As reported by The Hacker News, Palo Alto Networks' Unit 42 has documented a novel attack class called phantom squatting — where threat actors systematically register domains that large language models hallucinate, then weaponize that infrastructure to intercept users and AI agents acting on fabricated URLs. This is not a theoretical concern. It is already operational.

AI Security Alert: As reported by The Hacker News, Palo Alto Networks' Unit 42 has documented a novel attack class called phantom squatting — where threat actors systematically register domains that large language models hallucinate, then weaponize that infrastructure to intercept users and AI agents acting on fabricated URLs.

Why This Attack Class Is Structurally Different

Traditional typosquatting relies on human error — a mistyped character, a forgotten hyphen. Phantom squatting is fundamentally different because the source of the mistake is not the user, but the tool the user trusts. When an LLM confidently returns a hallucinated domain as part of a recommendation, code snippet, or research summary, the victim has no intuitive reason to distrust it. The AI said it. It looked authoritative. That asymmetry of trust is precisely what makes this technique so dangerous at scale.

This also represents a meaningful evolution in how attackers are thinking about AI as an attack surface. Rather than trying to compromise AI systems directly, adversaries are harvesting their failure modes. LLM hallucinations are well-documented, reproducible, and — critically — somewhat predictable. Researchers have already shown that certain types of prompts reliably generate certain categories of invented resources. Attackers can industrialize this process: query models at scale, extract hallucinated URLs, register the cheapest ones, and wait.

Who Bears the Most Risk

The exposed population is broader than most defenders currently appreciate:

Who Bears the Most Risk
Developers using AI coding assistants — Models like GitHub Copilot, Cursor, and others regularly suggest package imports, API endpoints, and documentation URLs. A hallucinated npm package domain or SDK endpoint becomes a direct software supply chain risk.
AI agentic workflows — Autonomous agents that browse the web, submit forms, or call APIs based on LLM-generated instructions are especially vulnerable. There is no human in the loop to catch a suspicious URL before the agent acts on it.
Enterprise knowledge workers — Employees using AI assistants for research, vendor lookups, or technical guidance may be handed a phantom domain and click through without a second thought.
Security teams themselves — Ironically, analysts using AI tools for threat intelligence or IOC enrichment could be handed fabricated infrastructure that poisons their own investigations.

The Detection Gap

Standard phishing defenses — domain reputation lists, URL filtering, email gateway scanning — are largely ineffective here because phantom domains can be registered fresh, hosted on clean infrastructure, and activated only after they accumulate traffic from AI referrals. By the time a domain earns a reputation signal, it may have already served its purpose.

The challenge for defenders is that phantom squatting abuses the AI layer, which sits upstream of most existing security controls. You cannot filter what you do not yet know to look for.

DNS telemetry becomes more valuable in this context — specifically, monitoring for newly registered domains that match patterns consistent with AI-generated naming conventions (e.g., plausible-sounding but unverifiable tech product names, SDK domains, or documentation subdomains).

Shield53 Recommendations

For Security Teams

  • Extend URL validation to AI-generated outputs. Any URL surfaced by an LLM tool — in chat, in generated code, in automated reports — should be treated as unverified until resolved and checked against threat intel feeds.
  • Monitor for hallucination-pattern domains in DNS logs. Work with your threat intelligence provider to develop heuristics for domains that match AI naming patterns but have no established organizational presence.
  • Apply zero-trust principles to agentic AI workflows. Any autonomous AI agent that can make external network calls needs an approval layer or sandboxed execution environment. Do not let agents browse freely based on LLM-generated URLs.
  • Add AI output validation to your security awareness training. Employees should be coached to independently verify any URL or resource name provided by an AI assistant before clicking or installing.

For Development Teams

  • Validate all AI-suggested package names, API endpoints, and external URLs against official registries before using them in code or CI/CD pipelines.
  • Consider blocking or alerting on outbound connections to newly registered domains from developer workstations and build environments.

For CISOs and Risk Owners

  • Include phantom squatting in your AI risk register. This is no longer a speculative threat class — Unit 42's findings confirm active exploitation.
  • Engage your AI tool vendors about output validation and hallucination reduction controls, particularly for any product that generates clickable URLs or external references.
Phantom squatting is a reminder that attackers adapt faster than most organizations update their threat models. The trust users place in AI tools is now itself an attack surface — and defenders need to start treating it as one.