Attackers hijack ccTLDs to fake certs for Google

Key points

Unknown attackers hijacked the ccTLD registries for Ghana, Sierra Leone and American Samoa to obtain unauthorised HTTPS certificates for major brand sites.

Attackers hijack ccTLDs to fake certs for Google

Attackers hijack ccTLDs to fake certs for Google

Key points

  • Unknown attackers hijacked the ccTLD registries for Ghana, Sierra Leone and American Samoa to obtain unauthorised HTTPS certificates for major brand sites.
  • Google said Chrome immediately blocked the invalid certificates, and iTnews found 32 digital credentials issued to the attackers between 22 and 27 September.
  • The bogus certificates have now been revoked by the CAs, though Google did not say how the ccTLD registries were compromised.




Attackers hijack ccTLDs to fake certs for Google








Unknown attackers have hijacked the country top level domain registries for Sierra Leone, Ghana and American Samoa, and obtained trusted web certificates for major brand sites such as Google and YouTube.

The hijacks came to light after Google Security reported them, and involve the .gh, .sl and .as suffixes.

Google said its Chrome web browser immediately blocked the invalid HTTPS certificates which impersonated the tech giant itself.

A check of public certificate transparency (CT) logs by iTnews, referenced against the Chrome blocklist found 32 digital credentials issued to the attackers between September 22 and 27 of this year.

Several international brand names were found in the CT logs.

With such certificates, web browsers will display a padlock or similar symbol to indicate a visited site is the one it purports to be, and that the connection is secure.

An attacker that can present that kind of trusted certificate for a site and is able to redirect users’ traffic can impersonate even well-known brands without any warnings being triggered.

“During these hijacks, attackers modified authoritative DNS records and obtained unauthorised HTTPS certificates covering several Google domains, as well as domains belonging to other organisations,” Google said.

“Due to the nature of the attacks, we have no reason to believe the Certification Authorities (CAs) that issued the impacted certificates did anything wrong,” Google added.

Certificate authorities (CAs) check if an applicant controls a domain by looking it up in the domain name system (DNS).

Public data suggests Ghana’s registry was first compromised on September 22nd UTC, followed by Sierra Leone on the 25th and American Samoa on the 27th.

On each of those days, most certificates were issued within a window of 90 minutes.

Attackers used free transport layer security (TLS) certificates with wildcards from the Let’s Encrypt and Sectigo’s ZeroSSL CAs.

They also received a certificate from Cloudflare’s CA for a domain belonging to another major tech brand; such a certificate issuance involves domains added to a Cloudflare account, which may provide a clue to the identify of the attackers.

The bogus certificates have now been revoked by the CAs.

iTnews contacted the operators for Ghana’s .gh, American Samoa’s .as and Sierra Leone’s .si top level domains (ccTLDs) but received no responses.

Google did not say how the ccTLD registries were compromised, and did not provide further comment on the hijacks before publication.

Registry compromises not new

Attacking ccTLD registries has happened in the past, ditto using them to obtain trusted digital certificates.

In April 2019, Cisco Talos reported that a state-sponsored group it dubbed Sea Turtle had hijacked domains belonging to at least 40 organisations across 13 countries, in part by compromising registrars and registries.

Three months later,Talos linked Sea Turtle to a breach of ICS-Forth, which operates Greece’s .gr registry, and the hijacking of three Greek government domains.

Sea Turtle also installed certificates from Let’s Encrypt, Comodo and Sectigo on its man-in-the-middle servers, a technique Talos called “certificate impersonation”.

The technique was not new: in 2012, a breach of Pakistan’s PKNIC registry redirected 284 .pk domains to a hacker-controlled server, including google.com.pk and apple.pk.

A well-known case of rogue certificates for Google involved Dutch CA DigiNotar that was breached in 2011.

Some 531 fraudulent certificates were produced for *.google.com in that breach that was named Operation Black Tulip.

Investigators found about 300,000 unique internet protocol (IP) addresses, almost all in Iran, had requested access to google.com using the fraudulent certificates.

Google advised organisations not to rely on web browsers to catch such impersonation, and to monitor certificate transparency logs across all their domains.

This includes parked and regional country-code registrations that rate get attention.

Domain owners can also publish DNS records that restrict issuance to their own account with a certificate authority.

This means a hijacker’s account is refused even after passing domain checks.



About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.