HomeSecurityPhantom Squatting: Hackers exploit AI hallucinations for phishing

Phantom Squatting: Hackers exploit AI hallucinations for phishing

Phantom squatting is a new and extremely dangerous cyberattack technique in which attackers register domains that AI models themselves “invent” — and use them for phishing and malware distribution . The technique was detected and analyzed by Palo Alto Networks ’ Unit 42 team , which warns that the phenomenon is already active online and is growing rapidly. Unlike traditional phishing attacks that require malicious emails or advertisements, phantom squatting exploits users’ trust in AI tools.

See also: Phantom Stealer: Phishing attack with ISO images targets Russia

phantom squatting AI hallucination phishing malware domains
Phantom Squatting: Hackers exploit AI hallucinations for phishing

The problem stems from a structural flaw in Large Language Models (LLMs), known as hallucination: the models generate URLs that appear plausible based on their linguistic patterns, without verifying whether those domains actually exist. An attacker only needs to “query” the model repeatedly for well-known companies and services, identify the imaginary domains it generates, and then register them for a few dollars before someone else does. The result: a domain with zero threat history, which automatically bypasses most security systems.

To measure the scale of the problem, Unit 42 submitted 685,339 queries to two different AI models, covering 913 well-known companies from sectors such as technology, finance, healthcare, government and gambling. The models produced a total of 2.1 million URLs . Of these, 13,229 had already been flagged as malicious by threat intelligence feeds, while about 250,000 were unregistered domains — ready to be registered by any attacker. It is worth noting that 67.2% of the detected malicious URLs were used for malware (drive-by downloads, exploit kits), 16.2% for phishing and 3% as command-and-control (C2) infrastructure .

Phantom Squatting: How the attack cycle works

The attack follows four phases: Discover, Act, Lure, and Bypass. In the Discover phase, the attacker uses AI models to detect domains that are systematically “invented.” In the Act phase, they register the domain. In the Lure phase, they set up malicious infrastructure — a phishing kit, a website clone, or a malicious application. In the Bypass phase, the new domain has no threat history, so filtering systems don’t block it. A notable finding of the research is that different models often “invent” the exact same domain for the same query, which makes the next target easily predictable. Increasing the “creativity” (temperature) of the model simply produces more imaginary domains.

Two real-life cases reveal just how mature this threat is. On March 8, 2026 , Unit 42 ’s system predicted that AI models would “invent” a domain that resembled the online marketplace of a national postal service. Both models produced it at every temperature setting. Just 23 days later , on March 31, an attacker registered that exact domain and installed a phishing kit called Montana Empire . The kit replicated the real online store in real time, stealing card numbers, bank transfer details, and national IDs. A Telegram bot allowed the operator to manually approve victims’ OTPs. The telltale sign: project files and logs showed that the criminal had built the kit with the help of an AI coding assistant — meaning both attacker and defender arrived at the same fictional domain in the same way.

See also: Hackers use news sites and social media to spread malware

Gaslight macOS malware prompt injection AI analysis tools
Phantom Squatting: Hackers exploit AI hallucinations for phishing

Phantom Squatting and slopsquatting: The evolution of the AI-driven threat

In the second case, Unit 42 detected a hallucinated postal service domain 51 days before the attacker registered it. The attacker created a pixel-perfect clone of the official page, added a fake 4.8-star rating and claimed over 2 million users , and used it to distribute a malicious Android app. Other detected domains mimicked a major UAE bank that an attacker had already been abusing for almost a year, a European bank, and sports betting websites targeting users in Bangladesh .

Phantom squatting is an evolution of slopsquatting — the technique where attackers register fake software package names that AI coding tools invent. A large USENIX found that code generation models systematically suggest package names that don’t exist, and the PhantomRaven turned this very behavior into malware hidden in 126 npm packages with over 86,000 installs. Now, the risk is shifting from fake software packages to fake web infrastructure, API endpoints, and corporate portals.

Unit 42 researchers emphasize that phantom squatting “ exploits a structural property of LLM architectures that remains inherently unpatchable .” This means there is no patch — the solution must come from the defense side. Organizations are urged to implement advanced URL filtering designed for the modern AI ecosystem, use autonomous AI agents to proactively collect and register hallucinated domains before attackers do, and always verify links provided by AI tools before following them. The 18- to 51-day prediction window identified by Unit 42 shows that proactive defense is possible — as long as it is activated in a timely manner.

See also: Phantom Goblin delivers stealer malware

Phantom Squatting: Hackers exploit AI hallucinations for phishing

Phantom squatting signals a broader shift in the cyberthreat landscape: the output of AI models becomes the input for attacks. Developers, AI agents, and security teams act on AI-generated links, and that trust is leveraged as a weapon. This threat represents a critical shift in cybercrime, turning trust in AI into a weapon against users and supply chains.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS