Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
Attackers hijacked the .gh, .sl, and .as registries and obtained later-revoked HTTPS certificates for Google and YouTube domains.
Google said on October 6 that attackers compromised the .gh, .sl, and .as country-code registries and obtained unauthorized HTTPS certificates for Google and YouTube names, without breaching Google's own systems. Certificate Transparency logs show 12 domain-validated certificates, 11 from Let's Encrypt and one from ZeroSSL, logged between September 22 and 27 for names including google.com.gh, google.sl, and google.as. Chrome blocked the Google certificates via CRLSets, the issuing certificate authorities revoked all 12, and Google said the same DNS hijacks appear to have hit other unnamed organizations. Google did not confirm the certificates were used to intercept traffic and did not name the attackers.