
Threat actors successfully hijacked three country-code top-level domains (.gh, .sl, and .as) and leveraged their control to generate fraudulent TLS certificates for Google and several other prominent online services, according to an announcement Tuesday.
The attackers modified authoritative DNS records within these compromised domains to bypass automated validation procedures used by certificate authorities. By controlling the DNS infrastructure, they were able to pass domain control verification checks required for certificate issuance. This technique allowed them to obtain unauthorized credentials for multiple Google properties as well as certificates for other major global brands and widely used online services. Google responded by updating its Chrome browser to block all identified unauthorized certificates and coordinated with relevant certification authorities to revoke the counterfeit Google certificates.
TLS certificates function as cryptographic credentials that establish the authenticity and encryption for websites and internet infrastructure. These certificates bind domain names to specific public keys through digital signatures, allowing users to verify they are connecting to legitimate services. Possession of unauthorized certificates enables attackers to impersonate affected infrastructure and potentially intercept communications.
Google declined to identify the specific domains affected by the attacks or name the other compromised organizations. The company emphasized that while Chrome users are protected through browser-level interventions, these measures should not be considered a complete defense. Google recommended domain owners monitor certificate transparency logs for unexpected certificate issuance, implement restrictive Certification Authority Authorization DNS records, and avoid assuming browser-side protections alone will shield their users from attack.
The incident echoes previous certificate compromise incidents, including a 2011 breach of the DigiNotar certificate authority that resulted in unauthorized certificates for Google.com and over 200 other high-traffic domains being used to target approximately 300,000 users in Iran. Google noted that in this case, the attackers did not compromise the infrastructure of the affected domain owners themselves, and that certificate authorities adhered to all required protocols.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI