Phantom Squatting Turns AI Hallucinations Into Infrastructure

ByteVanguard graphic showing how an AI-invented domain can be registered and controlled by an attacker.
Featured Analysis

Phantom squatting turns an AI-generated web address from fiction into attacker-controlled infrastructure—and may allow a trusted assistant to deliver the victim.

ByteVanguard• September 2026• AI Security

Bottom Line Phantom squatting begins when an AI system invents a domain that does not exist. If the address is available, an attacker can register it, weaponize it, and wait for the model to recommend it again. Organizations must verify AI-generated destinations before people, applications, or autonomous agents are allowed to trust them.

An AI assistant invents a convincing support portal.

Nobody owns the domain.

An attacker registers it.

The next time the model produces the same answer, the fictional address leads somewhere real.

This is phantom squatting: the registration and weaponization of domains that artificial intelligence systems are likely to hallucinate.

Traditional phishing begins with an attacker creating a lure and finding a way to deliver it. Phantom squatting reverses that order. The model creates the plausible destination first. The attacker discovers the prediction, purchases the address, and waits for the AI system to send someone there.

The attacker does not need to compromise the model, poison its training data, or breach the AI provider.

The attacker only needs to own the place the model invented.

913
Global brands examined in Unit 42’s phantom-squatting research
2.1M
URLs generated during the research project
13,229
Generated URLs confirmed as malicious by the researchers
~250K
Hallucinated domains found unregistered and potentially available

How phantom squatting turns fiction into infrastructure

Language models generate responses by predicting plausible sequences of words. That ability allows them to produce fluent explanations, realistic code, and names that sound as though they should exist.

Sometimes they do not.

A model asked for an employee-benefits portal might combine a company name with words such as “benefits,” “login,” or “support.” A coding assistant might produce a believable API hostname. A research agent could offer a convincing address for a government program, bank service, or technical-documentation site.

At the moment the answer is generated, the destination may be harmless because nothing exists there. But domain names operate on ownership, not intent. If the address is unregistered, almost anyone can buy it.

The invention then stops being merely a model error. It becomes a location on the public internet controlled by whoever registered it first.

The phantom-squatting attack path
01 · PROBE
Query AI systems for portals, APIs, documentation, or services associated with selected brands
map predictable hallucinations
02 · REGISTER
Purchase the most convincing hallucinated domains before defenders notice them
convert fiction into infrastructure
03 · WEAPONIZE
Host phishing pages, malware, false documentation, or malicious API responses
prepare the destination
04 · RECEIVE
Wait for a person or autonomous agent to follow the AI-generated recommendation
let the model deliver the target
MODEL INVENTS → ATTACKER OCCUPIES → AI RECOMMENDS → TARGET ARRIVES
credential theft malware delivery data exfiltration false documentation
“The attacker does not have to make the domain famous. The model only has to make it plausible.“

The fake domain is born clean

Reputation-based security systems usually identify malicious infrastructure after it develops an observable history.

A domain may be blocked because it appeared in earlier attacks, served malware, shared infrastructure with known threats, triggered sandbox detections, or was reported by users.

A newly registered phantom domain begins with none of those signals.

It may have no blocklist entry, no established reputation score, no previous campaign activity, and no known connection to criminal infrastructure. During its earliest—and potentially most valuable—period, it can resemble any other newly created website.

Unit 42 describes this as a zero-reputation bypass. The domain is not considered safe because investigators verified its ownership or purpose. It is simply too new for conventional threat intelligence to have reached a conclusion.

The AI recommendation supplies the credibility that the domain itself has not earned.

Traditional phishing compared with phantom squatting
Attack element Traditional phishing Phantom squatting
Lure creation The attacker creates a message designed to look legitimate The AI produces a plausible destination in an ordinary response
Delivery channel Email, text message, advertisement, or social media A trusted assistant, coding tool, research agent, or automated workflow
Attacker action Push the malicious link toward selected targets Register a predicted hallucination and wait for targets to arrive
Early reputation May reuse infrastructure already associated with abuse Can begin as a newly registered domain with no malicious history
Primary trust signal The message appears to come from a familiar sender The address is presented by an AI system the user already trusts

Evidence that phantom squatting is operational

In research published in June 2026, Palo Alto Networks Unit 42 examined how language models generate domains associated with well-known organizations.

The researchers analyzed 913 global brands and submitted 685,339 URL queries across multiple configurations of two different models. Those queries produced approximately 2.1 million URLs.

Among them, Unit 42 reported 13,229 generated URLs confirmed as malicious and approximately 250,000 hallucinated domains that remained unregistered.

These figures do not mean that every invented address will become an attack site. They demonstrate something more operationally important: models can produce a large, discoverable inventory of plausible destinations, and many can potentially be purchased before defenders know they matter.

The research also documented real-world cases in which domains identified through its discovery process were later registered and weaponized. In one case, researchers reported detecting a predicted domain 23 days before an attacker registered it and deployed a phishing kit.

This creates a narrow but valuable defensive window. A company may be able to identify a domain its AI systems are likely to invent before an adversary occupies it.

Operational Read The important number is not the total quantity of possible domain variations. It is the smaller set of addresses that AI systems generate repeatedly, convincingly, and in high-risk contexts such as authentication, payments, customer support, software downloads, or API access.

From slopsquatting to phantom squatting

Phantom squatting extends a problem already observed in AI-generated software development.

A coding model may recommend a library that does not exist in PyPI, npm, or another package registry. If an attacker publishes malicious code under that invented name, a developer following the generated installation command may retrieve the attacker’s package.

This related technique is commonly called slopsquatting.

Research presented at USENIX Security examined hundreds of thousands of AI-generated code samples. It reported hallucinated-package rates of at least 5.2% for the commercial models tested and 21.7% for the open-source models tested. The researchers identified 205,474 unique hallucinated package names.

Phantom squatting applies the same adversarial logic to web infrastructure.

Software Registry

Slopsquatting

The model invents a software package. An attacker publishes code under that name and waits for a developer or coding agent to install it.

Domain Name System

Phantom Squatting

The model invents a web address. An attacker registers the domain and waits for a person or agent to visit it.

Shared Weakness

Plausibility replaces verification

The suggested name looks structurally correct, but nothing independently confirms who controls it.

Attacker Advantage

Registration is cheap

Turning a predicted hallucination into an owned package or domain can be faster than waiting for defenders to classify it.

Both techniques exploit the gap between a plausible name and a verified identity.

Why autonomous agents raise the stakes

A person who follows an invented address may still stop when the page requests credentials, initiates a download, or behaves unexpectedly.

An autonomous agent may not.

AI agents increasingly retrieve documentation, download dependencies, call APIs, submit information, follow redirects, and process responses without pausing for approval at every step.

Consider a coding agent instructed to configure a new integration:

  • GENERATE
    The agent produces what appears to be the vendor’s API-documentation address.
  • CONNECT
    The invented domain has already been registered and prepared by an attacker.
  • TRUST
    The agent retrieves a malicious configuration example that appears structurally valid.
  • ACT
    The resulting code sends an API key, authentication token, or application data to attacker-controlled infrastructure.

No employee clicked a suspicious email. No vulnerability in the AI model was required. Each component may have behaved as designed, but the workflow crossed from generated text into hostile infrastructure without an independent identity check.

The relevant security boundary is the moment generated text becomes an external action.

“When an AI can invent a destination and then contact it, hallucination becomes an outbound-security problem.“

Phantom squatting is not ordinary typosquatting

Typosquatting anticipates human error. An attacker registers a misspelling of a popular domain and waits for someone to type it incorrectly.

Phantom squatting anticipates machine output.

The attacker searches for names a model is likely to generate and registers them before the recommendation reaches a victim.

This difference complicates brand protection. Organizations commonly monitor missing letters, added hyphens, alternative top-level domains, and visually similar characters. A hallucinated address may not resemble the official domain closely enough to appear on those lists.

Instead, it may be a semantically plausible service name containing words such as “portal,” “developer,” “claims,” “connect,” “verify,” “support,” or “api.” It looks credible because it reflects the type of name a real organization might have selected.

How domain-based impersonation techniques differ
Technique What the attacker predicts Typical pattern
Typosquatting A human will mistype a known address Missing, duplicated, or transposed letters
Combosquatting A human will trust a brand combined with a familiar term Brand plus “login,” “secure,” or “support”
Homograph attack A human will overlook visually similar characters Lookalike letters from different alphabets
Phantom squatting An AI will repeatedly invent the same plausible destination A nonexistent portal, API, or service recommended by the model

How to defend against phantom squatting

Eliminating every hallucinated URL is unrealistic. Preventing generated destinations from receiving automatic trust is achievable.

  • VERIFY BEFORE SENDING SECRETS
    Never transmit API keys, OAuth tokens, cookies, source code, customer records, or internal documents to an endpoint solely because an AI system supplied it.
  • RESTRICT AGENT EGRESS
    Give autonomous workflows allowlisted destinations, verified API endpoints, controlled package registries, and explicit redirect policies.
  • VALIDATE OWNERSHIP
    Check domain age, registration data, certificate history, DNS infrastructure, and links from established corporate properties instead of relying only on reputation scores.
  • MAP THE HALLUCINATION SURFACE
    Test what major models produce when asked for the organization’s portals, APIs, downloads, regional services, and support pages. Monitor the most credible unregistered results.

Separate retrieved links from generated strings

AI interfaces should distinguish between a link retrieved from a verified source and an address created as part of generated text.

To a user, both may appear as identical hyperlinks. Technically, they represent different levels of evidence.

A retrieved URL can be connected to an indexed page, approved document, search result, or internal directory. A generated URL may be nothing more than a statistically plausible sequence of characters.

Applications should avoid allowing models to invent destinations when a validated directory can supply them instead. A support assistant should retrieve the official help portal from an approved knowledge base. A coding agent should select API endpoints from verified vendor documentation. An internal agent should use centrally managed service records rather than constructing hostnames from memory.

When a previously unseen destination is unavoidable, the workflow should pause before transmitting sensitive information or executing downloaded content.

Build controls around the action boundary

Warnings inside a chat interface will not protect every automated workflow. The most reliable controls must operate outside the model.

A safer AI destination-verification path
MODEL OUTPUT
AI proposes a URL, package, API, or external resource
untrusted recommendation
IDENTITY CHECK
Application verifies source, ownership, registration age, and expected organization
deterministic validation
POLICY DECISION
Allow, block, isolate, or require human approval based on destination risk
enforced outside the model
CONTROLLED ACTION
The workflow connects with limited permissions and monitored data access
observable execution
GENERATE → VERIFY → AUTHORIZE → MONITOR
block unknown auth endpoints review new domains allow verified services

Organizations should log the URLs generated, resolved, visited, and contacted by AI-enabled systems. Useful signals include newly registered domains, first-seen destinations, unexpected redirects, certificate mismatches, direct IP connections, and outbound requests carrying sensitive headers or unusual volumes of data.

The objective is not to monitor every sentence an employee writes. It is to make consequential machine actions visible.

Operational Test Ask one question about every AI-enabled workflow: Can the model invent a destination and then cause the system to contact it? If the answer is yes, hallucination has crossed from a content-quality problem into a security boundary.

Plausible is not authenticated

For years, defenders have warned users that a familiar logo does not prove who owns a website. AI creates the next version of that lesson: a confident recommendation does not prove that the destination exists for the reason the model claims.

The web makes this form of hallucination unusually dangerous because names can be purchased.

A fabricated historical event remains false. An invented person remains fictional. But an invented domain can be registered in minutes, connected to a server, and transformed into an operational attack asset.

The answer is not to expect perfect output from probabilistic systems. It is to stop an unverified string from becoming a trusted destination merely because a model produced it fluently.

An AI can invent the address. An attacker can own it. Security must decide whether anyone—or anything—is allowed to go there.

Sources

1
Palo Alto Networks Unit 42
Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
↗Source
2
USENIX Security 2025
We Have a Package for You: A Comprehensive Analysis of Package Hallucinations by Code-Generating LLMs
↗Source
3
2026 Frontier-Model Research
The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort
↗Source

Support independent security analysis

If you find ByteVanguard useful, you can support the site and help keep the analysis independent.

Support the analysis
Intelligence over headlines. Signal over noise.

Stay Connected

Report Intelligence
© 2026 ByteVanguard. Built for security professionals.