Back Darkreading 'Phantom Squatting': An Emerging AI
LLMs consistently hallucinate Web domains for legitimate brands that attackers can register for malicious activity in a difficult-to-detect attack vector.
Cybercriminals are taking advantage of a new large language model (LLM)-driven attack vector called "phantom squatting" to threaten the software supply chain by registering nonexistent domains linked to legitimate brands to intercept traffic generated by AI systems. One attacker even used an AI coding assistant to build a full phishing kit targeting a high-risk phantom domain that researchers had identified earlier.
LLMs consistently hallucinate Web domains for legitimate brands, and this leaves the door open for cybercriminals to exploit of these domains, according to research from Palo Alto Networks' Unit 42 published June 30. The researchers analyzed 913 global brands via 685,339 URL queries across multiple configurations of two distinct LLM models, which generated 250,000 hallucinated domains. They exist alongside the more than 13,220 confirmed malicious URLs related to the brands, the researchers found.
Unit 42 compared hallucinations of Web domains to how LLMs frequently hallucinate software package names that do not exist in any registry. "Just as an LLM might hallucinate a library name, it can generate fictitious domains for Web portals, API endpoints, or corporate services for a target brand," Unit 42 researchers wrote in the report . People making requests to AI assistants that are directed to the phantom portals are then at risk for malicious activity hiding behind them, they said.
Given this, and the fact that LLMs now exist "as a trusted supply chain dependency" across many enterprises, these hallucinated domains are emerging as a significant threat stemming from the use of AI assistants across the enterprise.
One exploit path is if a coding assistant generates a plausible but unregistered benefits portal URL, which would allow an adversary to preemptively register it. Another is if an AI research agent produces a plausible banking portal domain that an adversary could have already registered to capture traffic, according to Unit 42. A third way is if a developer integrates an AI-generated API endpoint into their code, unknowingly directing application data to an attacker-controlled server.
"The attack chain is simple: Probe models for invented domains that appear repeatedly, register the most useful names, place phishing or malicious content behind them, and wait for a person (or, increasingly, an autonomous agent) to follow the recommendation," Johan Edholm, security engineer and co-founder at Detectify, tells Dark Reading. "It's cheap, repeatable, and scalable, which is what actually makes an attack dangerous."
Phantom squatting is related to typosquatting, with a key difference, he says. Typosquatting waits for someone to mistype a known domain, while phantom squatting waits for a model to invent a plausible one to which users are directed.
This makes detection of the vector more difficult, "because the domain may sit outside the predictable variations defenders normally monitor, and a newly registered domain begins with little or no reputation history," Edholm says.
Unit 42’s proactive monitoring of high-priority hallucinated domains detected registrations of phantom domains by would-be attackers 18 to 51 days after initial identification, they said. In one case, this led to the flagging of a "high-risk" postal service e-commerce domain 23 days before registration that later was used as the victim-facing site for a phishing kit called "Montana Empire."
The attacker used an AI coding assistant to build the full phishing kit, including scraping legitimate storefronts, building the PHP backend, and establishing a Telegram -based command-and-control (C2) before registering the domain, which was later used for credential theft.
"This case demonstrates the full cycle of the phantom squatting supply chain threat model," the researchers observed. "The adversary used AI systems to generate attack tooling against infrastructure identified by our discovery pipeline 23 days earlier. Both parties arrived at the spoofed domain via the same mechanism, the LLM's internal prediction of a structurally inevitable hallucination for the target brand."
Unit 42 found additional cases in which phantom squatting was used to target national postal services and other sectors with phishing and a malicious Android application.
The danger in attackers abusing phantom squatting is that the delivery mechanism for the malicious activity has already been sanctioned by the system, Edholm says. "The recommendation arrives through a trusted assistant rather than a phishing email, so it inherits credibility the attacker never had to earn, and it bypasses defenses that depend on a domain having a bad reputation first," he explains.
The vector can also potentially evolve from not only providing misleading answers to questions or recommendations, but to executing "an automated supply chain compromise without ever requiring a human click," Edholm says. "That's the direction to plan for: the point of failure shifts from a person following bad advice to a system acting on it on their behalf."
To protect against the existing threat and prepare for the future, Edholm recommends that organizations set up security protocols that verify URLs against authoritative documentation or approved allowlists, as well as prevent AI agents from connecting freely to arbitrary new domains. They also should tightly limit the credentials and data that those systems can access. "In short," he advises, "don't let a confident-sounding recommendation become an action without an independent check standing in between."
Elizabeth Montalbano is freelance writer, editor, and journalist with 30 years of professional experience and a master's degree from Arizona State University. Her areas of expertise include enterprise technology, cybersecurity, business, and culture. During her long career, Elizabeth has lived and worked as a full-time journalist in Phoenix, San Francisco, and New York City. She specializes in news coverage and analysis, using her years of experience to look at the current state of cybersecurity with a critical gaze. She currently resides in a village on the southwest coast of Portugal, where in her free time she enjoys surfing, hiking with her dogs, growing plants, and playing and performing as a singer and musician.
The State of Cloud Security: The Latest Challenges
The total economic impact™ of Snyk
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Practical Zero Trust Implementation on a Budget in the Age of Mythos
Building a Risk Based Vulnerability Management Program
Threat Hunting That Gets Big Results Despite Small Budgets
Say Yes to AI: Securing Innovation Without Compromise
Zero Trust Identity: Beyond Traditional Authentication
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
