Hackers hijack domains and obtain fake Google certificates

 

Hackers hijack domains and obtain fake Google certificates

Hackers obtained unauthorized HTTPS certificates for several Google domains after compromising third-party operators and changing DNS records for country-code domains in Ghana, American Samoa, and Sierra Leone.

The attack affected organizations using the .GH, .AS, and .SL domains, but Google said its own systems were not compromised.

By changing DNS records, the attackers were able to redirect domains to servers they controlled and pass the checks needed to obtain valid HTTPS certificates. This could allow them to impersonate legitimate websites and serve visitors malicious or misleading content.

Google said it blocked the unauthorized certificates in Chrome using CRLSets, an emergency system for blocking revoked or untrusted certificates. The company also worked with certificate authorities to revoke the certificates and reviewed Certificate Transparency logs for additional affected domains.

Google said several major global brands and online services may have been affected, although it did not reveal who the attackers were or the exact number of affected certificates.

The company warned that it may not have identified every affected domain.

“While Chrome took steps during these incidents to identify and block suspected unauthorized certificates across the affected ccTLDs, browser-side intervention should not be relied on to protect your users. Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users,” the vendor said.

Back to the list