$ techbeacon▋
Breaches

Cybercriminals Exploit Registry Weaknesses to Hijack Google Subdomains in Ghana, American Samoa and Sierra Leone

Cybercriminals Exploit Registry Weaknesses to Hijack Google Subdomains in Ghana, American Samoa and Sierra Leone

Security researchers have uncovered a coordinated attack in which threat actors obtained fraudulent HTTPS certificates for a range of Google-owned sites and subsequently altered DNS records for domains registered under the country-code top-level domains (ccTLDs) of Ghana (.gh), American Samoa (.as) and Sierra Leone (.sl). The intrusion was traced to compromised third‑party operators that manage the authoritative name servers for these ccTLDs, allowing the attackers to reroute traffic intended for legitimate Google services to servers under their control.

The scheme began with the illicit issuance of TLS certificates, a process that typically relies on trusted Certificate Authorities (CAs) to validate domain ownership. By exploiting vulnerabilities in the registration workflow of the involved registrars, the hackers were able to convince a CA to issue certificates for Google subdomains without proper verification. Once the certificates were in hand, the perpetrators modified DNS entries at the registry level, pointing the targeted domains to malicious IP addresses that hosted the counterfeit sites.

While the hijacked domains represented a relatively small slice of Google’s overall web presence, the incident highlights a broader risk to the internet’s trust infrastructure. Manipulating ccTLD registries can have outsized effects because many national internet ecosystems depend on a handful of operators for DNS management. A successful breach can enable phishing campaigns, credential harvesting, or the distribution of malware, especially when the spoofed sites appear under the familiar Google brand.

Google’s security teams have responded by revoking the fraudulent certificates and working with affected registrars to restore correct DNS records. The company also issued a public advisory urging users to verify the authenticity of any unexpected Google login prompts, particularly those originating from the affected country domains. Meanwhile, industry watchdogs are calling for stricter oversight of third‑party DNS providers and a review of certificate‑issuance policies to prevent similar abuses.

Experts suggest that the incident could spur regulatory bodies in the affected countries to tighten controls over their ccTLD operations, potentially introducing more rigorous authentication mechanisms for changes to authoritative records. As the investigation continues, the broader cybersecurity community is monitoring for signs of further exploitation of compromised registrars, a vector that could be leveraged against other high‑profile brands if left unchecked.

Threat Desk — Threat desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related