Hackers hijack Google domains in attack on country-code registries

Unauthorized TLS certificates obtained for .GH, .SL and .AS domains after DNS records altered

By LineZotpaper
Published
Read Time2 min
Google has revealed that hackers obtained unauthorized HTTPS certificates for several of its domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa and Sierra Leone, after breaching third-party operators and modifying authoritative DNS records.

The company said the attacks also affected domains of other organizations in those ccTLDs but "did not involve a compromise of Google's systems." By gaining access to DNS records, the threat actor could point affected domains to infrastructure it controlled and request valid TLS certificates from certificate authorities (CAs), which issued them after the hijacked DNS records appeared to verify ownership. This allowed the attacker to impersonate legitimate brands and serve visitors arbitrary content.

Google said it immediately blocked the unauthorized certificates for its properties in Chrome through CRLSets, an emergency mechanism for quickly blocking revoked or untrusted certificates, and worked with issuing authorities to revoke them, extending protection to other clients. After examining Certificate Transparency (CT) logs, the company blocked additional certificates it believes were connected to the attacks and notified affected organizations where possible.

"Following our initial mitigation, Certificate Transparency (CT) log data revealed additional organizations, including several leading global brands and widely used online services, believed to have been impacted by the same attacks," Google explained. "To ensure users of those sites were kept safe as soon as possible, we proactively blocked these certificates in Chrome."

Google warned that it may not have identified every affected domain, and that CRLSets only protects Chrome users. "Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users," the company said.

It advised domain owners to monitor CT logs across their entire domain portfolio, including parked domains, and to publish restrictive Certification Authority Authorization (CAA) records. CAA records cannot stop certificate issuance during an active DNS hijack, but they prevent attackers obtaining additional certificates using cached domain validation after legitimate DNS control is restored, Google noted.

The announcement did not identify the attackers or the number of certificates involved.

§

Analysis

Why This Matters

  • The attack struck the trust foundations of the web: registry-level DNS records and the certificate system that proves a site is genuine.
  • With valid TLS certificates in hand, attackers could impersonate well-known brands and serve fake content that browsers would not flag as suspicious.
  • Google's response is necessarily partial; it may not have found every affected domain, and its blocking lists only protect Chrome users.

Background

TLS certificates are how browsers verify that a connection to a website is authentic. Certificate authorities issue them after checking that the requester controls the domain, typically by asking the requester to create a specific DNS record. Country-code top-level domains such as .GH, .SL and .AS are administered by registry operators, and their authoritative DNS records decide where those domains point. An attacker who can alter those records can satisfy a CA's ownership check and obtain certificates for domains they do not control.

Key Perspectives

Google: States its own systems were not compromised, and says it moved quickly to block the unauthorized certificates in Chrome, revoke them through the issuing authorities and notify affected organizations. Affected organizations and domain owners: Google warns it cannot guarantee it found every affected domain, and urges owners to monitor CT logs across their whole domain portfolio and publish restrictive CAA records. Users of other browsers: CRLSets covers only Chrome users, so people using other browsers may not be protected by the current blocking lists.

What to Watch

  • Further disclosures about which other organizations were affected and how many unauthorized certificates were issued.
  • Whether investigators identify the attackers or link the operation to a known threat group.
  • Whether registry operators in other ccTLDs tighten access controls and monitoring in response to the breach.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.