Threat Actors Hijack ccTLDs (.gh, .sl, .as) to Obtain Rogue HTTPS Certificates for Google Domains
Threat actors compromised third-party operators of the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) country-code top-level domains (ccTLDs), enabling them to alter authoritative DNS records and obtain unauthorized HTTPS certificates for Google domains.
Assessment
Threat actors compromised third-party operators of the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) country-code top-level domains (ccTLDs), enabling them to alter authoritative DNS records and obtain unauthorized HTTPS certificates for Google domains. This incident confirms a systemic vulnerability in global DNS infrastructure, with potential for large-scale traffic interception and credential theft. The full scope of the compromise and attribution remain unclear.
Why it matters: This incident highlights critical weaknesses in ccTLD governance and DNS security, posing a significant risk to internet infrastructure and user trust.
Key facts
- UnknownThreat actors compromised ccTLD registries for .gh, .sl, and .as.
- UnknownCompromise enabled alteration of authoritative DNS records.
- UnknownUnauthorized HTTPS certificates were obtained for Google domains.
- UnknownThe incident underscores systemic risks in global DNS infrastructure.
- UnknownFull scope of the compromise.
- UnknownAttribution of the threat actors.
Indicators to watch
- →Identification of specific threat actor groups or state sponsors.
- →Further details on the method of initial compromise of ccTLD operators.
- →Reports of actual traffic interception or credential theft using the rogue certificates.
Evidence
Central claim Hackers breach ccTLD registries, hijack Google domains via rogue HTTPS certs100% on claim
Topics dns-hijacking · ccTLD · google · https-certificates · infrastructure-attack · cyber-espionage · infrastructure
Discussion
…Sign in to add a note, contribute a source, or challenge the assessment.