$ techbeacon▋
Phishing

Cybercriminals Breach Three Country‑Code Domains to Secure Illicit Google SSL Certificates

Cybercriminals Breach Three Country‑Code Domains to Secure Illicit Google SSL Certificates

Security researchers have confirmed that attackers managed to infiltrate the registries responsible for the .gh, .sl and .as country‑code top‑level domains, using that access to obtain unauthorized HTTPS certificates from Google’s Certificate Authority.

Top‑level domain registries maintain the authoritative records for all second‑level domains under their suffix. When a certificate authority (CA) validates a request for an SSL/TLS certificate, it typically checks that the applicant can demonstrate control over the domain name, often through DNS or WHOIS records. By compromising the registry accounts, the attackers were able to manipulate those records and satisfy Google’s validation checks.

According to the investigation, the intrusion allowed the perpetrators to alter DNS entries and WHOIS information for selected domains within the three affected ccTLDs. Once the changes were in place, they submitted certificate signing requests to Google Trust Services, which issued the certificates without detecting the underlying fraud.

The forged certificates can be used to impersonate legitimate websites, enabling man‑in‑the‑middle attacks, phishing campaigns, or the distribution of malware while appearing trusted to browsers and users. Because the certificates are signed by Google, they inherit the same level of trust as any legitimate Google‑issued certificate, making detection difficult without specialized monitoring.

Google responded by revoking the compromised certificates and notifying the affected registries. The three registry operators have launched internal investigations, are resetting credentials, and are working with law‑enforcement agencies to identify the breach vector.

The incident underscores a growing concern about the security of domain name infrastructure. While CAs have tightened validation procedures in recent years, the attack demonstrates that compromising a registry can bypass many of those safeguards. Experts recommend stronger multi‑factor authentication, regular audit logs, and tighter separation of duties for registry staff.

Going forward, the affected registries are expected to implement additional security controls and may coordinate with the Internet Corporation for Assigned Names and Numbers (ICANN) to review best practices. The episode also raises questions about whether CAs will adjust their validation policies to require more direct proof of control beyond registry data, a move that could add resilience against similar supply‑chain attacks.

Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related