Large language models continue to "invent" non-existent web addresses. Cybercriminals are now actively exploiting this: they are the first to register these domains and host phishing pages or malicious content on them. The victims come on their own—led by trusted AI tools, The Hacker News reports.
Researchers from Palo Alto Networks' Unit 42 division have dubbed this tactic Phantom Squatting. According to their new report, the technique is already being actively used in real-world attacks.
How the attack works
When an AI answers a prompt, it frequently generates links to non-existent websites. These domains are still available, have zero reputation, and are not blacklisted. An attacker quickly registers such a domain and deploys a phishing page or malware on it. The user, trusting the AI, clicks the link and falls into the trap—without a single malicious email being sent.
As part of the Unit 42 study, two popular AI models answered 685,339 questions about 913 well-known brands from various industries. As a result, the models generated over 2.1 million links. Around 250,000 of them turned out to be completely fabricated and were not yet registered at the time of the study.
Real-world examples
In one instance, researchers predicted the generation of a domain resembling the online store of a national postal service. 23 days later, an attacker registered that exact domain and deployed an advanced phishing kit on it. In another case, a fake domain was hijacked 51 days after the prediction and used to distribute a malicious Android application.
Why is this dangerous? New domains have a "clean history," so traditional security tools do not block them. Different models often invent the exact same non-existent domains. Increasing the creativity of a model only increases the number of hallucinations.
As experts note, this is a structural characteristic of the architecture of large language models, which is extremely difficult to eliminate completely.
What users and companies should do
Never click on links provided by an AI without independently verifying the official domain. Prohibit AI agents from automatically opening links or downloading files from generated links. Treat model responses as a draft rather than a verified source.
Phantom Squatting is a clear example of how attackers quickly adapt to new technologies. As long as AI continues to "invent" the internet, this window of opportunity for attackers remains open. Who claims these "phantom" domains first—defenders or criminals—will largely determine the threat landscape in the coming years.
month
week
day