# Phantom Squatting: Adversaries Weaponize AI-Hallucinated Domains as Supply Chain Attack Vector

> Unit 42 (Palo Alto Networks) documents 'phantom squatting,' where adversaries systematically probe LLMs to discover domains the models hallucinate for legitimate brands, then preemptively register those domains before defenders detect them. Analysis of 913 global brands across 685,339 adversarial prompts against two production LLMs generated 2.1 million unique URLs, of which 13,229 (0.61%) were confirmed malicious and roughly 250,000 unregistered phantom domains remain immediate registration opportunities for attackers.

- **Published:** 2026-06-30T00:00:00Z
- **Last reviewed:** 2026-06-30T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1018
- **ID:** TL-2026-1018
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Unit 42 researchers (Keerthiraj Nagaraj, Diva-Oriane Marty, Beliz Kaleli, Oleksii Starov) systematically prompted two production LLMs — 'LLM1' (a production-optimized mini-class enterprise model, April 2025 build) and 'LLM2' (a low-latency lite-class frontier model, June 2025 build) — with 685,339 adversarial prompts referencing 913 global brands spanning Technology, Finance, Healthcare, E-commerce, Government, Gambling, and Logistics. The prompts, run across three temperature configurations (Precise T=0.1, Balanced T=0.7, Creative T=1.5), asked for customer support links, corporate portal logins, and software download pages. Because LLMs do not verify link existence before responding, they predicted plausible-looking URLs based on training-data patterns, generating 2.1 million unique URLs. Of these, 13,229 (0.61%) resolved to currently malicious infrastructure, 41,313 (1.90%) were high-risk parked/opportunistic domains, and 809,455 (37.28%) were non-existent domains (NXD) — roughly 250,000 of which remain unregistered and available for immediate adversarial preemption. LLM1 produced a 44.6% overall hallucination rate versus LLM2's 27.5%, though LLM2 skewed more toward higher-value subdomain- (45.1%) and domain-level (20.0%) hallucinations versus LLM1's path-level bias (56.6%), expanding the registerable attack surface. Confirmed malicious infrastructure broke down as 67.2% malware (drive-by downloads, exploit kits), 16.2% phishing (credential harvesting, brand impersonation), 13.7% grayware (adware/PUP installers), and 3.0% command-and-control. The technique creates a distinct supply-chain risk for autonomous AI agents, which can execute web requests to hallucinated domains without human verification; newly registered phantom domains carry zero reputation history, bypassing traditional URL/reputation filtering. Unit 42 documented multiple real-world exploitation windows: the 'Montana Empire' campaign (March 8-31, 2026, 23-day adversarial exploitation window/AEW) cloned a national postal service e-commerce marketplace storefront in real time, using an AI coding assistant to build a PHP-based phishing kit (7.96 MB ZIP archive, SHA256 eb07edaa2786cfddfa4c15526168f2200d85300aee0a8f253b32d2462a7b0bcd) that performed dual-channel payment interception (credit cards and IBAN transfers) plus national identity document harvesting, controlled through a Telegram-based C2 panel branded 'Kimseye Güvenme' ('Trust No One') supporting real-time OTP relay by a human operator. A second campaign (February 18-April 10, 2026, 51-day AEW) distributed a malicious Android APK (12.6 MB, SHA256 2202a30daad9928ef47cca5f4ab04ce083692a94428e386fa01c2dd44557e34b) impersonating a national postal delivery service app via a pixel-accurate brand-clone landing page with fabricated social-proof (4.8-star rating, '2M+ users'), delivered out-of-band outside official app marketplaces. Additional detections included a Bangladesh-targeted sports-betting credential harvester (45-day AEW), a second sports-betting lookalike registered 18 minutes after the first using identical infrastructure (40-day AEW) — indicating orchestrated regional targeting of Bengali-language markets with Bangladeshi Taka payment processing — a re-registered European retail-bank lookalike (35-day AEW), and an 11-month-old UAE commercial-bank lookalike historically validating corporate database-admin targeting. Unit 42 recommends proactive hallucination-surface mapping (simulating adversarial prompting against target LLMs to preemptively identify and monitor phantom domains), domain-registration event-stream monitoring, multi-signal verification (threat intel + content crawling + ownership analysis) before trusting AI-suggested URLs, and validating autonomous-agent web-request output before execution.

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1592 Gather Victim Host Information
- T1598 Phishing for Information
- T1590 Gather Victim Network Information
- T1199 Trusted Relationship
- T1583 Acquire Infrastructure
- T1587 Develop Capabilities
- T1608 Stage Capabilities
- T1566 Phishing
- T1204 User Execution
- T1187 Forced Authentication
- T1040 Network Sniffing
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1102 Web Service
- T1657 Financial Theft

## Sources

- [Phantom Squatting: AI-Hallucinated Domains as Supply Chain Threat](https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/)
- [What is Phantom Squatting? Protecting Against AI Hallucination Risks](https://live.paloaltonetworks.com/t5/community-blogs/how-ai-hallucinations-create-new-security-risks-for-users/ba-p/1255418)
- [Unit42_Intel: Montana Empire is an AI-assisted phishing kit mimicking a national postal service's e-commerce platform](https://x.com/Unit42_Intel/status/2041879323963982303)
- [pan-unit42/iocs — Indicators from Unit 42 Public Reports](https://github.com/pan-unit42/iocs)
- [PaloAltoNetworks/Unit42-Threat-Intelligence-Article-Information](https://github.com/PaloAltoNetworks/Unit42-Threat-Intelligence-Article-Information)
- [Cybersquatting: Attackers Mimicking Domains of Major Brands Including Facebook, Apple, Amazon and Netflix to Scam Consumers](https://unit42.paloaltonetworks.com/cybersquatting/)
- [The most popular brand websites that hackers use for typosquatting campaigns](https://cyberscoop.com/typosquatting-palo-alto-networks-unit-42-wells-fargo-netflix-faceboook-microsoft/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1018
