# Phantom Squatting: Attackers Register AI-Hallucinated Domains to Hijack LLM-Guided Traffic (Montana Empire / PhantomRaven)

> Unit 42 (Palo Alto Networks) documents 'phantom squatting': attackers monitor and preemptively register domains that LLMs hallucinate when answering brand-related queries, then serve phishing kits or malware from them to intercept traffic misdirected by AI assistants, chatbots, and coding tools. Across 685,339 adversarial prompts against two production LLMs, researchers generated 2.1 million URLs, of which ~250,000 pointed to unregistered 'phantom' domains, and confirmed attacker registration within 18-51 days of hallucination detection in real-world cases including the 'Montana Empire' postal-service phishing kit and a related npm slopsquatting campaign, PhantomRaven.

- **Published:** 2026-07-01T00:00:00Z
- **Last reviewed:** 2026-07-01T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1031
- **ID:** TL-2026-1031
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 33 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Phantom squatting exploits a structural, unpatchable property of LLM architectures: when asked about a brand, product, or API, models sometimes hallucinate plausible but non-existent URLs. Unit 42's four-phase attack lifecycle model — Discover, Act, Lure, Bypass — shows that attackers can query the same LLMs used by victims (via systematic adversarial probing across 913 global brands and 685,339 prompts), identify domains the models consistently hallucinate across temperature settings (a property Unit 42 calls Thermal Hallucination Persistence), and register those domains before defenders do. Because the domains are freshly registered and have no history in threat-intelligence feeds, they achieve 'zero-reputation bypass' against reputation-based URL/DNS filtering. Of 2.1 million URLs generated by two LLMs (a production-optimized enterprise mini-class model released April 2025, and a low-latency frontier lite-class model released June 2025), 13,229 (0.61%) were already flagged malicious, 41,313 (1.90%) were high-risk, and roughly 250,000 pointed to unregistered phantom domains ripe for attacker registration; 809,455 URLs resolved to non-existent domains overall. Malware delivery (drive-by downloads, exploit kits) accounted for 67.2% of malicious/high-risk hits, phishing/credential harvesting 16.2%, grayware 13.7%, and C2 infrastructure 3.0%. Two confirmed cases anchor the research: the 'Montana Empire' kit, an AI-coding-assistant-built phishing platform that cloned a national postal service's e-commerce marketplace within 23 days of the hallucination being detected (predicted 2026-03-08, registered 2026-03-31), using a PHP backend to intercept dual-channel payments (card numbers and IBAN transfers) and national ID documents, exfiltrating in real time via a Telegram bot that also relayed OTPs to a human operator control panel (labeled 'Kimseye Güvenme' — Turkish for 'Trust No One'); and a second postal-service case where a pixel-accurate cloned storefront with fabricated 4.8-star ratings and 2M+ user claims distributed a malicious Android APK, registered 51 days after hallucination detection. Additional confirmed abuse includes Bangladesh-targeted sports-betting phishing domains registered in a coordinated 18-minute window across two brands, a re-registered European bank phishing domain, and a UAE bank domain that a threat actor registered in April 2025 which Unit 42's detection pipeline independently rediscovered as a hallucinated phantom domain 11 months later — validating that AI hallucination and real attacker targeting converge on the same domain names. Unit 42 explicitly ties phantom squatting to the adjacent 'slopsquatting' technique used in the PhantomRaven npm supply-chain campaign (126 malicious packages, 86,000+ installs, active since August 2025), where a threat actor registered npm package names that coding-assistant LLMs hallucinate, using Remote Dynamic Dependencies (RDD) — HTTP-fetched payloads invisible to static dependency scanners — to steal npm tokens, GitHub credentials, and CI/CD secrets at install time. Both campaigns represent the same underlying attack surface: AI systems (chatbots, coding assistants, and increasingly autonomous agents) generating URLs or package names that a human or an agent then trusts and acts on without verification.

## MITRE ATT&CK

- T1593 Search Open Websites/Domains
- T1598.003 Spearphishing Link
- T1589.001 Credentials
- T1583.001 Domains
- T1583.006 Web Services
- T1608.001 Upload Malware
- T1566.002 Spearphishing Link
- T1195.002 Compromise Software Supply Chain
- T1204.001 Malicious Link
- T1036.005 Match Legitimate Resource Name or Location
- T1119 Automated Collection
- T1102.002 Bidirectional Communication
- T1071.001 Web Protocols
- T1567 Exfiltration Over Web Service
- T1041 Exfiltration Over C2 Channel
- T1114 Email Collection
- T1584.001 Domains
- T1195.001 Compromise Software Dependencies and Development Tools
- T1059.007 JavaScript
- T1546.016 Installer Packages
- T1555 Credentials from Password Stores
- T1552.001 Credentials In Files
- T1518 Software Discovery
- T1082 System Information Discovery
- T1016 System Network Configuration Discovery
- T1036 Masquerading
- T1140 Deobfuscate/Decode Files or Information

## Sources

- [Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector](https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/)
- [Phantom Squatting: AI-Hallucinated Domains for Phishing](https://thehackernews.com/2026/07/phantom-squatting-uses-ai-hallucinated.html)
- [What is Phantom Squatting? Protecting Against AI Hallucination Risks](https://live.paloaltonetworks.com/t5/community-blogs/how-ai-hallucinations-create-new-security-risks-for-users/ba-p/1255418)
- [Unit 42 (@Unit42_Intel) - Montana Empire phishing kit thread](https://x.com/Unit42_Intel/status/2041879323963982303)
- [PhantomRaven Malware Found in 126 npm Packages Stealing GitHub Tokens From Devs](https://thehackernews.com/2025/10/phantomraven-malware-found-in-126-npm.html)
- [PhantomRaven: NPM Malware Hidden in Invisible Dependencies](https://www.koi.ai/blog/phantomraven-npm-malware-hidden-in-invisible-dependencies)
- [PhantomRaven Attack Discovered in 126 Malicious npm Packages, Exceeding 86,000 Downloads](https://gbhackers.com/phantomraven-attack/)
- [Malicious packages in npm evade dependency detection through invisible URL links](https://www.csoonline.com/article/4082195/malicious-packages-in-npm-evade-dependency-detection-through-invisible-url-links-report.html)
- [PhantomRaven attack floods npm with credential-stealing packages](https://www.bleepingcomputer.com/news/security/phantomraven-attack-floods-npm-with-credential-stealing-packages/)
- [PhantomRaven returns to npm with 88 bad packages](https://www.csoonline.com/article/4144231/phantomraven-returns-to-npm-with-88-bad-packages.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1031
