# ccTLD Hijacks Force Unauthorized Google HTTPS Certificates

> Attackers hijacked .gh, .sl, and .as registries to obtain unauthorized HTTPS certificates for Google domains via DNS manipulation.

- Published: 2026-10-07T20:55:24.000Z
- Severity: medium
- Category: Threat Intel
- Tags: DNS Hijacking, Certificate Authority, Let S Encrypt, ZeroSSL, Certificate Transparency
- Author: Runtime Rebel Intel
- Primary source: https://thehackernews.com/2026/10/attackers-hijack-gh-sl-and-as.html
- Canonical: https://runtimerebel.com/blog/cctld-hijacks-force-unauthorized-google-https-certificates

## Key points

- Attackers compromised country-code top-level domains to obtain fraudulent HTTPS certificates for Google and other global brands.
- Domains ending in .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) were exploited during the registry hijacks.
- Domain owners must implement strict CAA records to prevent unauthorized certificate issuance after DNS restoration.

## Overview of ccTLD Registry Compromise

Attackers successfully compromised three country-code top-level domains (ccTLDs) to acquire unauthorized HTTPS certificates for multiple Google domains, according to [The Hacker News](https://thehackernews.com/2026/10/attackers-hijack-gh-sl-and-as.html). While Google's internal infrastructure remained uncompromised, the threat actors targeted the top-level registries for `.gh` (Ghana), `.sl` (Sierra Leone), and `.as` (American Samoa). By altering authoritative Domain Name System (DNS) records during the hijacks, the operators convinced Certificate Authorities (CAs) that they controlled the targeted domains, enabling the generation of domain-validated certificates.

Certificate Transparency (CT) logs revealed at least 12 unauthorized certificates issued between September 22 and 27 for Google and YouTube names, including `google.com.gh`, `google.sl`, and `google.as`. Let's Encrypt issued 11 of these certificates, while ZeroSSL issued one. Although Google's own [CA](/glossary#certificate-authority-ca), Google Trust Services, typically manages these records, the registry-level manipulation diverted validation checks to the attackers.

## Technical Analysis and Certificate Lifecycle

The attack unfolded across three distinct dates in late September, aligning with the sequential targeting of each ccTLD registry:

* **September 22:** `.gh` certificates logged and subsequently revoked on September 26.
* **September 25:** `.sl` certificates logged.
* **September 27:** `.as` certificates logged.

In total, 12 certificates covered seven distinct domains. Because these were standard domain-validated certificates, the CAs followed normal validation procedures by confirming domain control via DNS. The attackers achieved this control temporarily by tampering with the authoritative DNS servers of the respective ccTLDs. Let's Encrypt staff confirmed on their community forum that the certificates were issued during the incidents and noted that all associated artifacts have since been revoked.

Google stated that CT logs indicate additional global brands and widely used online services were targeted in the same campaign. The search giant utilized its Chrome CRLSets mechanism to rapidly block the unauthorized certificates in transit, while working alongside the affected CAs to achieve full revocation across the wider ecosystem.

## Mitigation and Defense Strategies

Defenders and domain administrators must recognize that browser-level protections and emergency blocklists do not eliminate the underlying risk posed by registry-level DNS tampering. Security teams managing international or country-code domains should prioritize the following actions:

* **Deploy Strict CAA Records:** Implement Certificate Authority [Authorization](/glossary#authorization) (CAA) DNS records restricting certificate issuance exclusively to authorized CAs (such as `pki.goog` for Google properties). This prevents attackers from obtaining subsequent certificates even if a domain check reuse window remains active.
* **Monitor Certificate Transparency Logs:** Utilize monitoring tools and services such as Cert Spotter or ctlogs.dev to audit newly issued certificates for organizational domains continuously.
* **Audit Registry Access Controls:** Ensure that domain registries and registrars enforce multi-factor authentication, registry locks, and strict verification protocols to prevent unauthorized DNS record modifications.

**Related:** [Public Wi-Fi DNS Hijacking: Credential Theft Risk](/blog/public-wi-fi-dns-hijacking-credential-theft-risk), [CubePilot DNS Hijacking: How Attackers Intercepted UAV Flight Data](/blog/cubepilot-dns-hijacking-how-attackers-intercepted-uav-flight-data)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/cctld-hijacks-force-unauthorized-google-https-certificates
