Google says counterfeit TLS certificates of major services stolen by hackers
Attackers hijacked three country-code domains to obtain fraudulent HTTPS certificates for major websites Fake certificates could enable convincing traffic interception and phishing against affected domains Google revoked the certificates, protected Chrome users, and warned impacted organizations Cybercriminals recently managed to hijack three country-code top-level domains ( ccTLDs ) and used the access to generate HTTPS certificates covering several Google domains, as well as those belonging to other organizations.
Google said the attack placed thousands of websites at risk, but stressed that the certificates have since been revoked.
According to Google, the domains that were hijacked are .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa).
During the attacks, the threat actors modified authoritative DNS records, obtaining HTTPS certificates covering not just Google, but other organizations, too.
In other words, any website operating on these domains was at risk, as well as all of the visitors.
By manipulating authoritative DNS records, threat actors could redirect traffic away from legitimate websites and towards malicious ones under their control, all the while telling users they were visiting the legitimate one by showing the padlock icon.
Visitors entering login credentials, payment information, or other data, would easily lose them to the attackers, and depending on the circumstances, they could also end up installing malware.
“Due to the nature of the attacks, we have no reason to believe the Certification Authorities (CAs) that issued the impacted certificates did anything wrong,” Google said.
Affecting major brands Although Google blocked the unauthorized certificates in Chrome and worked to have them revoked, it warned that its interventions might not have identified every affected domain or protected users of other browsers .
“As part of our usual incident response process, we immediately acted to protect users by blocking the use of unauthorized certificates for Google properties in Chrome via CRLSets,” Google added.
“We also worked with the issuing CAs to ensure the certificates were revoked to protect users in clients other than Chrome.” The risk for websites wasn’t theoretical.
Google said “several leading global brands and widely used online services” were impacted by these attacks, and stressed that all of the certificates used in these attacks were blocked.
“Where possible, we reached out to impacted organizations to alert them to our findings and actions,” Google concluded.
The company did not say which of its own domains were affected, and did not want to name the victim companies.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.