Threat reportSupply ChainTL-2026-1018
Phantom Squatting: Adversaries Weaponize AI-Hallucinated Domains as Supply Chain Attack Vector
Phantom Squatting (TL-2026-1018), also tracked as Phantom Squatting, is a high-severity supply-chain compromise, first published 2026-06-30. It has no confirmed attribution, affects Multiple (913 global brands) Brand-facing customer portals, e-commerce, maps to 16 MITRE ATT&CK techniques (T1005, T1040, T1071), and is covered by 9 detection rules and 21 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 16MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 21Indicators of compromise
Key facts for TL-2026-1018
- Threat ID
- TL-2026-1018
- Also known as
- Phantom Squatting, AI Hallucination Squatting, LLM Domain Hallucination Squatting
- Severity
- HIGH
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- technology, finance, health, ecommerce, government administration, gambling, logistics, postal, banking
- Target regions
- Global, South Asia, Europe, Middle East
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in Phantom Squatting
Malware and tooling: Montana Empire, Telegram-based C2 relay panel (admin panel branded 'Kimseye Güvenme' / 'Trust No One')
How Phantom Squatting works
Unit 42 (Palo Alto Networks) documents 'phantom squatting,' where adversaries systematically probe LLMs to discover domains the models hallucinate for legitimate brands, then preemptively register those domains before defenders detect them. Analysis of 913 global brands across 685,339 adversarial prompts against two production LLMs generated 2.1 million unique URLs, of which 13,229 (0.61%) were confirmed malicious and roughly 250,000 unregistered phantom domains remain immediate registration opportunities for attackers.
Unit 42 researchers (Keerthiraj Nagaraj, Diva-Oriane Marty, Beliz Kaleli, Oleksii Starov) systematically prompted two production LLMs — 'LLM1' (a production-optimized mini-class enterprise model, April 2025 build) and 'LLM2' (a low-latency lite-class frontier model, June 2025 build) — with 685,339 adversarial prompts referencing 913 global brands spanning Technology, Finance, Healthcare, E-commerce, Government, Gambling, and Logistics. The prompts, run across three temperature configurations (Precise T=0.1, Balanced T=0.7, Creative T=1.5), asked for customer support links, corporate portal logins, and software download pages. Because LLMs do not verify link existence before responding, they predicted plausible-looking URLs based on training-data patterns, generating 2.1 million unique URLs. Of these, 13,229 (0.61%) resolved to currently malicious infrastructure, 41,313 (1.90%) were high-risk parked/opportunistic domains, and 809,455 (37.28%) were non-existent domains (NXD) — roughly 250,000 of which remain unregistered and available for immediate adversarial preemption. LLM1 produced a 44.6% overall hallucination rate versus LLM2's 27.5%, though LLM2 skewed more toward higher-value subdomain- (45.1%) and domain-level (20.0%) hallucinations versus LLM1's path-level bias (56.6%), expanding the registerable attack surface. Confirmed malicious infrastructure broke down as 67.2% malware (drive-by downloads, exploit kits), 16.2% phishing (credential harvesting, brand impersonation), 13.7% grayware (adware/PUP installers), and 3.0% command-and-control. The technique creates a distinct supply-chain risk for autonomous AI agents, which can execute web requests to hallucinated domains without human verification; newly registered phantom domains carry zero reputation history, bypassing traditional URL/reputation filtering. Unit 42 documented multiple real-world exploitation windows: the 'Montana Empire' campaign (March 8-31, 2026, 23-day adversarial exploitation window/AEW) cloned a national postal service e-commerce marketplace storefront in real time, using an AI coding assistant to build a PHP-based phishing kit (7.96 MB ZIP archive, SHA256 eb07edaa2786cfddfa4c15526168f2200d85300aee0a8f253b32d2462a7b0bcd) that performed dual-channel payment interception (credit cards and IBAN transfers) plus national identity document harvesting, controlled through a Telegram-based C2 panel branded 'Kimseye Güvenme' ('Trust No One') supporting real-time OTP relay by a human operator. A second campaign (February 18-April 10, 2026, 51-day AEW) distributed a malicious Android APK (12.6 MB, SHA256 2202a30daad9928ef47cca5f4ab04ce083692a94428e386fa01c2dd44557e34b) impersonating a national postal delivery service app via a pixel-accurate brand-clone landing page with fabricated social-proof (4.8-star rating, '2M+ users'), delivered out-of-band outside official app marketplaces. Additional detections included a Bangladesh-targeted sports-betting credential harvester (45-day AEW), a second sports-betting lookalike registered 18 minutes after the first using identical infrastructure (40-day AEW) — indicating orchestrated regional targeting of Bengali-language markets with Bangladeshi Taka payment processing — a re-registered European retail-bank lookalike (35-day AEW), and an 11-month-old UAE commercial-bank lookalike historically validating corporate database-admin targeting. Unit 42 recommends proactive hallucination-surface mapping (simulating adversarial prompting against target LLMs to preemptively identify and monitor phantom domains), domain-registration event-stream monitoring, multi-signal verification (threat intel + content crawling + ownership analysis) before trusting AI-suggested URLs, and validating autonomous-agent web-request output before execution.
MITRE ATT&CK techniques used in TL-2026-1018
Collection
Credential Access
T1040 Network Sniffing; T1187 Forced Authentication
Command and Control
T1071 Application Layer Protocol; T1102 Web Service
Initial Access
T1199 Trusted Relationship; T1566 Phishing
Execution
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1608 Stage Capabilities
Reconnaissance
T1589 Gather Victim Identity Information; T1590 Gather Victim Network Information; T1592 Gather Victim Host Information; T1598 Phishing for Information
Impact
Affected products and versions in Phantom Squatting
- Multiple (913 global brands) — Brand-facing customer portals, e-commerce marketplaces, postal/logistics services, banking portals, sports-betting platforms
Vulnerable versions: Any brand referenced in LLM training data whose customer-facing URLs the model has not been grounded to verify - Unnamed LLM vendors — LLM1 (production-optimized mini-class enterprise model, April 2025 build); LLM2 (low-latency lite-class frontier model, June 2025 build)
Vulnerable versions: LLM1 baseline (44.6% hallucination rate); LLM2 baseline (27.5% hallucination rate)
Remediation for Phantom Squatting
Immediate actions
- Enroll high-value brand domains and predictable AI-hallucinated variants in registration event-stream / newly-registered-domain monitoring so lookalikes are flagged at registration time rather than after weaponization
- Deploy Advanced URL Filtering and Advanced DNS Security (or equivalent) to block access to newly registered, zero-reputation domains at the network egress layer
- Block/alert on Telegram Bot API traffic (api.telegram.org) originating from unexpected endpoint or server-side processes, a common low-cost C2/exfil channel for AI-built phishing kits
- Warn customers of high-value brands (banking, postal/logistics, sports betting) about out-of-band APK distribution and lookalike login pages during active AEW windows
Workarounds
- Restrict autonomous AI agents from executing unauthenticated outbound web requests to domains outside an allowlist until multi-signal verification completes
- Require human-in-the-loop confirmation before an AI agent acts on a URL it generated rather than retrieved from a verified source
Longer-term hardening
- Run proactive hallucination-surface mapping: simulate adversarial prompting (varied temperature configurations) against the LLMs your own users/agents rely on to preemptively discover and pre-register or monitor brand-relevant phantom domains before attackers do
- Deploy AI runtime security controls (e.g. Prisma AIRS or equivalent) and agentic endpoint security to validate any URL an autonomous AI agent is about to fetch before the request executes
- Establish multi-signal verification (threat intelligence + content crawling + WHOIS/ownership analysis) as a gate before trusting any AI-suggested or AI-agent-generated URL in production workflows
- Commission a formal AI security assessment of internally deployed LLMs/agents to quantify hallucination rate and structural hallucination pattern (path- vs subdomain- vs domain-level) as an attack-surface metric
Timeline of Phantom Squatting
- LLM1 (production-optimized mini-class enterprise model) baseline used for Unit 42's adversarial hallucination study, exhibiting a 44.6% hallucination rate across the test corpus.
- LLM2 (low-latency lite-class frontier model) baseline used for the study, exhibiting a 27.5% hallucination rate but a higher proportion of higher-value subdomain- and domain-level hallucinations.
- Unit 42's discovery pipeline first identifies hallucinated URLs for the postal-delivery-app domain, marking the start of the 51-day adversarial exploitation window for the APK campaign.
- Unit 42 detects the Montana Empire postal e-commerce hallucinated domain in its monitoring pipeline (13 distinct hallucinated URLs surfaced across both tested LLMs), starting the 23-day adversarial exploitation window.
- Montana Empire campaign's documented adversarial exploitation window closes after 23 days of active credential and payment-data interception.
- Adversary registers the Montana Empire lookalike domain and deploys the AI-assisted PHP phishing kit the same day, cloning a national postal service e-commerce marketplace storefront in real time.
- Postal-service APK impersonation campaign's documented adversarial exploitation window closes after 51 days.
- Unit 42 (Palo Alto Networks) publishes 'Phantom Squatting: AI-Hallucinated Domains as Supply Chain Threat,' documenting the 685,339-prompt, 913-brand study and associated real-world campaigns.
Sources cited for Phantom Squatting
- Phantom Squatting: AI-Hallucinated Domains as Supply Chain Threat
- What is Phantom Squatting? Protecting Against AI Hallucination Risks
- Unit42_Intel: Montana Empire is an AI-assisted phishing kit mimicking a national postal service's e-commerce platform
- pan-unit42/iocs — Indicators from Unit 42 Public Reports
- PaloAltoNetworks/Unit42-Threat-Intelligence-Article-Information
- Cybersquatting: Attackers Mimicking Domains of Major Brands Including Facebook, Apple, Amazon and Netflix to Scam Consumers
- The most popular brand websites that hackers use for typosquatting campaigns
Detection coverage for TL-2026-1018
As of 2026-06-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1018 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.