www.malwarebytes.com 8 Oct 2026, 15:53 UTC

Attackers Hijack Three Country Domains to Impersonate Google and Others

Attackers Hijack Three Country Domains to Impersonate Google and Others
CyberSIXT Evidence Panel Source marked as original reporting

ATTACKERS have hijacked three country-code top-level domain namespaces—.gh (Ghana), .sl (Sierra Leone) and .as (American Samoa)—to impersonate Google and other services. By compromising the infrastructure behind these ccTLDs, they were able to pass domain verification checks and obtain legitimate-looking HTTPS certificates for domains they did not control.

This is not a breach of encryption or Google systems; rather, it exploits the DNS and certificate verification processes to make phishing attempts appear authentic and to redirect traffic to attacker‑controlled servers.

The risk extends beyond sites simply using those country endings, since attackers can impersonate trusted services from anywhere and exploit users who trust the familiar address or padlock icon. Google reported blocking unauthorized certificates for its properties in Chrome and coordinated with certificate authorities to revoke them, and similar steps were taken for other organisations.

The underlying issue is an infrastructure one: control of DNS records can be leveraged to demonstrate apparent control of a domain, enabling the issuance of valid certificates and convincing, redirected traffic. Practically, the response involves infrastructure-level fixes by domain operators to restore control, revoke or block existing certificates, and prevent further issuance, while users are urged to keep software updated, heed certificate warnings, and verify sensitive actions through separate channels.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline