AI-Generated Domains Become Pre-Positioned Attack Surface
LLM-generated links can give attackers a ready-made target list before anyone treats the names as real. The break is timing: if a model invents a plausible brand domain, an attacker can register it first and sit on it until users or tools follow the AI output.
Unit 42 says it found real registrations across multiple sectors, and its monitoring predicted some of them 18–51 days before the adversary acted. It also tied one AI-built phishing kit to a domain it had flagged 23 days earlier, which shows this is already being used as an attack workflow, not just a branding problem.
The practical risk is pre-positioned infrastructure. If employees or internal assistants use AI to find vendor sites or generate links, the output itself can become an attack surface weeks before any visible abuse starts.