Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware
This article details a new phishing and malware tactic called "phantom squatting," where large language models (LLMs) generate non-existent domain names that attackers quickly register and use to host malicious content. Palo Alto Networks' Unit 42 discovered that LLMs routinely produce these fake domains, often before they appear on threat intelligence feeds, creating a window for attackers to exploit trust in AI-generated links. This tactic highlights a growing vulnerability as developers and security teams increasingly rely on AI for information, potentially leading to widespread phishing attacks and malware distribution.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
