AI News Feed
Market watch
Cybersecurity

Attackers Hijack Three Country-Code Domains to Mint Counterfeit TLS Certificates for Google and Other Brands

Google said attackers took control of the .gh, .sl and .as country-code top-level domains, altered authoritative DNS records to clear domain control checks and obtained unauthorized TLS certificates for several Google domains and other major brands.

Google said the attackers launched a series of attacks on the .gh, .sl and .as country-code top-level domains, and then modified authoritative DNS records for selected domains inside those namespaces. Control over those records allowed the attackers to pass automated domain control validation checks, the step certificate authorities use to confirm that an applicant controls the domain named in a certificate request.

Passing those checks let the attackers obtain unauthorized certificates for "several Google domains" and for "several leading global brands and widely used online services," Google said.

Google said it updated Chrome to block all certificates it identified as unauthorized, and that it worked with the issuing certification authorities to ensure the unauthorized certificates covering Google properties were revoked. The company's account did not identify the attackers, say how many certificates were issued, or name the other organizations affected. Ars Technica reported Google's statement.

TLS certificates are the cryptographic credentials that underpin authentication and encryption protections for websites, mail servers and other internet infrastructure. These x.509 certificates use a digital signature to bind a domain name such as google.com to a public key. The public key is publicly available, while the private key is held only by the website operator. When a connection shows that the keys match, the visiting party knows it is connected to the authentic site rather than an impostor. Possession of unauthorized certificates allows attackers to cryptographically impersonate the affected infrastructure.