← Blog · · df00tech

Hackers Hijack Google Domains After Breaching ccTLD Registries

security-news technique

What Happened

According to BleepingComputer, attackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains by breaching third-party operators of country-code top-level domain (ccTLD) registries for Ghana, American Samoa, and Sierra Leone. The attackers modified authoritative DNS records at the registry/operator level, allowing them to redirect or impersonate affected domains. Details on the full scope, attribution, and timeline are still emerging.

Why It Matters

This incident highlights a supply-chain-style weak point in the domain ecosystem: compromising a ccTLD registry operator can cascade into trust failures far beyond the registry itself. Obtaining valid HTTPS certificates for Google domains via DNS manipulation undermines the domain-validation assumptions that certificate authorities and browsers rely on, potentially enabling man-in-the-middle interception, phishing with valid TLS, or traffic redirection for any organization or user resolving through the affected ccTLD infrastructure.

What Defenders Should Watch For

  • Monitor Certificate Transparency logs for unexpected certificate issuance covering your organization's domains, especially via domains or subdomains tied to ccTLDs in the affected regions.
  • Review DNS resolution paths and authoritative DNS records for any domains dependent on third-party ccTLD operators; watch for unexpected NS, A, or CNAME changes.
  • Audit domain registrar and registry account access, including any delegated or reseller relationships, for signs of unauthorized changes.
  • Treat unexpected TLS certificate validation failures or mismatches as a potential indicator, not just a configuration issue.
  • Consider DNSSEC and CAA record enforcement where feasible to reduce the blast radius of unauthorized certificate issuance.

Developing Story

This is a net-new report with details still emerging; attribution, full scope, and remediation status have not been independently confirmed here. For the latest facts, see the original reporting from BleepingComputer: Hackers hijack Google domains after breaching ccTLD registries.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.