Attackers Hijack Three Country TLDs to Forge Google Certificates

Google says attackers compromised the .gh, .sl and .as registries, altered DNS records and obtained fraudulent HTTPS certificates for Google and other domains.
Table of Contents
    Add a header to begin generating the table of contents

    Google said on Wednesday that attackers compromised the registries behind three country-code top-level domains, altered DNS records, and used that control to obtain unauthorized HTTPS certificates for Google domains and for domains belonging to other organizations.

    The three registries cover Ghana (.gh), Sierra Leone (.sl) and American Samoa (.as). Google did not name the specific domains that received counterfeit certificates, and it did not identify the other organizations that were affected.

    How Compromised Registries Produced Valid-Looking Certificates for Google

    Google said attackers gained control of the three country-code registries and changed DNS records. With that access, the attackers were then able to obtain HTTPS certificates for domains they did not own. A certificate issued this way is valid in the eyes of a browser, which means the normal warning that appears when a site presents a bad certificate does not appear.

    Google also said the attackers held the private keys for the certificates in addition to controlling DNS routing. That combination matters because it lets an attacker sit in the path of traffic for a targeted domain and present a certificate the browser accepts. Google listed interception, malware delivery and phishing under trusted brand names as the uses this position enables.

    What Google Says About the Certification Authorities

    Google stated that it has no reason to believe the Certification Authorities that issued the certificates did anything wrong. The company’s account places the failure upstream of the issuers, at the registry level, where the DNS records that issuers rely on to validate domain control were altered by the attackers.

    Scope That Google Has Not Disclosed

    Google has not said how many certificates were issued, which Google domains were affected, or which other organizations were targeted. It also did not describe how the attackers got into the three registries. The company said it became aware of the attacks the week before the public announcement, which places its discovery in late September or early October.

    Chrome Blocks the Suspected Counterfeit Certificates

    Google said Chrome now blocks the certificates it suspects are counterfeit. The company paired that statement with a warning that organizations should not depend on browser-side blocking alone, since the protection covers only the browser and only the certificates Google has identified.

    Certificate Transparency Monitoring and CAA Records

    Google urged organizations to monitor Certificate Transparency logs, the public records of issued certificates, so that a certificate issued for one of their domains without their knowledge can be spotted. It also urged them to publish restrictive CAA DNS records, which let a domain owner state which Certification Authorities may issue certificates for it.

    Both measures address the same gap the attackers exploited. A fraudulent certificate that was issued legitimately by a trusted authority can only be noticed if the domain owner is watching the logs, and it can only be narrowed in advance if the owner has restricted who may issue.

    Why Registry-Level Compromise Changes the Threat

    Most public discussion of fraudulent certificates centers on a mistake or a compromise at a Certification Authority. Google’s account describes a different route, in which the issuers behaved normally and the attackers instead took control of the DNS layer that sits above them. Because the attackers controlled routing as well as the keys, the certificates they obtained would have looked ordinary to any client that trusts the issuing authority.

    The reach of a country-code registry compounds the problem. A registry sits above every domain registered beneath it, so a compromise at that level gives an attacker influence over many names at once. Google has said only that Google and other organizations were affected, without a count, so the full extent of the exposure is unknown from the public statement.

    Google has not attributed the attacks to a named actor. The disclosure leaves open whether the three registries were compromised in a single operation or in separate ones, a question Google’s announcement did not address.

    Domain owners with a presence under .gh, .sl or .as, and any organization whose names could be targeted through a registry, now have a concrete reference for what to check: issued-certificate logs and the CAA records on their zones. Google’s guidance treats those two controls as the practical response while details of the registry intrusions remain unpublished.

    Related Posts