Skip to content
Cyber Attacks

Organizations urged to check SSL certs after hackers hijacked .gh, .sl, .as to forge Google HTTPS

Attackers hijacked three country-code top-level domains to issue unauthorised HTTPS certificates for Google properties, though core systems remained secure.

Organizations urged to check SSL certs after hackers hijacked .gh, .sl, .as to forge Google HTTPS
Illustration: Malware Brief

Key points

  • Attackers compromised .gh, .sl, and .as registries to obtain unauthorised certificates.
  • Google confirmed its own infrastructure was not breached during the incident.
  • The attack involved modifying authoritative DNS records via third-party operators.

Organisations relying on specific country-code top-level domains faced exposure to certificate fraud after attackers hijacked registry operations for Ghana, Sierra Leone, and American Samoa. Google disclosed the incident on 6 October, confirming that threat actors had obtained unauthorised HTTPS certificates for several of its domains. While the core Google infrastructure remained uncompromised, the breach of these registries allowed attackers to pose as legitimate sites over encrypted connections, potentially intercepting user traffic.

How it unfolded

  • Threat actors compromised the third-party operators responsible for the .gh, .sl, and .as country-code top-level domains.
  • The attackers modified authoritative DNS records within these registries to facilitate the issuance of fraudulent certificates.
  • Unauthorised HTTPS certificates were subsequently obtained for multiple Google domains, enabling potential man-in-the-middle attacks against users of these specific top-level domains.

Who is affected

The primary impact falls on users and organisations interacting with domains ending in .gh, .sl, or .as. According to Google, any domain within these three country-code top-level domains was placed at risk during the window of the compromise. Although Google’s own systems were not breached, the integrity of the certificate chain for these specific domains was undermined. Users visiting Google services hosted on these domains could have been exposed to interception if they trusted the fraudulent certificates. The incident highlights the fragility of the public key infrastructure when third-party registry operators are compromised.

The fix

Google has stated that its own systems were not breached, limiting the scope of the incident to the external registry compromises. No specific patch or update has been confirmed by the vendors of the affected registry operators in the provided reports. The resolution relies on the restoration of secure control over the .gh, .sl, and .as registries by their respective authorities and the revocation of the unauthorised certificates. Organisations should monitor for official statements from the registry operators regarding the restoration of integrity.

Background: Threat actors

A threat actor is any entity that initiates a cyber attack. They range from automated software to organised criminal groups. Understanding their motive helps you predict their behaviour. Most are not after you specifically but exploit common weaknesses for quick financial gain.

Read the full guide: Threat Actors Explained: Motives, Methods and Misconceptions

What to do and how to stay safe: Google

  • Verify the validity of SSL/TLS certificates for any .gh, .sl, or .as domains you operate or frequently access, checking for unexpected issuers or expiration dates.
  • Monitor DNS logs for authoritative record changes on your domains hosted within these country-code top-level domains to detect further manipulation.
  • Educate users to inspect browser security warnings carefully, as attackers may have used the compromised certificates to mask malicious sites as legitimate Google properties.
  • Review access controls for any third-party DNS or registry management tools to ensure that only authorised personnel can modify authoritative records.

Step-by-step guide: Incident Response Plans: Real Benefits and Hidden Costs

General security guidance from the Malware Brief newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

Were Google's internal systems hacked during this incident?

No, Google confirmed that its own systems were not breached; the attack targeted the external ccTLD registries.

Which country-code top-level domains were compromised?

The .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) registries were hijacked.

When did Google disclose this security incident?

Google announced the incident on 6 October, detailing the unauthorised certificate issuances.

Sources

  1. The Hacker News
  2. BleepingComputer
  3. Infosecurity Magazine
GoogleccTLDSSL/TLSDNSCertificate Authority

Related stories

Service Outages Loom as CISA Orders Federal BIND TKEY Fixes by Oct 11

CISA added an old but active BIND vulnerability to its critical catalog, demanding federal action within three days to prevent service outages.

Cybersecurity news without the noiseDaily Briefing