As cited
Copy frozen at (site build).
threat intel
Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware
Attackers are purchasing domains that large language models (LLMs) hallucinate or fabricate, then hosting phishing and malware on those nonexistent addresses to capture traffic directed by AI tools. Security researchers at Palo Alto Networks' Unit 42 have documented this technique, termed phantom squatting, actively occurring in real-world attacks.
Why it matters: Organizations and users relying on LLM-generated web addresses are at risk of being redirected to attacker-controlled phishing and malware sites; security teams should educate users on the unreliability of AI-suggested domains and monitor for fraudulent registrations of hallucinated addresses.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware
Attackers are registering domains that large language models (LLMs) hallucinate and reference in their outputs, a technique researchers call phantom squatting. Once registered, adversaries host phishing pages on these fake domains to capture traffic from users following LLM-generated suggestions. Palo Alto Networks' Unit 42 has documented active exploitation of this attack pattern.
Why it matters: Organizations and users relying on LLM outputs for domain validation or navigation face increased phishing risk from non-existent domains, and security teams should monitor for similar phantom squatting campaigns targeting their industry or user base.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware
Attackers are registering domains that large language models (LLMs) hallucinate and reference in their outputs, a technique researchers call phantom squatting. Once registered, adversaries host phishing pages on these fake domains to capture traffic from users following LLM-generated suggestions. Palo Alto Networks' Unit 42 has documented active exploitation of this attack pattern.
Why it matters: Organizations and users relying on LLM outputs for domain validation or navigation face increased phishing risk from non-existent domains, and security teams should monitor for similar phantom squatting campaigns targeting their industry or user base.
- Source published
- First seen by Cybersecurity Tracker