Threat actors are using a new technique called “phantom squatting” to trick AI tools into directing users to phishing sites, according to researchers at Palo Alto Networks’ Unit 42.
Since AI models frequently hallucinate phony information, they sometimes point users to websites that don’t exist. Threat actors are now registering these AI-hallucinated domains and using them to host phishing sites.
“To detect the risk posed by phantom squatting, we analyzed 913 global brands and executed 685,339 URL queries across multiple configurations of two distinct LLM models,” Unit 42 says. “This generated 2.1 million URLs and revealed over 13,229 confirmed malicious URLs. Furthermore, we discovered approximately 250,000 hallucinated domains that remain unregistered, presenting a significant opportunity for adversaries to exploit the software supply chain through preemptive registration.”
This technique exploits users’ trust in AI tools to generate accurate information. Users are more likely to trust a link provided by an AI chatbot than one sent in an unsolicited email or text message.
“Any user or autonomous AI agent that issues a query triggering the hallucinated URL receives an authoritative, high-confidence recommendation to navigate directly to attacker-controlled infrastructure,” the researchers write. “This represents a defining characteristic of the phantom squatting threat. The delivery vector bypasses traditional phishing emails, malvertising or watering hole attacks. Instead, the delivery mechanism is the trusted AI assistant already integrated into the user’s workflow.”
Attackers are quickly adopting this technique, and in at least one case have already incorporated it into a phishing kit called “Montana Empire.”
“Armed with a prioritized inventory of phantom domains, adversaries proceed to preemptively register those most valuable for attacks,” the researchers write. “For generic top-level domains (TLDs), the barriers to entry are negligible. Registration is both economical and nearly instantaneous. Our analysis confirms that threat actors operate with significant speed, often well within the window of any feasible defensive response. In observed real-world telemetry, these domains transitioned from initial registration to active malicious content deployment within hours. In the case of Montana Empire, the adversary had even staged the server-side phishing kit prior to the domain’s registration, demonstrating a highly optimized zero-reputation bypass strategy.”
Unit 42 has the story: Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
