verify their DNS records and issued certificates. The Hacker News recommends monitoring CT logs for all owned domains, including parked and regional names; publishing a strict CAA record listing permitted certificate authorities; and reporting any unrequested certificate to the issuing CA, which must investigate within 24 hours under industry rules. The publication noted that CAA records cannot stop issuance during an active DNS hijack but matter once control is restored, because CAs may reuse earlier domain validation. Google said it will continue pushing for shorter certificate lifetimes and reduced validation reuse through the Chrome Root Program.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.