Threat reportSupply ChainTL-2026-1050
Phantom Squatting: Adversaries Preemptively Register AI-Hallucinated Domains to Hijack Software Supply Chain Trust (Unit 42 "Montana Empire" Case)
Phantom Squatting (TL-2026-1050), also tracked as Phantom Squatting, is a high-severity supply-chain compromise, first published 2026-07-01. It has no confirmed attribution, affects Multiple LLM-generated brand/domain output (production-optimized, maps to 21 MITRE ATT&CK techniques (T1005, T1102, T1102.002), and is covered by 9 detection rules and 15 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 21MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-1050
- Threat ID
- TL-2026-1050
- Also known as
- Phantom Squatting, Montana Empire
- Severity
- HIGH
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- technology, finance, health, ecommerce, government administration, gambling, logistics, postal-services, retail-banking
- Target regions
- Global, turkey, united arab emirates, bangladesh, Europe
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in Phantom Squatting
Malware and tooling: Montana Empire, PhantomRaven, AI coding assistant (unspecified)
How Phantom Squatting works
Unit 42 research shows LLMs consistently hallucinate plausible-but-nonexistent brand domains, and adversaries are preemptively registering these hallucinated domains to intercept traffic from humans and autonomous agents that trust AI-generated URLs. Analysis of 913 global brands across 685,339 adversarial prompts (2.1M unique generated URLs) found 13,229 confirmed malicious URLs and ~250,000 unregistered phantom domains still available for takeover; the documented "Montana Empire" case shows a hallucinated postal-ecommerce domain flagged 23 days before an attacker registered it and stood up an AI-assisted, PHP-based credential-phishing kit with Telegram C2.
Unit 42 (Palo Alto Networks) coined the term "phantom squatting" to describe a software supply-chain attack vector in which large language models (LLMs) hallucinate plausible but non-existent domains when asked about legitimate brands, and threat actors preemptively or reactively register those exact hallucinated domains to weaponize them for phishing, malware distribution, and command-and-control before the brand or defenders can claim them.
Researchers tested two production LLMs — an unnamed 'production-optimized mini-class enterprise model' (dated April 2025) and a 'low-latency lite-class frontier model' (dated June 2025) — by issuing 685,339 adversarial brand-related prompts covering 913 global brands across technology, finance, healthcare, e-commerce, government, gambling, and logistics sectors. Prompts were run at three temperature settings (Precise T=0.1, Balanced T=0.7, Creative T=1.5) to test hallucination sensitivity to model randomness. The corpus of 2.1 million unique generated URLs was then checked against domain registration data and threat intelligence feeds.
Key findings: the first model hallucinated non-existent domains (NXD) at a 44.6% rate and the second at 27.5%; the Creative temperature setting produced the highest NXD rate (43.10%) confirming that higher-randomness generation increases hallucination risk. Of the full corpus, 13,229 URLs (0.61%) were confirmed malicious and 41,313 (1.90%) were high-risk; the confirmed-malicious set broke down as 67.2% malware, 16.2% phishing, 13.7% grayware, and 3.0% command-and-control. Roughly 250,000 hallucinated domains had no registered owner at time of analysis — a live, discoverable attack surface for adversaries to claim.
URL hallucinations were most commonly path-level fabrications on otherwise legitimate domains (49.7%), followed by subdomain-level fabrications (39.5%) and pure fabricated root domains (10.8%).
The flagship case study, 'Montana Empire,' involved a postal/e-commerce brand: Unit 42's multi-agent discovery pipeline flagged a hallucinated brand domain as a high-risk target on March 8, 2026. On March 31, 2026 — an adversarial exploitation window (AEW) of 23 days — an attacker registered the exact domain and deployed a phishing kit named 'Montana Empire.' The kit's distribution ZIP archive (SHA-256 eb07edaa2786cfddfa4c15526168f2200d85300aee0a8f253b32d2462a7b0bcd, 7,958,528 bytes) contained a PHP backend that served a real-time scraped clone of the legitimate storefront, harvested credentials, credit-card numbers, IBAN/bank-transfer details, and national identity documents, and relayed one-time passwords (OTPs) in real time. Stolen data and operator commands were exfiltrated and controlled via a Telegram bot serving as the kit's command-and-control channel. The kit's admin panel displayed the banner 'Kimseye Güvenme' ('Trust No One' in Turkish). Forensic artifacts (project files and session logs) indicated the operator used an AI coding assistant to build the phishing kit itself, layering AI-assisted attacker tooling on top of an AI-hallucination-driven target selection process.
A second documented case involved a national postal service brand clone distributing a malicious Android APK (SHA-256 2202a30daad9928ef47cca5f4ab04ce083692a94428e386fa01c2dd44557e34b) via a pixel-perfect cloned storefront that displayed a fabricated 4.8-star rating and false '2M+ users' claim; this case had a 51-day adversarial exploitation window. Additional detected phantom-squatting incidents targeted a Bangladesh-focused sports-betting brand (45-day AEW, credential harvesting), a second sports-betting brand with a coordinated dual domain registration 18 minutes apart (40-day AEW), a European retail bank (35-day AEW, re-registration event), and a UAE commercial bank domain that had been registered and abused roughly 11 months prior to detection, validating the historical persistence of the technique.
Unit 42 frames the vulnerability as structural and "inherently unpatchable": hallucinated domains are functionally indistinguishable from legitimate new domains at registration time, carry no prior threat-intelligence history, have no established reputation score, and are absent from all blocklists — allowing attackers to bypass reputation- and blocklist-based defenses entirely during the exploitation window between hallucination-discovery and domain weaponization. The vector is explicitly called out as a software supply-chain risk because both human users trusting AI chatbot/search answers and autonomous AI agents that programmatically follow LLM-generated URLs (e.g., in agentic browsing, coding assistants, or automated procurement workflows) are exposed to identical risk, without any code, package, or dependency being compromised. The report also connects phantom squatting to the related and independently reported 'slopsquatting' vector, in which code-generating LLMs hallucinate non-existent software package names (e.g., npm/PyPI) that attackers then register with malicious payloads; a related campaign, PhantomRaven, embedded malware in 126 npm packages that together achieved 86,000+ installs, and a documented case involved an attacker registering a hallucinated shortened package name ('unused-imports') derived from the legitimate 'eslint-plugin-unused-imports'.
Palo Alto Networks lists its own product mitigations (Advanced WildFire, Advanced URL Filtering, Advanced DNS Security, Prisma AIRS, Koi Agentic Endpoint Security, Unit 42 AI Security Assessment) and recommends organizational controls: proactively mapping an organization's own LLM hallucination surface before deploying AI assistants/agents, establishing phantom-domain watchlists tied to brand and product names, building continuous discovery pipelines that regenerate and re-check hallucinated URLs over time (since AEWs of 20-50+ days were observed), and requiring independent verification of any URL surfaced by an AI system before a human or autonomous agent acts on it (credential entry, file download, payment).
MITRE ATT&CK techniques used in TL-2026-1050
Collection
Command and Control
T1102 Web Service; T1102.002 Bidirectional Communication
Credential Access
T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie
Initial Access
T1189 Drive-by Compromise; T1566 Phishing; T1566.002 Spearphishing Link
Execution
T1204.001 Malicious Link; T1204.002 Malicious File
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583.001 Domains; T1583.006 Web Services; T1584.001 Domains; T1585.001 Social Media Accounts; T1587.001 Malware; T1608.001 Upload Malware
Reconnaissance
T1589 Gather Victim Identity Information; T1589.001 Credentials; T1594 Search Victim-Owned Websites
Impact
Affected products and versions in Phantom Squatting
- Multiple — LLM-generated brand/domain output (production-optimized mini-class enterprise model, low-latency lite-class frontier model)
Vulnerable versions: April 2025 model snapshot; June 2025 model snapshot - Various — 913 global brands across technology, finance, healthcare, e-commerce, government, gambling, and logistics sectors
Vulnerable versions: N/A - structural LLM hallucination issue, not a software version defect
Remediation for Phantom Squatting
Immediate actions
- Register defensive/watchlist domains for high-value hallucination-prone brand variants identified via LLM prompting
- Block or warn on newly-registered domains (WHOIS age < 60 days) that resemble owned brand names before allowing outbound navigation
- Deploy DNS security / URL filtering that flags zero-reputation domains resembling monitored brand strings
- Alert users and internal AI agents against entering credentials or OTPs on any AI-suggested link without independent verification
Workarounds
- Treat all LLM-generated URLs and package/domain names as unverified draft output requiring independent confirmation against an authoritative source before use
- Prevent automatic OTP relay or credential auto-fill on domains not present on an internally maintained allowlist
Longer-term hardening
- Map the organization's own brand hallucination surface by systematically prompting production LLMs and logging generated domains/URLs
- Build a continuous discovery and re-check pipeline for hallucinated domains, since adversarial exploitation windows of 18 minutes to 51+ days were observed
- Restrict autonomous AI agents (browsing, coding assistants, procurement bots) from auto-navigating to or auto-trusting LLM-generated URLs without allowlist validation
- Extend brand-protection / anti-phishing monitoring programs to include LLM-hallucination-derived domain permutations, not just traditional typosquatting
Timeline of Phantom Squatting
- LLM1 (production-optimized mini-class enterprise model) snapshot dated used in Unit 42 hallucination study
- LLM2 (low-latency lite-class frontier model) snapshot dated used in Unit 42 hallucination study
- Unit 42 multi-agent discovery pipeline generates and flags the hallucinated postal/e-commerce brand domain later used in the Montana Empire case as high-risk
- Attacker registers the flagged hallucinated domain and deploys the Montana Empire PHP phishing kit with Telegram C2, 23 days after Unit 42's initial detection (adversarial exploitation window)
- Infosecurity Magazine reports on related 'slopsquatting' AI package-hallucination supply chain threat
- Cloud Security Alliance publishes research note on slopsquatting AI supply chain attacks
- Dark Reading, GBHackers, CyberPress, Cybernews, and IT Security News publish coverage summarizing the Unit 42 findings
- Unit 42 (Palo Alto Networks) publishes 'Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector' research report, coining the term and detailing the 685,339-prompt / 913-brand / 2.1M-URL study
- The Hacker News publishes detailed technical coverage including additional case breakdowns and recommended defenses
Sources cited for Phantom Squatting
- Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
- Phantom Squatting: AI-Driven Supply Chain Threat
- Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware
- Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
- Attackers Register AI-Hallucinated Domains to Deliver Phishing Kits and Malware
- Montana Empire Phishing Kit Abuses AI-Hallucinated Domain to Steal Credentials
- "Phantom squatting" uses AI hallucinated domains for cyber attacks
- Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
- Slopsquatting: AI Code Hallucinations Fuel Supply Chain Attacks
- AI Hallucinations Create "Slopsquatting" Supply Chain Threat
Detection coverage for TL-2026-1050
As of 2026-07-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1050 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.