Criminals exploited three country domains to impersonate Google securely
Attackers hijacked top-level domains in Ghana (.gh), Sierra Leone (.sl), and American Samoa (.as), allowing them to modify DNS records and obtain fraudulent HTTPS certificates for Google domains and other organisations. This type of attack is particularly dangerous because it allows criminals to impersonate legitimate websites without triggering browser security warnings, potentially enabling data interception, phishing campaigns and malware distribution.
Google discovered the attacks last week and confirmed that Chrome browser quickly blocked the suspected counterfeit certificates, protecting its users. The company stated that the Certification Authorities that issued the certificates were not at fault. Google recommends that domain owners monitor Certificate Transparency logs continuously for all their domains, and implement restrictive Certification Authority Authorization (CAA) DNS records to specify which certificate authorities are permitted to issue certificates for their domains, particularly those operating in the affected country-code namespaces.
- Attackers hijacked domains in three countries to mint fake security certificates for Google and others.
- Fraudulent certificates allowed website impersonation without browser warnings, risking data theft and phishing.
- Google advises monitoring Certificate Transparency logs and using CAA DNS records for protection.
New here? Start with this
Criminals have taken control of the internet domains belonging to Ghana, Sierra Leone and American Samoa and used them to create fake websites impersonating Google and other organisations. By hijacking these country-code domains, attackers were able to redirect people to fraudulent sites under their control.
The attack is particularly dangerous because the criminals obtained security certificates that make fake websites appear legitimate to web browsers. Browsers normally protect users by warning them about unverified websites, but these forged certificates bypass that safeguard, causing the browser to trust the fraudulent pages. This allows criminals to steal login details, spread malware or conduct phishing attacks without triggering any security warnings.
Country-code domains like .gh, .sl and .as are managed by registries that handle registration for their respective countries, yet this case shows that security measures in some registries may be insufficient to prevent unauthorised access. Once attackers gain control of such a domain, they can cause harm across organisations and users worldwide.
Read the full article at the source →
Originally published by The Register as “Attackers hijacked top-level domains, minted fake security certs for Google and other orgs”.