LIVE · cybersecurity feed
Live wire
aihigh

AI Hallucinations Create Phantom Domains for Supply Chain Attacks

Artificial intelligence models can generate domain names that do not actually exist, a phenomenon known as "phantom squatting." Attackers are leveraging this AI hallucination to create malicious domains that mimic legitimate ones, thereby posing a significant threat to software supply chains. This tactic allows them to potentially intercept or manipulate software development processes.

zeroday.news · 31d ago

Large language models (LLMs) have been found to consistently generate nonexistent web domains for legitimate brands, a phenomenon researchers are calling "phantom squatting." Adversaries are actively registering these AI-hallucinated domains to intercept traffic, posing a significant new risk to the software supply chain.

Researchers from Unit 42, the threat intelligence arm of Palo Alto Networks, conducted an analysis of 913 global brands, executing 685,339 URL queries across multiple configurations of two distinct LLM models. This process generated 2.1 million URLs, revealing over 13,229 confirmed malicious URLs. Additionally, approximately 250,000 hallucinated domains were discovered that remain unregistered, presenting a substantial opportunity for exploitation.

The research indicates that attackers can predict the use of these phantom domains between 18 and 51 days before adversary registration. In one confirmed instance, an attacker leveraged an AI coding assistant to develop a phishing kit named "Montana Empire." This kit targeted a domain that Unit 42's detection pipeline had identified as a high-risk hallucination target 23 days earlier, illustrating the full attack cycle from AI-assisted development to exploitation of an LLM-hallucinated domain.

LLMs are increasingly integrated into the software development lifecycle, with developers consulting AI coding assistants for documentation links, and enterprise CI/CD pipelines using AI assistants to recommend third-party service endpoints. When an LLM generates a URL, it may be directly ingested by autonomous AI agents, integrated into production code by developers, suggested as an authoritative endpoint, or included in automated documentation. In these scenarios, the LLM acts as a trusted supply chain dependency, making its output, including hallucinated URLs, susceptible to exploitation.

This new threat extends prior research on "slopsquatting," where LLMs hallucinate nonexistent software package names. Phantom squatting applies this adversarial logic to web infrastructure, with LLMs generating fictitious domains for web portals, API endpoints, or corporate services. Examples include a coding assistant generating an unregistered benefits portal URL, an AI research agent producing a plausible banking portal domain, or a developer unknowingly integrating an AI-generated API endpoint into their code, directing data to an attacker-controlled server.

Traditional URL filtering and threat intelligence frameworks are often ineffective against phantom squatting because they rely on historical reports of malicious activity or require a domain to accumulate a reputation before classification. A newly registered phantom domain carries no threat intelligence history, has no established reputation score, and lacks any blocklist entries, effectively bypassing conventional defenses. The domain appears legitimate because it originates from the LLM's own language patterns.

The phantom squatting attack lifecycle involves four phases: Discover, Act, Lure, and Bypass. The "Discover" phase involves adversarial probing of LLM hallucination patterns, where attackers systematically query models with realistic prompts to map the resulting phantom domains. In the "Act" phase, attackers register these hallucinated phantom domains before defenders can react. The "Lure" phase involves directing users or automated systems to these attacker-controlled domains, and the "Bypass" phase exploits the lack of reputation or threat intelligence associated with these newly registered domains.

aisupply chaindomain namescybersecurityphantom squatting
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

ai

Microsoft, tech companies throw weight behind spread of open-source AI

Other signatories of the letter include Meta, Palantir, Perplexity, Mistral, NVIDIA, Mozilla, The Linux Foundation, Hugging Face, Dell Technologies and IBM. The post Microsoft, tech companies throw weight behind spread of open-source AI appeared first on CyberScoop.

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.