Also to note that RS domain is Serbia, who could simply redirect all rust users to malicious domains in a supply chain attack.

How realistic is for a TLD “owner” to take over a domain like this?

Doesn't USA do that all the time with .com and such?

How would that get around the SSL certificate?

If you control the domain, LetsEncrypt will happily issue you a fresh certificate.