Three country-code top-level domains were hijacked
Cybercriminals recently managed to hijack three country-code top-level domains (ccTLDs) and used the access to generate HTTPS certificates covering several Google domains, as well as those belonging to other organizations. Google said the attack placed thousands of websites at risk, but stressed that the certificates have since been revoked.
- Attackers hijacked three country-code domains to obtain fraudulent HTTPS certificates for major websites
- Fake certificates could enable convincing traffic interception and phishing against affected domains
- Google revoked the certificates, protected Chrome users, and warned impacted organizations
According to Google, the domains that were hijacked are .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa). During the attacks, the threat actors modified authoritative DNS records, obtaining HTTPS certificates covering not just Google, but other organizations, too.
In other words, any website operating on these domains was at risk, as well as all of the visitors. By manipulating authoritative DNS records, threat actors could redirect traffic away from legitimate websites and towards malicious ones under their control, all the while telling users they were visiting the legitimate one by showing the padlock icon. Visitors entering login credentials, payment information, or other data, would easily lose them to the attackers, and depending on the circumstances, they could also end up installing malware.
“Due to the nature of the attacks, we have no reason to believe the Certification Authorities (CAs) that issued the impacted certificates did anything wrong,” Google said.
Read more: