What You Need to Know About Fake TLS Certificates Used in Recent Domain Hijacking Attacks

Hackers hijacked three country-code domains to issue fake TLS certificates for major websites, enabling phishing and traffic interception risks. Learn who is affected and what steps to take.

What You Need to Know About Fake TLS Certificates Used in Recent Domain Hijacking Attacks
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

How Did Hackers Obtain Fake TLS Certificates?

Cybercriminals exploited control over three country-code top-level domains (.gh, .sl, and .as) by hijacking their authoritative DNS records. With this access, they generated fraudulent HTTPS certificates for prominent websites, including Google domains and other major global brands.

This abuse of domain control allowed attackers to impersonate legitimate websites convincingly. Visitors could see the padlock icon typically indicating a secure connection, while their traffic was intercepted or redirected to malicious sites without their knowledge.

What Are the Risks for Web Users and Site Owners?

Hackers hijack .gh, .sl and .as and get rogue TLS certificates for Google
Hackers hijack .gh, .sl and .as and get rogue TLS certificates for Google

For users, fake TLS certificates create a serious phishing risk. They might unknowingly submit sensitive information such as login credentials or payment data to attackers posing as trusted sites. Additionally, attackers could serve malware through these deceptive channels.

Websites operating on the compromised ccTLDs also face exposure. Threat actors could maliciously redirect visitors or degrade trust in those domains due to security breaches.

Even though browser protections like Chrome’s certificate revocation mechanisms were swiftly applied, users of other browsers might remain vulnerable if the fraudulent certificates are not fully blocked elsewhere.

What Measures Are in Place and What Should Domain Owners Do?

Google promptly revoked the fraudulent certificates and blocked them in Chrome, mitigating immediate threats to many users. Despite this, the incident highlights the importance of vigilance among domain owners, especially those using these ccTLDs.

Domain administrators should continuously monitor Certificate Transparency logs to detect any unauthorized certificates promptly. Additionally, implementing restrictive Certificate Authority Authorization (CAA) DNS records with Account Configuration Management (ACME) bindings can help prevent unauthorized certificate issuance.

How Does This Incident Compare to Past Certificate Authority Breaches?

mTLS: When certificate authentication is done wrong - The GitHub Blog
mTLS: When certificate authentication is done wrong - The GitHub Blog

This attack is part of a broader pattern where attackers exploit weaknesses in domain control or certificate authorities to issue fraudulent TLS certificates. Past cases like the DigiNotar breach in 2011 demonstrate the potentially severe outcomes, including widespread interception of encrypted communications and a collapse of trust leading to the CA’s demise.

Unlike those incidents, this attack primarily leveraged domain hijacking rather than direct compromise of certificate authorities themselves. This distinction underlines the criticality of securing domain registration and DNS infrastructure as part of an overall web security strategy.

Key Takeaway: What Should Users and Site Owners Remember?

For end users, no immediate action is required if using updated mainstream browsers like Chrome, as protections against these fake certificates are in place.

Domain owners, however, bear responsibility for strengthening defenses. Regular monitoring for rogue certificates and strict DNS CAA policies are essential to minimize risk.

This event serves as a reminder that security is only as strong as the weakest link in the certificate issuance and domain control chain. Ongoing vigilance and adopting best practices remain critical in defending HTTPS trust on the web.

React to this story

Related Posts