Phantom Squatting: Adversaries Preemptively Register AI-Hallucinated Domains to Hijack Software Supply Chain Trust (Unit 42 "Montana Empire" Case) — Threadlinqs Intelligence
As of 2026-07-01, Phantom Squatting: Adversaries Preemptively Register AI-Hallucinated Domains to Hijack Software Supply Chain Trust (Unit 42 "Montana Empire" Case) is a high-severity supply chain threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-1050 · Severity: HIGH · Status: ACTIVE · Category: SUPPLY_CHAIN
Unit 42 research shows LLMs consistently hallucinate plausible-but-nonexistent brand domains, and adversaries are preemptively registering these hallucinated domains to intercept traffic from humans
Unit 42 (Palo Alto Networks) coined the term "phantom squatting" to describe a software supply-chain attack vector in which large language models (LLMs) hallucinate plausible but non-existent domains when asked about legitimate brands, and threat actors preemptively or reactively register those exact hallucinated domains to weaponize them for phishing, malware distribution, and command-and-control before the brand or defenders can claim them.
Researchers tested two production LLMs — an unnamed 'production-optimized mini-class enterprise model' (dated April 2025) and a 'low-latency lite-class frontier model' (dated June 2025) — by issuing 685,339 adversarial brand-related prompts covering 913 global brands across technology, finance, healthcare, e-commerce, government, gambling, and logistics sectors. Prompts were run at three temperature settings (Precise T=0.1, Balanced T=0.7, Creative T=1.5) to test hallucination sensitivity to model randomness. The corpus of 2.1 million unique generated URLs was then checked against domain registration data and threat intelligence feeds.
Key findings: the first model hallucinated non-existent domains (NXD) at a 44.6% rate and the second at 27.5%; the Creative temperature setting produced the highest NXD rate (43.10%) confirming that higher-randomness generation increases hallucination risk. Of the full corpus, 13,229 URLs (0.61%) were confirmed malicious and 41,313 (1.90%) were high-risk; the confirmed-malicious set broke down as 67.2% malware, 16.2% phishing, 13.7% grayware, and 3.0% command-and-control. Roughly 250,000 hallucinated domains had no registered owner at time of analysis — a live, discoverable attack surface for adversaries to claim.
URL hallucinations were most commonly path-level fabrications on otherwise legitimate domains (49.7%), followed by subdomain-level fabrications (39.5%) and pure fabricated root domains (10.8%).
The flagship case study, 'Montana Empire,' involved a postal/e-commerce brand: Unit 42's multi-agent discovery pipeline flagged a hallucinated brand domain as a high-risk target on March 8, 2026. On March 31, 2026 — an adversarial exploitation window (AEW) of 23 days — an attacker registered the exact domain and deployed a phishing kit named 'Montana Empire.' The kit's distribution ZIP archive (SHA-256 eb07edaa2786cfddfa4c15526168f2200d85300aee0a8f253b32d2462a7b0bcd, 7,958,528 bytes) contained a PHP backend that served a real-time scraped clone of the legitimate storefront, harvested credentials, credit-card numbers, IBAN/bank-transfer details, and national identity documents, and relayed one-time passwords (OTPs) in real time. Stolen data and operator commands were exfiltrated and controlled via a Telegram bot serving as the kit's command-and-control channel. The kit's admin panel displayed the banner 'Kimseye Güvenme' ('Trust No One' in Turkish). Forensic artifacts (project files and session logs) indicated the operator used an AI coding assistant to build the phishing kit itself, layering AI-assisted attacker tooling on top of an AI-hallucination-driven target selection process.
A second documented case involved a national postal service brand clone distributing a malicious Android APK (SHA-256 2202a30daad9928ef47cca5f4ab04ce083692a94428e386fa01c2dd44557e34b) via a pixel-perfect cloned storefront that displayed a fabricated 4.8-star rating and false '2M+ users' claim; this case had a 51-day adversarial exploitation window. Additional detected phantom-squatting incidents targeted a Bangladesh-focused sports-betting brand (45-day AEW, credential harvesting), a second sports-betting brand with a coordinated dual domain registration 18 minutes apart (40-day AEW), a European retail bank (35-day AEW, re-registration event), and a UAE commercial bank domain that had been registered and abused roughly 11 months prior to detection, validating the historical persistence of the technique.
Unit 42 frames the vulnerability as structural and "inherently unpatcha
Target sectors: technology, finance, health, ecommerce, government administration, gambling, logistics, postal-services, retail-banking
Target regions: Global, turkey, united arab emirates, bangladesh, Europe
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, HIGH, threat intelligence, cybersecurity, T1589, T1589.001, T1594, T1583.001, T1583.006, T1587.001, T1585.001, T1584.001, T1608.001, T1566