ccTLD registry hijacks of .gh, .sl and .as (September 2026)
incident · incident:cctld-registry-hijacks-gh-sl-as-2026-09
Attackers compromised the .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) country-code registries, changed authoritative DNS records and obtained unauthorized HTTPS certificates for Google and YouTube names and for other organizations' domains; Chrome blocked them and Google had the issuing authorities revoke the Google certificates; Google names no attacker or entry vector and says it cannot guarantee it found every affected domain (Google Chrome Secure Web and Networking Team, 2026-10-06; The Hacker News, 2026-10-08).
Aliases: ccTLD registry hijacks
Defender insights
What each entry about ccTLD registry hijacks of .gh, .sl and .as (September 2026) tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (2 across 1 tactic)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Resource DevelopmentCompromise Infrastructure: DNS Server · Obtain Capabilities: Digital Certificates
Resource Development TA0042
T1584.002Compromise Infrastructure: DNS Server×1
Adversaries may compromise third-party DNS servers that can be used during targeting. During post-compromise activity, adversaries may utilize DNS traffic for various tasks, including for Command and Control (ex: Application Layer Protocol). Instead of setting up their own DNS servers, adversaries may compromise third-party DNS servers in support of operations.
Evidence: 2026-10-11/cctld-registry-hijacks-gh-sl-as-certificates-for-google · ATT&CK page ↗
T1588.004Obtain Capabilities: Digital Certificates×1
Adversaries may buy and/or steal SSL/TLS certificates that can be used during targeting. SSL/TLS certificates are designed to instill trust. They include information about the key, information about its owner's identity, and the digital signature of an entity that has verified the certificate's contents are correct. If the signature is valid, and the person examining the certificate trusts the signer, then they know they can use that key to communicate with its owner.
Evidence: 2026-10-11/cctld-registry-hijacks-gh-sl-as-certificates-for-google · ATT&CK page ↗
Entries about ccTLD registry hijacks of .gh, .sl and .as (September 2026) (1)
Where this entity is cited
Source distribution
- blog.google1 (33%)
- community.letsencrypt.org1 (33%)
- thehackernews.com1 (33%)
All cited sources (3)
- blog.googleGoogle Chrome Secure Web and Networking Teamhttps://blog.google/security/chromes-response-to-recent-cctld-registry-hijacks/
- community.letsencrypt.orgLet's Encrypt community forumhttps://community.letsencrypt.org/t/chromes-response-to-recent-cctld-registry-hijacks/251941/2
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/10/attackers-hijack-gh-sl-and-as.html