Threat reportPhishingTL-2026-1031

Phantom Squatting: Attackers Register AI-Hallucinated Domains to Hijack LLM-Guided Traffic (Montana Empire / PhantomRaven)

highACTIVE

Phantom Squatting (TL-2026-1031), also tracked as Phantom Squatting, is a high-severity phishing campaign, first published 2026-07-01. It has no confirmed attribution, affects Multiple Large Language Models used as chatbots / coding assistants, maps to 27 MITRE ATT&CK techniques (T1016, T1036, T1036.005), and is covered by 9 detection rules and 33 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
27MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
33Indicators of compromise

Key facts for TL-2026-1031

Threat ID
TL-2026-1031
Also known as
Phantom Squatting, AI Hallucination Squatting, Slopsquatting
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
technology, finance, health, government administration, gambling, logistics, ecommerce
Target regions
Global, Middle East, South Asia, Europe, North America
Detection rules
9
Indicators of compromise
33

Malware and tooling in Phantom Squatting

Malware and tooling: Montana Empire, PhantomRaven, AI coding assistant (unspecified), Telegram Bot API

How Phantom Squatting works

Unit 42 (Palo Alto Networks) documents 'phantom squatting': attackers monitor and preemptively register domains that LLMs hallucinate when answering brand-related queries, then serve phishing kits or malware from them to intercept traffic misdirected by AI assistants, chatbots, and coding tools. Across 685,339 adversarial prompts against two production LLMs, researchers generated 2.1 million URLs, of which ~250,000 pointed to unregistered 'phantom' domains, and confirmed attacker registration within 18-51 days of hallucination detection in real-world cases including the 'Montana Empire' postal-service phishing kit and a related npm slopsquatting campaign, PhantomRaven.

Phantom squatting exploits a structural, unpatchable property of LLM architectures: when asked about a brand, product, or API, models sometimes hallucinate plausible but non-existent URLs. Unit 42's four-phase attack lifecycle model — Discover, Act, Lure, Bypass — shows that attackers can query the same LLMs used by victims (via systematic adversarial probing across 913 global brands and 685,339 prompts), identify domains the models consistently hallucinate across temperature settings (a property Unit 42 calls Thermal Hallucination Persistence), and register those domains before defenders do. Because the domains are freshly registered and have no history in threat-intelligence feeds, they achieve 'zero-reputation bypass' against reputation-based URL/DNS filtering. Of 2.1 million URLs generated by two LLMs (a production-optimized enterprise mini-class model released April 2025, and a low-latency frontier lite-class model released June 2025), 13,229 (0.61%) were already flagged malicious, 41,313 (1.90%) were high-risk, and roughly 250,000 pointed to unregistered phantom domains ripe for attacker registration; 809,455 URLs resolved to non-existent domains overall. Malware delivery (drive-by downloads, exploit kits) accounted for 67.2% of malicious/high-risk hits, phishing/credential harvesting 16.2%, grayware 13.7%, and C2 infrastructure 3.0%. Two confirmed cases anchor the research: the 'Montana Empire' kit, an AI-coding-assistant-built phishing platform that cloned a national postal service's e-commerce marketplace within 23 days of the hallucination being detected (predicted 2026-03-08, registered 2026-03-31), using a PHP backend to intercept dual-channel payments (card numbers and IBAN transfers) and national ID documents, exfiltrating in real time via a Telegram bot that also relayed OTPs to a human operator control panel (labeled 'Kimseye Güvenme' — Turkish for 'Trust No One'); and a second postal-service case where a pixel-accurate cloned storefront with fabricated 4.8-star ratings and 2M+ user claims distributed a malicious Android APK, registered 51 days after hallucination detection. Additional confirmed abuse includes Bangladesh-targeted sports-betting phishing domains registered in a coordinated 18-minute window across two brands, a re-registered European bank phishing domain, and a UAE bank domain that a threat actor registered in April 2025 which Unit 42's detection pipeline independently rediscovered as a hallucinated phantom domain 11 months later — validating that AI hallucination and real attacker targeting converge on the same domain names. Unit 42 explicitly ties phantom squatting to the adjacent 'slopsquatting' technique used in the PhantomRaven npm supply-chain campaign (126 malicious packages, 86,000+ installs, active since August 2025), where a threat actor registered npm package names that coding-assistant LLMs hallucinate, using Remote Dynamic Dependencies (RDD) — HTTP-fetched payloads invisible to static dependency scanners — to steal npm tokens, GitHub credentials, and CI/CD secrets at install time. Both campaigns represent the same underlying attack surface: AI systems (chatbots, coding assistants, and increasingly autonomous agents) generating URLs or package names that a human or an agent then trusts and acts on without verification.

MITRE ATT&CK techniques used in TL-2026-1031

Discovery

T1016 System Network Configuration Discovery; T1082 System Information Discovery; T1518 Software Discovery

Defense Evasion

T1036 Masquerading; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Execution

T1059.007 JavaScript; T1204.001 Malicious Link

Command and Control

T1071.001 Web Protocols; T1102.002 Bidirectional Communication

Collection

T1114 Email Collection; T1119 Automated Collection

Initial Access

T1195.001 Compromise Software Dependencies and Development Tools; T1195.002 Compromise Software Supply Chain; T1566.002 Spearphishing Link

Persistence

T1546.016 Installer Packages

Credential Access

T1552.001 Credentials In Files; T1555 Credentials from Password Stores

Resource Development

T1583.001 Domains; T1583.006 Web Services; T1584.001 Domains; T1608.001 Upload Malware

Reconnaissance

T1589.001 Credentials; T1593 Search Open Websites/Domains; T1598.003 Spearphishing Link

Affected products and versions in Phantom Squatting

  • Multiple — Large Language Models used as chatbots / coding assistants (general-purpose, production and frontier-lite classes)
    Vulnerable versions: All versions - hallucination is an inherent architectural property, not a version-specific bug
  • npm, Inc. — npm package registry / Node.js dependency ecosystem
    Vulnerable versions: Registry accepts hallucinated package names and Remote Dynamic Dependency install-time HTTP fetches without provenance verification
  • Unnamed national postal service — Consumer e-commerce marketplace / delivery-tracking brand
    Vulnerable versions: Brand identity cloned via hallucinated domains; no software version applicable

Remediation for Phantom Squatting

Immediate actions

  • Verify any domain surfaced by an LLM/chatbot/coding assistant against authoritative brand-owned domain lists before entering credentials, payment data, or pasting it into build/deploy tooling
  • Block outbound requests from AI agents/assistants to newly registered or non-reputation-scored domains (NXD/zero-reputation heuristics) at DNS and URL-filtering layers
  • Disable or gate automatic link-opening, auto-download, and auto-fetch behavior in AI coding assistants and agentic pipelines pending human review
  • Audit CI/CD and developer environments for npm installs pulling packages via Remote Dynamic Dependencies (externally hosted HTTP payloads) rather than the npm registry proper
  • Search for the Montana Empire kit artifact hashes (eb07edaa2786cfddfa4c15526168f2200d85300aee0a8f253b32d2462a7b0bcd) and postal APK hash (2202a30daad9928ef47cca5f4ab04ce083692a94428e386fa01c2dd44557e34b) in EDR/file-reputation tooling

Workarounds

  • Require human-in-the-loop confirmation before any AI agent submits credentials, payment data, or downloads a dependency from a model-suggested URL
  • Pin dependency resolution to registry-verified package sources only; disallow HTTP(S) URL dependency specifiers in npm/yarn/pnpm manifests

Longer-term hardening

  • Run proactive LLM-hallucination-mapping pipelines against owned/trusted brand names to preemptively register or monitor phantom domains before adversaries do
  • Treat all LLM-generated output (URLs, package names, API endpoints) as an unverified draft requiring independent confirmation, not an authoritative source
  • Deploy agentic-AI runtime security (e.g., Prisma AIRS-class controls) to mediate and constrain what URLs an autonomous agent is permitted to fetch or execute against
  • Extend brand-protection / domain-monitoring programs to include AI-hallucination-derived domain variants alongside classic typosquat permutations
  • Establish NXD (non-existent domain) watchlists tied to brand names and alert on registration events for those exact strings

Weaknesses (CWE) in Phantom Squatting

CWE-1021, CWE-346, CWE-295

Timeline of Phantom Squatting

  • LLM1 (production-optimized enterprise mini-class model) used in the research is released.
  • Threat actor registers a phishing domain targeting a major UAE bank; unbeknownst to the actor, this exact domain string would independently be flagged as a phantom hallucination by Unit 42's detection pipeline 11 months later, providing historical validation that AI hallucination converges with real attacker targeting.
  • LLM2 (low-latency frontier lite-class model) used in the research is released.
  • PhantomRaven npm slopsquatting campaign begins, eventually reaching 126 malicious packages and over 86,000 installs stealing npm tokens, GitHub credentials, and CI/CD secrets via Remote Dynamic Dependencies.
  • Unit 42's phantom-domain detection pipeline independently predicts the same UAE bank domain registered by an attacker 11 months earlier, validating the hallucination-to-real-world-abuse convergence.
  • Second national postal-service phantom domain (later used for malicious Android APK distribution) is detected via hallucination monitoring.
  • Domain later used for the Montana Empire postal-service phishing kit is first detected as a hallucinated phantom domain.
  • Attacker registers the hallucinated domain and deploys the Montana Empire phishing kit, 23 days after detection (Adversarial Exploitation Window).
  • Attacker registers the second postal-service phantom domain and begins distributing a malicious Android APK via a pixel-accurate cloned storefront, 51 days after detection.
  • Unit 42 (Palo Alto Networks) publishes 'Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector,' detailing the methodology and confirmed cases.
  • The Hacker News publishes coverage of the Unit 42 phantom squatting research, broadening public/industry awareness.

Sources cited for Phantom Squatting

Detection coverage for TL-2026-1031

As of 2026-07-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1031 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
33 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-1031

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats