Unit 42 researchers introduce 'phantom squatting' — a supply chain attack vector where adversaries register domains that LLMs consistently hallucinate for legitimate brands. Analyzing 913 global brands with 685,339 adversarial prompts across two LLM families, they generated 2.1 million URLs, finding 13,229 confirmed malicious URLs and ~250,000 unregistered hallucinated domains ripe for adversarial registration. Real-world cases include the Montana Empire phishing kit, where an attacker used an AI coding assistant to build a full phishing operation targeting a domain the researchers had flagged 23 days earlier. The attack exploits a zero-reputation bypass: newly registered phantom domains carry no threat intelligence history, evading conventional URL defenses. Higher LLM temperature settings amplify hallucination rates (43% NXD at T=1.5 vs 34% at T=0.1), though malicious URL rates remain stable across temperatures. Proactive hallucination mapping and registration event monitoring are proposed as the primary defensive countermeasure, offering up to 51 days of lead time before adversarial weaponization.

27m read timeFrom unit42.paloaltonetworks.com
Post cover image
Table of contents
Executive SummaryIntroduction: LLMs as Supply Chain DependenciesThreat Model: The Phantom Squatting Attack LifecycleA Proactive Hallucination Discovery FrameworkResults: Quantifying the LLM Supply Chain Attack Surface for Phantom SquattingEvidence of Active Exploitation: Real-World Detection CasesImplications for AI-Powered Supply ChainsConclusionIndicators of CompromiseAcknowledgmentsAdditional Resources
200 Impressions