An emergent supply-chain attack vector they term “phantom squatting,” in which large language models (LLMs) routinely hallucinate plausible but nonexistent domains for legitimate brands and adversaries then preemptively register those domains to host phishing kits, malware, and other malicious infrastructure.
The phantom squatting attack lifecycle operates across four distinct phases Discover, Act, Lure, Bypass.
The team executed 685,339 adversarial prompts against 913 global brands and produced some 809,455 NXD (non-existent domain) URLs that normalized to roughly 250,000 unique phantom domains.
Of the total URLs generated, 13,229 were confirmed malicious via threat intelligence and active crawling, with malware delivery representing 67.2% and phishing 16.2% of confirmed threats.
A signature case, dubbed Montana Empire, demonstrates the end-to-end threat: Unit 42’s pipeline flagged a hallucinated postal-ecommerce domain as high-risk 23 days before an attacker registered it and deployed a full phishing kit.
Forensics of the kit revealed an AI coding assistant project directory and tooling used to scrape storefronts, implement a PHP backend, and exfiltrate credentials via a Telegram-based command-and-control interface.
Another detection involved a malicious Android APK served from a hallucinated postal app domain registered 51 days after Unit 42 added it to their watchlist.
These incidents show attackers leveraging AI both to discover promising hallucinations and to accelerate development of weaponized content.
Unit 42 said in a report shared with GBhackers , proactive monitoring detected that attackers registered many hallucinated domains within days to weeks of the models’ outputs; in multiple cases researchers predicted an adversary registration 18–51 days before it occurred.
Phantom squatting exploits a structural weakness in reputation-based defenses. New registrations carry zero historical telemetry, so traditional blocklists, reputation scores, and threat feeds provide no immediate signal.
When an LLM outputs an authoritative-looking URL, humans and autonomous agents often accept and use it without independent verification.
That trust transforms LLM outputs into a new class of supply-chain dependency : a model-generated artifact that can be weaponized at birth.
Sophisticated actors compound this advantage with evasion techniques like redirect cloaking and CAPTCHA gating to delay detection.
Unit 42’s methodology combines a query agent that crafts adversarial prompts, a URL-creator agent that executes prompts across model families and temperatures, and a verification pipeline that enriches results with crawling, ownership analysis, and threat intelligence.
Comparative analysis showed model and temperature effects: one enterprise-optimized LLM yielded a higher NXD rate (44.6%) than the other (27.5%), and the Creative temperature substantially increased hallucination frequency, although the malicious-URL percentage remained stable across configurations indicating hallucination volume.
Defenders can gain lead time by proactively enumerating hallucination surfaces and monitoring registration streams; Unit 42 demonstrated the ability to predict adversary registrations days to weeks in advance and to detect weaponized deployments same day.
Palo Alto Networks products Advanced WildFire, Advanced URL Filtering, Advanced DNS Security, Prisma AIRS, and Koi Agentic Endpoint Security are positioned to mitigate phantom-squatting threats, and the Unit 42 AI Security Assessment can help organizations harden AI usage.
As agentic AI systems increasingly automate web fetches, dependency downloads, and CI/CD integrations, the consequences escalate: an autonomous agent following a hallucinated URL can fetch and execute malicious content without human intervention.
Phantom squatting converts an LLM’s interior mistakes into a proactive adversary playbook, demanding defenders treat model outputs as untrusted third-party artifacts and apply registration monitoring, URL verification, and hardened AI-use policies as part of software supply-chain defense.
Note: IP addresses and domains are intentionally defanged (e.g., [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified a critical vulnerability in SimpleHelp,…
The Gentlemen ransomware group has emerged in 2026 as a highly adaptive and technically sophisticated…
A routine threat-feed alert for a RedLine Stealer command-and-control (C2) IP morphed into a full-scale…
Melbourne, Florida, June 30th, 2026, CyberNewswire OpenMatter Network today announced the launch of its cryptographically…
Fluentd, a widely used open-source data collector for unified logging, has reported several high-impact vulnerabilities…
A sophisticated new botnet family dubbed RustDuck emerged in early 2026, leveraging a two-stage Loader…
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
