Full Report
Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compromising third-party operators and modifying authoritative DNS records. [...]
Analysis Summary
# Incident Report: Multi-ccTLD Registry Hijack & Google Domain Impersonation
## Executive Summary
A threat actor compromised the third-party registry operators for the country-code top-level domains (ccTLDs) of Ghana (.gh), Sierra Leone (.sl), and American Samoa (.as). By modifying authoritative DNS records, the attackers obtained unauthorized HTTPS certificates for several Google domains and other global brands, enabling them to hijack traffic and impersonate legitimate services. Google mitigated the impact for its users by revoking and blocking the fraudulent certificates via Chrome’s CRLSets.
## Incident Details
- **Discovery Date:** October 2026 (Reported)
- **Incident Date:** Circa October 2026
- **Affected Organization:** Google, various global brands, and ccTLD registries for .GH, .SL, and .AS.
- **Sector:** Technology / Domain Name System (DNS) Infrastructure
- **Geography:** Ghana, American Samoa, Sierra Leone (Global Impact)
## Timeline of Events
### Initial Access
- **Date/Time:** Pre-October 7, 2026
- **Vector:** Compromise of third-party registry operators/operators of ccTLDs.
- **Details:** Attackers gained unauthorized access to the systems managing DNS records for the .GH, .SL, and .AS zones.
### Lateral Movement
- **Details:** The attackers moved from the registry's internal systems to the authoritative DNS management interface, allowing them to alter records for high-value domains.
### Data Exfiltration/Impact
- **Details:** Unauthorized HTTPS certificates were issued for Google and other major brands. Attackers redirected domain traffic to attacker-controlled infrastructure, potentially intercepting user data or serving malicious content.
### Detection & Response
- **Discovery:** Identified through Certificate Transparency (CT) log monitoring and anomaly detection in DNS records.
- **Response:** Google blocked unauthorized certificates via Chrome CRLSets, notified issuing Certificate Authorities (CAs) for revocation, and identified additional affected brands through CT logs.
## Attack Methodology
- **Initial Access:** Supply chain attack targeting third-party ccTLD registry operators.
- **Persistence:** Maintaining control over authoritative DNS records to renew or issue new certificates.
- **Defense Evasion:** Leveraging valid HTTPS certificates to bypass browser security warnings and appear legitimate.
- **Credential Access:** Likely compromise of registry administrative credentials (specifics not disclosed).
- **Discovery:** Reconnaissance of high-value domains hosted within the vulnerable ccTLDs.
- **Lateral Movement:** Movement within the registry infrastructure to access zone files.
- **Impact:** DNS hijacking and brand impersonation.
## Impact Assessment
- **Financial:** Not disclosed; potential loss due to redirected traffic and remediation costs.
- **Data Breach:** Risk of user credential theft or session hijacking via Man-in-the-Middle (MitM) attacks.
- **Operational:** Disruption of services for users in affected regions; significant remediation effort for CAs and brands.
- **Reputational:** High impact on the perceived security of the affected ccTLDs.
## Indicators of Compromise
- **Network Indicators:**
- Unauthorized DNS TXT records used for ACME/DCV (Domain Control Validation).
- IPs: [Attacker-controlled infrastructure IPs - Not specifically listed in source].
- **Behavioral Indicators:**
- Unexpected certificate issuance for domains in .GH, .SL, and .AS visible in Certificate Transparency logs.
- Authoritative DNS NS or A records pointing to non-standard IP ranges.
## Response Actions
- **Containment:** Google deployed CRLSet updates to Chrome to block specific serial numbers of fraudulent certificates.
- **Eradication:** Coordinated with CAs to revoke certificates and worked with registries to restore correct DNS records.
- **Recovery:** Restoration of authoritative DNS control to legitimate owners.
## Lessons Learned
- **Registry Vulnerability:** Reliance on ccTLDs with potentially weaker security postures introduces significant supply chain risk to global brands.
- **CT Log Value:** Certificate Transparency logs remain the most effective tool for early detection of unauthorized certificate issuance.
- **Browser Limitations:** Protections like CRLSets are effective but limited to specific browsers (Chrome), leaving users of other browsers vulnerable until CA-level revocation propagates.
## Recommendations
- **Domain Monitoring:** Implement 24/7 Certificate Transparency (CT) log monitoring for all corporate domains and parked domains.
- **DNS Security:** Utilize Registry Lock services for high-value domains to prevent unauthorized DNS changes.
- **CAA Records:** Publish restrictive Certification Authority Authorization (CAA) records to limit which CAs can issue certificates and which validation methods (e.g., ACME) are permitted.
- **Browser Diversification:** Ensure security teams monitor for threats across multiple browser ecosystems, as mitigations may not be universal.