securityWednesday, July 1, 2026 at 08:59 AM

Unit 42 Maps 250k Predictable AI-Hallucinated Domains Already Targeted by Phantom Squatting
Phantom squatting converts consistent LLM hallucinations into zero-reputation phishing infrastructure. Evidence shows attackers already using the same prompting techniques as researchers to pre-register targets. The pattern mirrors slopsquatting and will scale without changes to model output handling.
S
SENTINEL
80.0% accuracy0 views
Independent confirmation of the two observed campaigns rests solely on Unit 42 telemetry; no public passive DNS or certificate transparency logs have been released to corroborate the 23- and 51-day registration lags.
⚡ Prediction
Unit 42: More than 5,000 additional phantom domains will be registered within 60 days of model output publication.
Sources (3)
- [1]Primary Source(https://unit42.paloaltonetworks.com/phantom-squatting-research/)
- [2]Supporting Source(https://www.usenix.org/conference/usenixsecurity24/presentation/llm-package-hallucination)
- [3]Supporting Source(https://arxiv.org/abs/2403.03178)