Hijacked .gh, .sl, and .as Registries Used to Obtain Rogue Certificates for Google Domains
What Happened
Google reported on October 6 that attackers compromised three country-code top-level domain (ccTLD) registries — .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) — and used that access to obtain unauthorized HTTPS certificates for several Google domains. Google's own infrastructure was not breached; the compromise occurred at the registry/registrar level that underpins domain validation for certificate issuance.
Why It Matters for Defenders
A fraudulently issued certificate for a trusted domain like a Google property can let an attacker impersonate that site with a valid, browser-trusted TLS session — enabling man-in-the-middle interception, credential phishing, or session hijacking that looks legitimate to end users and most automated checks. The exposure here isn't limited to Google: any organization relying on domain-validated (DV) certificates tied to infrastructure touching these three ccTLDs, or using subdomains/redirects under .gh, .sl, or .as, should consider themselves potentially at risk. This incident is a reminder that certificate trust is only as strong as the weakest link in the domain-validation chain — including registries defenders don't control.
What Defenders Should Watch For
- Monitor Certificate Transparency (CT) logs for unexpected certificates issued for your organization's domains, especially via unfamiliar CAs or unusual validation paths.
- Set up CT log alerting (e.g., via existing CT monitoring tools) if you haven't already, particularly for high-value or brand-sensitive domains.
- Review CAA (Certification Authority Authorization) DNS records to restrict which CAs can issue certificates for your domains.
- Treat any .gh, .sl, or .as domains/subdomains in your environment with added scrutiny until registry integrity is confirmed restored.
- Be alert to downstream phishing or MITM campaigns that may leverage certificates issued during the compromise window.
This is a developing story and details on scope, timeline, and remediation are still emerging — treat the specifics above as preliminary. For the full report, see the original coverage at The Hacker News.