Hackers hijack Google domains after breaching ccTLD registries

Summary

Hackers compromised third-party operators managing country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone. This allowed them to modify authoritative DNS records and obtain unauthorized HTTPS certificates for several Google domains, effectively hijacking them.

IFF Assessment

FOE

This incident highlights a successful attack that allowed unauthorized access and control over critical internet infrastructure, posing a significant threat to defenders.

Defender Context

This attack demonstrates the critical importance of supply chain security for domain name services and certificate authorities. Defenders should be aware of the risks associated with third-party compromises and the potential for widespread disruption when core internet infrastructure is targeted.

Read Full Story →