Hackers hijack .gh, .sl, .as ccTLDs, obtain HTTPS certs for Google domains
Threat actors compromised the country-code top-level domains (ccTLDs) .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa), enabling them to issue fraudulent HTTPS certificates for Google domains. The incident underscores systemic weaknesses in ccTLD governance and DNS infrastructure, with potential for targeted interception or impersonation of Google services. Scope and attribution remain unclear.
Score Breakdown
Part of 2 situations
United States — 230 developments
Threat Actors Hijack ccTLDs (.gh, .sl, .as) to Obtain Rogue HTTPS Certificates for Google Domains
Threat actors compromised third-party operators of the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) country-code top-level domains (ccTLDs), enabling them to alter authoritative DNS records and obtain unauthorized HTTPS certificates for Google domains. This incident confirms a systemic vulnerability in global DNS infrastructure, with potential for large-scale traffic interception and credential theft. The full scope of the compromise and attribution remain unclear.