Hackers Hijacked Google Domains and Got Valid HTTPS Certificates


google domains hijacked
Image credit: Google

Hackers compromised third-party operators managing country-code top-level domains and changed authoritative DNS records for Google domains in Ghana (.GH), American Samoa (.AS), and Sierra Leone (.SL).

The attackers used that access to redirect affected domains to infrastructure they controlled and obtain unauthorized HTTPS certificates. Google said the attackers also hijacked domains belonging to other organizations.

Google confirmed that its own systems were not compromised.

Attackers used DNS control to impersonate legitimate domains

Controlling authoritative DNS records allowed the attackers to redirect traffic for legitimate domains to their own servers.

Because certificate authorities use domain validation before issuing TLS certificates, control over DNS also allowed the attackers to obtain valid certificates for domains they did not legitimately own.

Those certificates could then help attackers impersonate legitimate brands and serve arbitrary content over HTTPS while browsers displayed what appeared to be a valid secure connection.

Google has not identified the attackers or disclosed how many unauthorized certificates it confirmed during the investigation.

Google blocked the unauthorized certificates in Chrome

Google said it quickly blocked unauthorized certificates affecting its properties through Chrome’s CRLSets and worked with the certificate authorities that issued them to revoke the certificates.

The company also reviewed Certificate Transparency logs to look for other certificates connected to the attacks.

That investigation uncovered additional affected organizations, including major global brands and popular online services.

Google proactively added other suspicious certificates to Chrome’s blocklist and contacted affected organizations where possible.

The company said it found no evidence that the certificate authorities involved had acted improperly. The attackers instead exploited their control over authoritative DNS records to satisfy certificate validation requirements.

Chrome users do not need to take action

Google said Chrome users do not need to take any action to protect themselves from the attacks it has already identified.

However, the company warned that additional affected domains may remain unidentified. Certificates associated with those domains could therefore remain active until researchers, domain owners, or certificate authorities detect them.

Google’s CRLSet protections also apply specifically to Chrome. Users relying on other browsers could face different levels of protection depending on how those browsers handle certificate revocation and suspicious certificates.

Google urges domain owners to monitor certificate issuance

Google recommends that organizations continuously monitor Certificate Transparency logs for certificates issued for all domains they control.

That includes parked or rarely used domains, since attackers could still exploit those domains for impersonation or phishing.

Domain owners should also configure restrictive Certification Authority Authorization records. CAA records can limit which certificate authorities may issue certificates for a domain and can further restrict permitted accounts or validation methods.

The incident highlights how compromising DNS infrastructure can give attackers control far beyond simple website redirection, including the ability to obtain trusted certificates for legitimate domains.

In other security news, Google suspended its OSS Vulnerability Rewards Program as AI-generated reports surged, while researchers warned that fake ChatGPT and Gemini sites are stealing MFA codes. Japanese publishing giant Nikkei was also hit by Microsoft 365 and Google Workspace account breaches.

Via BleepingComputer

More about the topics: Cybersecurity, Google

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages