The company said the attacks also affected domains of other organizations in those ccTLDs but "did not involve a compromise of Google's systems." By gaining access to DNS records, the threat actor could point affected domains to infrastructure it controlled and request valid TLS certificates from certificate authorities (CAs), which issued them after the hijacked DNS records appeared to verify ownership. This allowed the attacker to impersonate legitimate brands and serve visitors arbitrary content.
Google said it immediately blocked the unauthorized certificates for its properties in Chrome through CRLSets, an emergency mechanism for quickly blocking revoked or untrusted certificates, and worked with issuing authorities to revoke them, extending protection to other clients. After examining Certificate Transparency (CT) logs, the company blocked additional certificates it believes were connected to the attacks and notified affected organizations where possible.
"Following our initial mitigation, Certificate Transparency (CT) log data revealed additional organizations, including several leading global brands and widely used online services, believed to have been impacted by the same attacks," Google explained. "To ensure users of those sites were kept safe as soon as possible, we proactively blocked these certificates in Chrome."
Google warned that it may not have identified every affected domain, and that CRLSets only protects Chrome users. "Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users," the company said.
It advised domain owners to monitor CT logs across their entire domain portfolio, including parked domains, and to publish restrictive Certification Authority Authorization (CAA) records. CAA records cannot stop certificate issuance during an active DNS hijack, but they prevent attackers obtaining additional certificates using cached domain validation after legitimate DNS control is restored, Google noted.
The announcement did not identify the attackers or the number of certificates involved.