Skip to main content
developing→ StableCyber

Threat Actors Hijack ccTLDs (.gh, .sl, .as) to Obtain Rogue HTTPS Certificates for Google Domains

Threat actors compromised third-party operators of the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) country-code top-level domains (ccTLDs), enabling them to alter authoritative DNS records and obtain unauthorized HTTPS certificates for Google domains.

Impact
4.9
Confidence
Low
Evidence status
Reported
Evidence
2 sig · 2 src
Trajectory
→ Stable
Geo
GH AS SL
First seen Oct 9·Updated Oct 9·Synthesized Oct 9
Export brief

Assessment

Low confidence: evidence reported (0 of 6 key facts linked to evidence; the model marked a key fact as unclear); 2 distinct outlets

Threat actors compromised third-party operators of the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) country-code top-level domains (ccTLDs), enabling them to alter authoritative DNS records and obtain unauthorized HTTPS certificates for Google domains. This incident confirms a systemic vulnerability in global DNS infrastructure, with potential for large-scale traffic interception and credential theft. The full scope of the compromise and attribution remain unclear.

Why it matters: This incident highlights critical weaknesses in ccTLD governance and DNS security, posing a significant risk to internet infrastructure and user trust.

Key facts

  • UnknownThreat actors compromised ccTLD registries for .gh, .sl, and .as.
  • UnknownCompromise enabled alteration of authoritative DNS records.
  • UnknownUnauthorized HTTPS certificates were obtained for Google domains.
  • UnknownThe incident underscores systemic risks in global DNS infrastructure.
  • UnknownFull scope of the compromise.
  • UnknownAttribution of the threat actors.

Indicators to watch

  • →Identification of specific threat actor groups or state sponsors.
  • →Further details on the method of initial compromise of ccTLD operators.
  • →Reports of actual traffic interception or credential theft using the rogue certificates.

Evidence

Reported · 2 signals · 2 distinct outlets

Central claim Hackers breach ccTLD registries, hijack Google domains via rogue HTTPS certs100% on claim

Reported2 · 2 src · best low 26%

Topics dns-hijacking · ccTLD · google · https-certificates · infrastructure-attack · cyber-espionage · infrastructure

Discussion

…

Sign in to add a note, contribute a source, or challenge the assessment.