CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 52

As cited

Copy frozen at (site build).

threat intel

Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware

Attackers are purchasing domains that large language models (LLMs) hallucinate or fabricate, then hosting phishing and malware on those nonexistent addresses to capture traffic directed by AI tools. Security researchers at Palo Alto Networks' Unit 42 have documented this technique, termed phantom squatting, actively occurring in real-world attacks.

Why it matters: Organizations and users relying on LLM-generated web addresses are at risk of being redirected to attacker-controlled phishing and malware sites; security teams should educate users on the unreliability of AI-suggested domains and monitor for fraudulent registrations of hallucinated addresses.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware

Attackers are registering domains that large language models (LLMs) hallucinate and reference in their outputs, a technique researchers call phantom squatting. Once registered, adversaries host phishing pages on these fake domains to capture traffic from users following LLM-generated suggestions. Palo Alto Networks' Unit 42 has documented active exploitation of this attack pattern.

Why it matters: Organizations and users relying on LLM outputs for domain validation or navigation face increased phishing risk from non-existent domains, and security teams should monitor for similar phantom squatting campaigns targeting their industry or user base.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware

Attackers are registering domains that large language models (LLMs) hallucinate and reference in their outputs, a technique researchers call phantom squatting. Once registered, adversaries host phishing pages on these fake domains to capture traffic from users following LLM-generated suggestions. Palo Alto Networks' Unit 42 has documented active exploitation of this attack pattern.

Why it matters: Organizations and users relying on LLM outputs for domain validation or navigation face increased phishing risk from non-existent domains, and security teams should monitor for similar phantom squatting campaigns targeting their industry or user base.

VendorsPalo Alto Networks
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary