Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware

Source: The Hacker News

Author: info@thehackernews.com (The Hacker News)

URL: https://thehackernews.com/2026/07/phantom-squatting-uses-ai-hallucinated.html

ONE SENTENCE SUMMARY:

LLM-hallucinated domains enable “phantom squatting,” where attackers register predicted fake links, bypass reputation controls, and phish users.

MAIN POINTS:

  1. Attackers buy nonexistent AI-invented domains, then host phishing pages to capture traffic.
  2. Unit 42 names this technique phantom squatting and confirms real-world exploitation.
  3. Trust in AI-provided links lets criminals succeed without emails, ads, or traditional lures.
  4. Study queried two models 685,339 times across 913 brands and multiple industries.
  5. Responses contained 2.1 million links, including 13,229 already known malicious.
  6. About 250,000 hallucinated domains were unregistered, creating a large pre-registration target set.
  7. New domains evade blocklists because reputation systems need time and observed abuse.
  8. Models generate consistent hallucinations across temperatures, making attacker predictions easier.
  9. Case one: predicted domain registered 23 days later, used Montana Empire kit stealing IDs and payments.
  10. Case two: predicted domain registered 51 days later, used for brand-clone and malicious Android app distribution.

TAKEAWAYS:

  1. Monitor and preemptively watch likely hallucinated domains because defenders can gain weeks of warning.
  2. Verify official domains independently before entering credentials or using links in code.
  3. Prevent AI agents from auto-opening or downloading content from model-generated URLs without validation.
  4. Assume model output is a draft requiring confirmation, not a reliable authority.
  5. Recognize the broader “model output becomes input” shift accelerating phishing-as-a-service and response timelines.