In a concerning development for internet security, attackers have compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, according to a statement from Google on October 6. The affected TLDs are .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa). While Google's own systems were not breached, any domain ending in these extensions was left vulnerable to interception and impersonation.

The incident highlights a critical weakness in the certificate issuance process: the reliance on domain registry operators to validate control over a domain. By hijacking the registries for these ccTLDs, attackers were able to manipulate DNS records and prove control over Google-owned domains under those TLDs, such as google.gh, google.sl, and google.as. With that control, they obtained valid TLS certificates from a certificate authority (CA). Such certificates would allow an attacker to impersonate the legitimate site over an encrypted connection, potentially intercepting sensitive data or spreading malware.

How the Attack Unfolded

According to Google, the attackers gained unauthorized access to the registry systems that manage the .gh, .sl, and .as TLDs. These registries are responsible for maintaining the authoritative DNS records for all domains under their respective TLDs. By compromising the registries, the attackers could alter DNS records to point Google's domains to servers they controlled. They then used this control to pass the domain validation checks required by CAs to issue certificates.

Google did not disclose the specific method used to compromise the registries, but such attacks often involve social engineering, credential theft, or exploitation of vulnerabilities in registry infrastructure. The company emphasized that its own systems were not breached; the issue lies with the third-party registries.

Impact and Response

Google has notified the affected registries and the certificate authorities involved. The unauthorized certificates have been revoked, and Google is working with the registries to secure their systems. However, the incident raises questions about the trust model of the web PKI, where CAs must verify domain control. If a registry is compromised, the entire TLD becomes a weak link.

Users of domains under .gh, .sl, and .as should be cautious. While Google's domains are the known targets, other domains under these TLDs could also be at risk if the attackers maintain persistence. Google recommends that users verify the certificate of any site they visit under these TLDs and avoid entering sensitive information if the certificate appears suspicious.

Broader Implications

This is not the first time ccTLD registries have been targeted. In recent years, attackers have increasingly focused on the supply chain of the internet infrastructure, recognizing that compromising a registry or a CA can yield widespread impact. The incident underscores the need for stronger security measures at registries, including multi-factor authentication, regular audits, and monitoring for unauthorized changes.

For organizations, the lesson is clear: trust in the DNS and PKI systems is not absolute. Defenders should implement additional layers such as certificate pinning, DNS security extensions (DNSSEC), and monitoring for anomalous certificate issuance. Users should also be educated about the risks of clicking on links that may lead to spoofed sites.

Google's quick response in revoking the certificates is commendable, but the incident serves as a reminder that the internet's foundational systems remain vulnerable to sophisticated attacks. As the digital landscape evolves, so too must the security of the registries and certificate authorities that underpin it.

For more details, refer to the original report by The Hacker News: Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains.