ccTLD Hijacks Expose DNS and Certificate Authority Weaknesses
Attackers exploited weaknesses at the country-code top-level domain (ccTLD) registry level to modify DNS records and fraudulently obtain HTTPS certificates for Google and other organizations' domains — without ever compromising those organizations directly. This illustrates that even well-resourced companies are vulnerable to infrastructure they do not control, such as upstream registries and certificate authorities. The attack undermines trust in core internet security mechanisms, including HTTPS and PKI. Without proactive monitoring of Certificate Transparency logs and restrictive CAA records, domain owners may not detect unauthorized certificate issuance until significant damage is done.
Tactical Insight
Immediate actions
- Add restrictive CAA (Certification Authority Authorization) DNS records to explicitly limit which CAs are authorized to issue certificates for your domains.
- Subscribe to Certificate Transparency log monitoring services (e.g., crt.sh, Google's Cert Spotter) to receive alerts for any unauthorized certificate issuance.
Long-term improvements
- Implement DNSSEC signing for all organizational domains to cryptographically protect DNS records from unauthorized modification.
- Establish a formal domain asset inventory and assign ownership responsibility for all registered domains, including country-code variants.
- Work with domain registrars to enable registry lock services that require out-of-band verification before DNS changes are permitted.
Detection measures
- Configure automated alerting for unexpected changes to DNS records across all owned domains.
- Integrate Certificate Transparency log feeds into your SIEM to correlate unauthorized certificate events with other anomalous activity.