Phantom Squatting: Attackers Register AI-Hallucinated Domains to Hijack LLM-Guided Traffic (Montana Empire / PhantomRaven) — Threadlinqs Intelligence
As of 2026-07-01, Phantom Squatting: Attackers Register AI-Hallucinated Domains to Hijack LLM-Guided Traffic (Montana Empire / PhantomRaven) is a high-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 33 indicators of compromise.
Threat ID: TL-2026-1031 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Unit 42 (Palo Alto Networks) documents 'phantom squatting': attackers monitor and preemptively register domains that LLMs hallucinate when answering brand-related queries, then serve phishing kits or
Phantom squatting exploits a structural, unpatchable property of LLM architectures: when asked about a brand, product, or API, models sometimes hallucinate plausible but non-existent URLs. Unit 42's four-phase attack lifecycle model — Discover, Act, Lure, Bypass — shows that attackers can query the same LLMs used by victims (via systematic adversarial probing across 913 global brands and 685,339 prompts), identify domains the models consistently hallucinate across temperature settings (a property Unit 42 calls Thermal Hallucination Persistence), and register those domains before defenders do. Because the domains are freshly registered and have no history in threat-intelligence feeds, they achieve 'zero-reputation bypass' against reputation-based URL/DNS filtering. Of 2.1 million URLs generated by two LLMs (a production-optimized enterprise mini-class model released April 2025, and a low-latency frontier lite-class model released June 2025), 13,229 (0.61%) were already flagged malicious, 41,313 (1.90%) were high-risk, and roughly 250,000 pointed to unregistered phantom domains ripe for attacker registration; 809,455 URLs resolved to non-existent domains overall. Malware delivery (drive-by downloads, exploit kits) accounted for 67.2% of malicious/high-risk hits, phishing/credential harvesting 16.2%, grayware 13.7%, and C2 infrastructure 3.0%. Two confirmed cases anchor the research: the 'Montana Empire' kit, an AI-coding-assistant-built phishing platform that cloned a national postal service's e-commerce marketplace within 23 days of the hallucination being detected (predicted 2026-03-08, registered 2026-03-31), using a PHP backend to intercept dual-channel payments (card numbers and IBAN transfers) and national ID documents, exfiltrating in real time via a Telegram bot that also relayed OTPs to a human operator control panel (labeled 'Kimseye Güvenme' — Turkish for 'Trust No One'); and a second postal-service case where a pixel-accurate cloned storefront with fabricated 4.8-star ratings and 2M+ user claims distributed a malicious Android APK, registered 51 days after hallucination detection. Additional confirmed abuse includes Bangladesh-targeted sports-betting phishing domains registered in a coordinated 18-minute window across two brands, a re-registered European bank phishing domain, and a UAE bank domain that a threat actor registered in April 2025 which Unit 42's detection pipeline independently rediscovered as a hallucinated phantom domain 11 months later — validating that AI hallucination and real attacker targeting converge on the same domain names. Unit 42 explicitly ties phantom squatting to the adjacent 'slopsquatting' technique used in the PhantomRaven npm supply-chain campaign (126 malicious packages, 86,000+ installs, active since August 2025), where a threat actor registered npm package names that coding-assistant LLMs hallucinate, using Remote Dynamic Dependencies (RDD) — HTTP-fetched payloads invisible to static dependency scanners — to steal npm tokens, GitHub credentials, and CI/CD secrets at install time. Both campaigns represent the same underlying attack surface: AI systems (chatbots, coding assistants, and increasingly autonomous agents) generating URLs or package names that a human or an agent then trusts and acts on without verification.
Weaknesses (CWE)
CWE-1021, CWE-346, CWE-295
Target sectors: technology, finance, health, government administration, gambling, logistics, ecommerce
Target regions: Global, Middle East, South Asia, Europe, North America
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 33 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
PHISHING, HIGH, threat intelligence, cybersecurity, T1593, T1598.003, T1589.001, T1583.001, T1583.006, T1608.001, T1566.002, T1195.002, T1204.001, T1036.005