Attackers hijacked three country-code top-level domains (ccTLDs) and used the compromised DNS control to obtain unauthorized HTTPS certificates for several Google and YouTube domains, Google said on October 6.

The affected ccTLDs were .gh for Ghana, .sl for Sierra Leone, and .as for American Samoa. Google said its own systems were not breached, but domains using those extensions were placed at risk. With a valid HTTPS certificate, an attacker could potentially impersonate a legitimate website over an encrypted connection and intercept information sent to it.

Chrome responded by blocking the unauthorized certificates through CRLSets, Google’s mechanism for quickly revoking trust in certificates during emergencies. Google also worked with the certificate authorities that issued the certificates to have them revoked, helping protect users of other browsers and applications.

Google did not identify the affected domains, but Certificate Transparency logs provide a public record of certificates issued by certificate authorities. Those records show at least 12 certificates issued between September 22 and September 27 for Google and YouTube domains using the three compromised ccTLDs. The certificates included names such as google.com.gh, google.sl and google.as.

HTTPS certificates can be issued after an applicant proves control of a domain, such as by changing a DNS record. According to Google, the attackers changed authoritative DNS records during the domain hijacks, allowing them to pass the domain-control checks. Google said there was no reason to believe the certificate authorities involved acted improperly.

READ
26-Year-Old in China Suspected of Using AI in South Korea Bank Hacks

The Hacker News identified the 12 certificates through Certificate Transparency search services. They covered seven domains, with Let’s Encrypt issuing 11 certificates and ZeroSSL issuing one. The certificates appeared in CT logs on September 22 for .gh domains, September 25 for .sl domains and September 27 for .as domains.

Among the certificates were ones covering google.com.gh, youtube.com.gh, google.sl, google.com.sl, youtube.sl, google.as and youtube.as. All were domain-validated certificates, meaning they were issued after the applicant successfully demonstrated control over the relevant domain.

Let’s Encrypt confirmed that certificates for Google and YouTube domains had been issued during the hijacks and were later revoked. The available records show that certificates for the .gh domains were revoked on September 26, while most of the certificates involving .sl and .as domains were revoked on October 1.

Google said its investigation also found evidence that other organizations may have been affected by the same DNS hijacking activity, including major global brands and widely used online services. The company did not identify those organizations or disclose how the three ccTLD registries were compromised.

Google said it learned about the hijacks the week before publishing its October 6 warning and responded immediately. Chrome also blocked certificates associated with other organizations when they were identified and contacted affected organizations where possible.

Chrome users do not need to take any action, according to Google. However, the company warned domain owners not to depend solely on browser protections because Chrome’s certificate blocks do not automatically protect users of every browser or application.

READ
KillSec Ransomware Group Targeted in International Crackdown

Google recommends that domain owners continuously monitor Certificate Transparency logs for their domains, including parked domains and regional ccTLD names. Organizations operating domains under .gh, .sl or .as should pay particular attention to certificates they did not request.

Domain owners should also publish strict Certification Authority Authorization (CAA) records in DNS. CAA records specify which certificate authorities are permitted to issue certificates for a domain. Google recommends linking CAA authorization to the organization’s account at the selected certificate authority when supported.

However, CAA records cannot completely prevent certificate issuance during an active DNS hijacking. An attacker controlling authoritative DNS could potentially remove or modify the CAA record. Once legitimate DNS control is restored, a strict CAA record can help prevent attackers from obtaining additional certificates.

Domain owners should also report unauthorized certificates to the certificate authority that issued them. Under the CA/Browser Forum’s requirements, certificate authorities must investigate certificate problem reports and provide initial findings within the required timeframe.

The incident also highlights the risk created when certificate authorities reuse previous domain-control validations. Under current rules, a CA can reuse a completed domain validation for a limited period, meaning an attacker who successfully proves domain control during a DNS hijack could potentially request another certificate after the hijack has ended. Strict CAA records can help reduce that risk.


Buy ExpressVPN with PayPal or Credit Card

Google said all seven domains identified in its investigation had strict CAA records by October 7, with Google Public DNS showing only Google Trust Services as an authorized certificate authority.

READ
OpenAI Pays $300 for Sandbox Escape Research Linked to Responses API

Google has not said whether the unauthorized certificates were actually used to impersonate Google or YouTube websites or to intercept user information. It also has not disclosed who carried out the attacks, how the ccTLD registries were compromised, or whether all of the affected registries have been fully secured.

Advertisement