ccTLD Registrar Hijacks

231 views
Skip to first unread message

Wayne

unread,
Oct 7, 2026, 5:26:03 PM (2 days ago) Oct 7
to dev-secur...@mozilla.org

The tldr is that Chrome discovered widespread domain hijacks happening on the .gh, .sl, and .as ccTLDs. While there's little information publicly beyond that, I did look into it.

Having checked CT logs through Censys, and cross-referencing against the CRLSet (10823) I've pieced together the certificates. See the attached file for the 102 certificates - these are all on the CRLSet.

There are 3 main bursts of compromises:
09-22: .gh, starting on a government site, pausing for an hour, and then just hitting common brand tlds for the next 2 hours. 23 certs total.

09-25: .sl, presumably with cybersecurity.gov.sl first - ZeroSSL scrubbing issuance time makes tracing this harder. This is a much longer compromise lasting at least 11 hours. 69 certs.

09-27: .as, only 10 certificates but its a more focused set of domains and lasts at least 19 hours.

There aren't any interesting issuance practices that stand out. The CSRs are minimal, go through what looks like certbot defaults, but there is an infrequent ECC wildcard -> RSA regular double-issue practice that stands out (see below).

As part of this I looked a bit more into keyCompromise events and potentially overlooked siblings. In researching this I did grab every CT issued certificate from 09-15 to 10-02 for the 3 ccTLDs. Also did targeted queries for government TLDs from 09-01 to see if there was any potential prior incident, and checked against normal issuance patterns. I don't think I overlooked anything here.

28/63 attacked domains: EC wildcard -> RSA within 2h without the wildcard. Across the same ccTLDs and time period only 0.3% share that characteristic. and most of those share one hosting platform.

If anyone can see any more interesting details in the certificates then feel free to mention. I've included as much information as I can short of including the certificates directly - but there's links to crt.sh and Censys for them and I do have local copies if a researcher requires them.
cctld-hijack-certificates.csv

Wayne

unread,
Oct 8, 2026, 9:15:20 AM (yesterday) Oct 8
to dev-secur...@mozilla.org, Wayne
I had a private request to look into the .ug hijack back in May. Here's the data for that, noting that CRLset is only from yesterday and these are about expired domains so them being missing is expected.

2 bursts:
05-17: 7 certs, active for an hour and only focused on google/youtube/microsoft.

05-19/20: 32 certs, active for under 2 hours. wider spread of companies involved here.

This incident is pretty publicly documented however with attribution existing. There isn't much to add that isn't already part of the public record there.
ug-certificates.csv
Reply all
Reply to author
Forward
0 new messages