← Blog · · df00tech

Hijacked .gh, .sl, and .as Registries Used to Obtain Rogue Certificates for Google Domains

security-news breach

What Happened

Google reported on October 6 that attackers compromised three country-code top-level domain (ccTLD) registries — .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) — and used that access to obtain unauthorized HTTPS certificates for several Google domains. Google's own infrastructure was not breached; the compromise occurred at the registry/registrar level that underpins domain validation for certificate issuance.

Why It Matters for Defenders

A fraudulently issued certificate for a trusted domain like a Google property can let an attacker impersonate that site with a valid, browser-trusted TLS session — enabling man-in-the-middle interception, credential phishing, or session hijacking that looks legitimate to end users and most automated checks. The exposure here isn't limited to Google: any organization relying on domain-validated (DV) certificates tied to infrastructure touching these three ccTLDs, or using subdomains/redirects under .gh, .sl, or .as, should consider themselves potentially at risk. This incident is a reminder that certificate trust is only as strong as the weakest link in the domain-validation chain — including registries defenders don't control.

What Defenders Should Watch For

  • Monitor Certificate Transparency (CT) logs for unexpected certificates issued for your organization's domains, especially via unfamiliar CAs or unusual validation paths.
  • Set up CT log alerting (e.g., via existing CT monitoring tools) if you haven't already, particularly for high-value or brand-sensitive domains.
  • Review CAA (Certification Authority Authorization) DNS records to restrict which CAs can issue certificates for your domains.
  • Treat any .gh, .sl, or .as domains/subdomains in your environment with added scrutiny until registry integrity is confirmed restored.
  • Be alert to downstream phishing or MITM campaigns that may leverage certificates issued during the compromise window.

This is a developing story and details on scope, timeline, and remediation are still emerging — treat the specifics above as preliminary. For the full report, see the original coverage at The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.