The tldr is that Chrome discovered widespread domain hijacks happening on the .gh, .sl, and .as ccTLDs. While there's little information publicly beyond that, I did look into it.
Having checked CT logs through
Censys, and cross-referencing against the
CRLSet (10823) I've pieced together the certificates. See the attached file for the 102 certificates - these are all on the CRLSet.
There are 3 main bursts of compromises:
09-22: .gh, starting on a government site, pausing for an hour, and then just hitting common brand tlds for the next 2 hours. 23 certs total.
09-25: .sl, presumably with
cybersecurity.gov.sl first - ZeroSSL scrubbing issuance time makes tracing this harder. This is a much longer compromise lasting at least 11 hours. 69 certs.
09-27: .as, only 10 certificates but its a more focused set of domains and lasts at least 19 hours.
There aren't any interesting issuance practices that stand out. The CSRs are minimal, go through what looks like certbot defaults, but there is an infrequent ECC wildcard -> RSA regular double-issue practice that stands out (see below).
As part of this I looked a bit more into keyCompromise events and potentially overlooked siblings. In researching this I did grab every CT issued certificate from 09-15 to 10-02 for the 3 ccTLDs. Also did targeted queries for government TLDs from 09-01 to see if there was any potential prior incident, and checked against normal issuance patterns. I don't think I overlooked anything here.
28/63 attacked domains: EC wildcard -> RSA within 2h without the wildcard. Across the same ccTLDs and time period only 0.3% share that characteristic. and most of those share one hosting platform.
If anyone can see any more interesting details in the certificates then feel free to mention. I've included as much information as I can short of including the certificates directly - but there's links to crt.sh and Censys for them and I do have local copies if a researcher requires them.