Back
Attackers Hijacked Three Country Code Domains to Forge TLS Certificates for Google and Others
SiTech AI Team3 min read

Attackers Hijacked Three Country Code Domains to Forge TLS Certificates for Google and Others

Attackers seized control of the .gh, .sl, and .as country code top-level domains and used it to obtain counterfeit TLS certificates for Google and other major services, prompting Chrome to block the unauthorized credentials.

Attackers seized control of three country code domains

Attackers hijacked the .gh, .sl, and .as country code top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, Google said Tuesday. By modifying authoritative DNS records for selected domains within those namespaces, the attackers were able to pass automated domain control validation checks and obtain unauthorized certificates for "several Google domains" and "several leading global brands and widely used online services."

Google blocked the certificates in Chrome

Google said it updated Chrome to block all certificates it identified as unauthorized and worked with the issuing certification authorities to ensure the unauthorized certificates for Google properties were revoked. The company said Chrome users do not need to take any action to be protected, but cautioned domain owners not to rely solely on browser-side interventions. Google advised domain owners to monitor certificate transparency logs for unexpected certificate issuance across their domains and to publish restrictive Certification Authority Authorization DNS records to prevent attackers from reusing cached validation data after DNS control is restored.

Scope of the incident remains unclear

Google did not identify the affected domains it owns or name any of the other organizations whose domains were affected. It is not immediately clear how many unauthorized certificates were issued or whether all of them, except for those for Google domains, have been blocked. Google noted that the incident did not involve the compromise of the infrastructure of any affected domain owner and that certificate authorities followed all requirements. With control of the three ccTLDs, the attackers changed the IP addresses of selected websites and modified authoritative DNS records and nameserver delegations, allowing them to pass industry validation checks that require an applicant to prove control of a domain.

Repeat of a known threat pattern

This is not the first time threat actors have obtained unauthorized certificates. A 2011 hack of Netherlands-based certificate authority DigiNotar allowed attackers to mint counterfeit certificates for Google.com and more than 200 other high-traffic domains, which were used against at least 300,000 people with ties to Iran. Many similar incidents have occurred since, most often through failures by certificate authorities but also by domain holders. Because the official certificate revocation process is slow and cumbersome, browser makers have devised quicker methods to block specific certificates at the browser level. With all known unauthorized certificates now blocked, the risk is mitigated, but Google noted that any certificates that remain undiscovered still pose a threat.

Sources: Arstechnica

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.