As reported by The Hacker News, Palo Alto Networks' Unit 42 has documented a novel attack class called phantom squatting — where threat actors systematically register domains that large language models hallucinate, then weaponize that infrastructure to intercept users and AI agents acting on fabricated URLs. This is not a theoretical concern. It is already operational.
Why This Attack Class Is Structurally Different
Traditional typosquatting relies on human error — a mistyped character, a forgotten hyphen. Phantom squatting is fundamentally different because the source of the mistake is not the user, but the tool the user trusts. When an LLM confidently returns a hallucinated domain as part of a recommendation, code snippet, or research summary, the victim has no intuitive reason to distrust it. The AI said it. It looked authoritative. That asymmetry of trust is precisely what makes this technique so dangerous at scale.
This also represents a meaningful evolution in how attackers are thinking about AI as an attack surface. Rather than trying to compromise AI systems directly, adversaries are harvesting their failure modes. LLM hallucinations are well-documented, reproducible, and — critically — somewhat predictable. Researchers have already shown that certain types of prompts reliably generate certain categories of invented resources. Attackers can industrialize this process: query models at scale, extract hallucinated URLs, register the cheapest ones, and wait.
Who Bears the Most Risk
The exposed population is broader than most defenders currently appreciate:
The Detection Gap
Standard phishing defenses — domain reputation lists, URL filtering, email gateway scanning — are largely ineffective here because phantom domains can be registered fresh, hosted on clean infrastructure, and activated only after they accumulate traffic from AI referrals. By the time a domain earns a reputation signal, it may have already served its purpose.
The challenge for defenders is that phantom squatting abuses the AI layer, which sits upstream of most existing security controls. You cannot filter what you do not yet know to look for.
DNS telemetry becomes more valuable in this context — specifically, monitoring for newly registered domains that match patterns consistent with AI-generated naming conventions (e.g., plausible-sounding but unverifiable tech product names, SDK domains, or documentation subdomains).
Shield53 Recommendations
For Security Teams
- Extend URL validation to AI-generated outputs. Any URL surfaced by an LLM tool — in chat, in generated code, in automated reports — should be treated as unverified until resolved and checked against threat intel feeds.
- Monitor for hallucination-pattern domains in DNS logs. Work with your threat intelligence provider to develop heuristics for domains that match AI naming patterns but have no established organizational presence.
- Apply zero-trust principles to agentic AI workflows. Any autonomous AI agent that can make external network calls needs an approval layer or sandboxed execution environment. Do not let agents browse freely based on LLM-generated URLs.
- Add AI output validation to your security awareness training. Employees should be coached to independently verify any URL or resource name provided by an AI assistant before clicking or installing.
For Development Teams
- Validate all AI-suggested package names, API endpoints, and external URLs against official registries before using them in code or CI/CD pipelines.
- Consider blocking or alerting on outbound connections to newly registered domains from developer workstations and build environments.
For CISOs and Risk Owners
- Include phantom squatting in your AI risk register. This is no longer a speculative threat class — Unit 42's findings confirm active exploitation.
- Engage your AI tool vendors about output validation and hallucination reduction controls, particularly for any product that generates clickable URLs or external references.
Phantom squatting is a reminder that attackers adapt faster than most organizations update their threat models. The trust users place in AI tools is now itself an attack surface — and defenders need to start treating it as one.