CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

ccTLD registry hijacks of .gh, .sl and .as (September 2026)

incident · incident:cctld-registry-hijacks-gh-sl-as-2026-09

Attackers compromised the .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) country-code registries, changed authoritative DNS records and obtained unauthorized HTTPS certificates for Google and YouTube names and for other organizations' domains; Chrome blocked them and Google had the issuing authorities revoke the Google certificates; Google names no attacker or entry vector and says it cannot guarantee it found every affected domain (Google Chrome Secure Web and Networking Team, 2026-10-06; The Hacker News, 2026-10-08).

Aliases: ccTLD registry hijacks

Coverage
1
first 2026-10-11 → last 2026-10-11
Latest activity
2026-10-11
Registry-level DNS hijacks of .gh, .sl and .as produced valid HTTPS certificates for Google names
Peak priority
notable
1 notable
Targets
technology
sectors: technology
Sources cited
3
3 hosts

Defender insights

What each entry about ccTLD registry hijacks of .gh, .sl and .as (September 2026) tells a defender to do, newest first.

2026-10-11NOTABLERegistry-level DNS hijacks of .gh, .sl and .as produced valid HTTPS certificates for Google names

Exposure · triage · detection

Story timeline

  1. 2026-10-11Attackers compromised the .gh, .sl and .as country-code registries, rewrote authoritative DNS and obtained valid HTTPS certificates for Google and YouTube names
    active-threatsRegistry-level DNS hijacks of .gh, .sl and .as produced valid HTTPS certificates for Google names

Hunting pivots

ATT&CK techniques (2 across 1 tactic)

2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Resource DevelopmentCompromise Infrastructure: DNS Server · Obtain Capabilities: Digital Certificates

Resource Development TA0042

T1584.002Compromise Infrastructure: DNS Server×1

Adversaries may compromise third-party DNS servers that can be used during targeting. During post-compromise activity, adversaries may utilize DNS traffic for various tasks, including for Command and Control (ex: Application Layer Protocol). Instead of setting up their own DNS servers, adversaries may compromise third-party DNS servers in support of operations.

Evidence: 2026-10-11/cctld-registry-hijacks-gh-sl-as-certificates-for-google · ATT&CK page ↗

T1588.004Obtain Capabilities: Digital Certificates×1

Adversaries may buy and/or steal SSL/TLS certificates that can be used during targeting. SSL/TLS certificates are designed to instill trust. They include information about the key, information about its owner's identity, and the digital signature of an entity that has verified the certificate's contents are correct. If the signature is valid, and the person examining the certificate trusts the signer, then they know they can use that key to communicate with its owner.

Evidence: 2026-10-11/cctld-registry-hijacks-gh-sl-as-certificates-for-google · ATT&CK page ↗

Entries about ccTLD registry hijacks of .gh, .sl and .as (September 2026) (1)

2026-10-11 · view entry permalink →

NOTABLENATOB1

Attackers compromised the .gh, .sl and .as country-code registries, rewrote authoritative DNS and obtained valid HTTPS certificates for Google and YouTube names

Google's Chrome Secure Web and Networking Team says attackers compromised the third-party .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) country-code top-level domains, modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains and domains of other organizations (Google, 2026-10-06). A certificate authority issues a domain-validated certificate once the applicant shows control of the domain, for example by adding a record to its DNS, so control of the registry's DNS passes that check; Google has no reason to believe the issuing authorities did anything wrong (The Hacker News, 2026-10-08; Google, 2026-10-06). Chrome blocked the Google certificates through its CRLSets mechanism and Google had the authorities revoke them; Certificate Transparency data then surfaced further organizations, among them leading global brands, whose certificates Chrome also blocked (Google, 2026-10-06).

The Hacker News' own review of public logs found 12 certificates for seven Google and YouTube names, 11 issued by Let's Encrypt and one by ZeroSSL, first logged on 2026-09-22 (.gh), 2026-09-25 (.sl) and 2026-09-27 (.as) and revoked between 2026-09-26 and 2026-10-01 (The Hacker News, 2026-10-08), and a Let's Encrypt staff member confirmed that certificates for Google and YouTube were issued and revoked (Let's Encrypt community forum, 2026-10-07). Google's post does not name the attackers, say how the registries were compromised, or say whether any certificate was used to pose as a Google site or read users' data (The Hacker News, 2026-10-08), and it names only these three registries (Google, 2026-10-06).

Triage: a valid, correctly chained certificate is no longer evidence that a site is genuine once registry DNS can be changed. In the logs The Hacker News reviewed, every other certificate for google.com.gh, google.sl and google.as came from Google's own authority, while the 12 unauthorized ones came from Let's Encrypt and ZeroSSL, so an issuing authority or account outside your inventory, especially several certificates for one registry's names logged within hours, is the discriminator (The Hacker News, 2026-10-08).

During these hijacks, attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as domains belonging to other organizations.

we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users.

Google Chrome Secure Web and Networking Team 2026-10-06

The 12 certificates are for seven domains. Let's Encrypt issued 11 of them and ZeroSSL issued one.

The Hacker News 2026-10-08

Yes, certificates for Google and Youtube were issued, and have been revoked.

Let's Encrypt community forum 2026-10-07
incident11 Oct 03:36Zmulti-sourceOpen finding →

explore in graph

Where this entity is cited

  • Threats1

Source distribution

  • blog.google1 (33%)
  • community.letsencrypt.org1 (33%)
  • thehackernews.com1 (33%)