# Phantom Squatting: Adversaries Preemptively Register AI-Hallucinated Domains to Hijack Software Supply Chain Trust (Unit 42 "Montana Empire" Case)

> Unit 42 research shows LLMs consistently hallucinate plausible-but-nonexistent brand domains, and adversaries are preemptively registering these hallucinated domains to intercept traffic from humans and autonomous agents that trust AI-generated URLs. Analysis of 913 global brands across 685,339 adversarial prompts (2.1M unique generated URLs) found 13,229 confirmed malicious URLs and ~250,000 unregistered phantom domains still available for takeover; the documented "Montana Empire" case shows a hallucinated postal-ecommerce domain flagged 23 days before an attacker registered it and stood up an AI-assisted, PHP-based credential-phishing kit with Telegram C2.

- **Published:** 2026-07-01T00:00:00Z
- **Last reviewed:** 2026-07-01T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1050
- **ID:** TL-2026-1050
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Unit 42 (Palo Alto Networks) coined the term "phantom squatting" to describe a software supply-chain attack vector in which large language models (LLMs) hallucinate plausible but non-existent domains when asked about legitimate brands, and threat actors preemptively or reactively register those exact hallucinated domains to weaponize them for phishing, malware distribution, and command-and-control before the brand or defenders can claim them.

Researchers tested two production LLMs — an unnamed 'production-optimized mini-class enterprise model' (dated April 2025) and a 'low-latency lite-class frontier model' (dated June 2025) — by issuing 685,339 adversarial brand-related prompts covering 913 global brands across technology, finance, healthcare, e-commerce, government, gambling, and logistics sectors. Prompts were run at three temperature settings (Precise T=0.1, Balanced T=0.7, Creative T=1.5) to test hallucination sensitivity to model randomness. The corpus of 2.1 million unique generated URLs was then checked against domain registration data and threat intelligence feeds.

Key findings: the first model hallucinated non-existent domains (NXD) at a 44.6% rate and the second at 27.5%; the Creative temperature setting produced the highest NXD rate (43.10%) confirming that higher-randomness generation increases hallucination risk. Of the full corpus, 13,229 URLs (0.61%) were confirmed malicious and 41,313 (1.90%) were high-risk; the confirmed-malicious set broke down as 67.2% malware, 16.2% phishing, 13.7% grayware, and 3.0% command-and-control. Roughly 250,000 hallucinated domains had no registered owner at time of analysis — a live, discoverable attack surface for adversaries to claim.

URL hallucinations were most commonly path-level fabrications on otherwise legitimate domains (49.7%), followed by subdomain-level fabrications (39.5%) and pure fabricated root domains (10.8%).

The flagship case study, 'Montana Empire,' involved a postal/e-commerce brand: Unit 42's multi-agent discovery pipeline flagged a hallucinated brand domain as a high-risk target on March 8, 2026. On March 31, 2026 — an adversarial exploitation window (AEW) of 23 days — an attacker registered the exact domain and deployed a phishing kit named 'Montana Empire.' The kit's distribution ZIP archive (SHA-256 eb07edaa2786cfddfa4c15526168f2200d85300aee0a8f253b32d2462a7b0bcd, 7,958,528 bytes) contained a PHP backend that served a real-time scraped clone of the legitimate storefront, harvested credentials, credit-card numbers, IBAN/bank-transfer details, and national identity documents, and relayed one-time passwords (OTPs) in real time. Stolen data and operator commands were exfiltrated and controlled via a Telegram bot serving as the kit's command-and-control channel. The kit's admin panel displayed the banner 'Kimseye Güvenme' ('Trust No One' in Turkish). Forensic artifacts (project files and session logs) indicated the operator used an AI coding assistant to build the phishing kit itself, layering AI-assisted attacker tooling on top of an AI-hallucination-driven target selection process.

A second documented case involved a national postal service brand clone distributing a malicious Android APK (SHA-256 2202a30daad9928ef47cca5f4ab04ce083692a94428e386fa01c2dd44557e34b) via a pixel-perfect cloned storefront that displayed a fabricated 4.8-star rating and false '2M+ users' claim; this case had a 51-day adversarial exploitation window. Additional detected phantom-squatting incidents targeted a Bangladesh-focused sports-betting brand (45-day AEW, credential harvesting), a second sports-betting brand with a coordinated dual domain registration 18 minutes apart (40-day AEW), a European retail bank (35-day AEW, re-registration event), and a UAE commercial bank domain that had been registered and abused roughly 11 months prior to detection, validating the historical persistence of the technique.

Unit 42 frames the vulnerability as structural and "inherently unpatchable": hallucinated domains are functionally indistinguishable from legitimate new domains at registration time, carry no prior threat-intelligence history, have no established reputation score, and are absent from all blocklists — allowing attackers to bypass reputation- and blocklist-based defenses entirely during the exploitation window between hallucination-discovery and domain weaponization. The vector is explicitly called out as a software supply-chain risk because both human users trusting AI chatbot/search answers and autonomous AI agents that programmatically follow LLM-generated URLs (e.g., in agentic browsing, coding assistants, or automated procurement workflows) are exposed to identical risk, without any code, package, or dependency being compromised. The report also connects phantom squatting to the related and independently reported 'slopsquatting' vector, in which code-generating LLMs hallucinate non-existent software package names (e.g., npm/PyPI) that attackers then register with malicious payloads; a related campaign, PhantomRaven, embedded malware in 126 npm packages that together achieved 86,000+ installs, and a documented case involved an attacker registering a hallucinated shortened package name ('unused-imports') derived from the legitimate 'eslint-plugin-unused-imports'.

Palo Alto Networks lists its own product mitigations (Advanced WildFire, Advanced URL Filtering, Advanced DNS Security, Prisma AIRS, Koi Agentic Endpoint Security, Unit 42 AI Security Assessment) and recommends organizational controls: proactively mapping an organization's own LLM hallucination surface before deploying AI assistants/agents, establishing phantom-domain watchlists tied to brand and product names, building continuous discovery pipelines that regenerate and re-check hallucinated URLs over time (since AEWs of 20-50+ days were observed), and requiring independent verification of any URL surfaced by an AI system before a human or autonomous agent acts on it (credential entry, file download, payment).

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1589.001 Credentials
- T1594 Search Victim-Owned Websites
- T1583.001 Domains
- T1583.006 Web Services
- T1587.001 Malware
- T1585.001 Social Media Accounts
- T1584.001 Domains
- T1608.001 Upload Malware
- T1566 Phishing
- T1566.002 Spearphishing Link
- T1189 Drive-by Compromise
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1005 Data from Local System
- T1539 Steal Web Session Cookie
- T1111 Multi-Factor Authentication Interception
- T1102 Web Service
- T1102.002 Bidirectional Communication
- T1567 Exfiltration Over Web Service
- T1657 Financial Theft

## Sources

- [Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector](https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/)
- [Phantom Squatting: AI-Driven Supply Chain Threat](https://www.darkreading.com/endpoint-security/phantom-squatting-ai-driven-supply-chain-threat)
- [Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware](https://thehackernews.com/2026/07/phantom-squatting-uses-ai-hallucinated.html)
- [Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector](https://www.hendryadrian.com/phantom-squatting-ai-hallucinated-domains-as-a-software-supply-chain-vector/)
- [Attackers Register AI-Hallucinated Domains to Deliver Phishing Kits and Malware](https://gbhackers.com/ai-hallucinated-domains/)
- [Montana Empire Phishing Kit Abuses AI-Hallucinated Domain to Steal Credentials](https://cyberpress.org/ai-hallucinated-domain-theft/)
- ["Phantom squatting" uses AI hallucinated domains for cyber attacks](https://cybernews.com/security/phantom-squatting-hallucinated-domains-cyber-attacks/)
- [Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector](https://www.itsecuritynews.info/phantom-squatting-ai-hallucinated-domains-as-a-software-supply-chain-vector/)
- [Slopsquatting: AI Code Hallucinations Fuel Supply Chain Attacks](https://labs.cloudsecurityalliance.org/research/csa-research-note-slopsquatting-ai-supply-chain-20260419-csa/)
- [AI Hallucinations Create "Slopsquatting" Supply Chain Threat](https://www.infosecurity-magazine.com/news/ai-hallucinations-slopsquatting/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1050
