Wire Observer.
Technology

Google reveals hackers stole fake TLS certificates after hijacking country-code domains

Google reveals hackers stole fake TLS certificates after hijacking country-code domains

Google disclosed on Tuesday that a group of attackers managed to obtain counterfeit HTTPS certificates for several high‑profile web services by compromising three country‑code top‑level domains.

The perpetrators redirected the registration process for the affected domains to issue certificates that appeared to be signed by legitimate certificate authorities. With those certificates, malicious actors could have performed man‑in‑the‑middle attacks or crafted convincing phishing pages that would bypass typical browser warnings.

Google’s security team responded by revoking the fraudulent certificates and pushing updates to Chrome that block any connections using them. Users of the browser were therefore shielded from potential interception without needing to take any action.

According to the company, the compromised domains were not directly owned by the targeted services but were used as intermediaries to satisfy the “domain‑validation” requirements that many public CAs employ. By controlling the DNS records for the three country‑code domains, the attackers could satisfy the validation checks and obtain trusted certificates.

Experts note that the incident underscores the ongoing risk posed by domain‑validation certificates, which rely on the ability to prove control over a domain rather than on more rigorous identity verification. While such certificates enable rapid issuance for legitimate sites, they can also be abused when an attacker gains control of a seemingly unrelated domain.

Google has warned other browser vendors and certificate‑authority operators to scrutinize similar requests and to consider additional safeguards, such as stricter validation for high‑value domains. The company also urged organizations to monitor for unauthorized certificates issued for their brand names.

The episode comes amid a broader wave of supply‑chain and credential‑theft attacks, reminding enterprises that even indirect assets like country‑code domains can become vectors for large‑scale credential fraud.

Source: TechRadar
Kabir Rao — Security desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related