Overview of ccTLD Registry Compromise
Attackers successfully compromised three country-code top-level domains (ccTLDs) to acquire unauthorized HTTPS certificates for multiple Google domains, according to The Hacker News. While Google’s internal infrastructure remained uncompromised, the threat actors targeted the top-level registries for .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa). By altering authoritative Domain Name System (DNS) records during the hijacks, the operators convinced Certificate Authorities (CAs) that they controlled the targeted domains, enabling the generation of domain-validated certificates.
Certificate Transparency (CT) logs revealed at least 12 unauthorized certificates issued between September 22 and 27 for Google and YouTube names, including google.com.gh, google.sl, and google.as. Let’s Encrypt issued 11 of these certificates, while ZeroSSL issued one. Although Google’s own CA, Google Trust Services, typically manages these records, the registry-level manipulation diverted validation checks to the attackers.
Technical Analysis and Certificate Lifecycle
The attack unfolded across three distinct dates in late September, aligning with the sequential targeting of each ccTLD registry:
- September 22:
.ghcertificates logged and subsequently revoked on September 26. - September 25:
.slcertificates logged. - September 27:
.ascertificates logged.
In total, 12 certificates covered seven distinct domains. Because these were standard domain-validated certificates, the CAs followed normal validation procedures by confirming domain control via DNS. The attackers achieved this control temporarily by tampering with the authoritative DNS servers of the respective ccTLDs. Let’s Encrypt staff confirmed on their community forum that the certificates were issued during the incidents and noted that all associated artifacts have since been revoked.
Google stated that CT logs indicate additional global brands and widely used online services were targeted in the same campaign. The search giant utilized its Chrome CRLSets mechanism to rapidly block the unauthorized certificates in transit, while working alongside the affected CAs to achieve full revocation across the wider ecosystem.
Mitigation and Defense Strategies
Defenders and domain administrators must recognize that browser-level protections and emergency blocklists do not eliminate the underlying risk posed by registry-level DNS tampering. Security teams managing international or country-code domains should prioritize the following actions:
- Deploy Strict CAA Records: Implement Certificate Authority Authorization (CAA) DNS records restricting certificate issuance exclusively to authorized CAs (such as
pki.googfor Google properties). This prevents attackers from obtaining subsequent certificates even if a domain check reuse window remains active. - Monitor Certificate Transparency Logs: Utilize monitoring tools and services such as Cert Spotter or ctlogs.dev to audit newly issued certificates for organizational domains continuously.
- Audit Registry Access Controls: Ensure that domain registries and registrars enforce multi-factor authentication, registry locks, and strict verification protocols to prevent unauthorized DNS record modifications.
Related: Public Wi-Fi DNS Hijacking: Credential Theft Risk, CubePilot DNS Hijacking: How Attackers Intercepted UAV Flight Data