AI · 75 days ago
LLM-generated links can give attackers a ready-made target list before anyone treats the names as real. The break is timing: if a model invents a plausible brand domain, an attacker can register it first and sit on it until users or tools follow the AI output.
Unit 42 says it found real registrations across multiple sectors, and its monitoring predicted some of them 18–51 days before the adversary acted. It also tied one AI-built phishing kit to a domain it had flagged 23 days earlier, which shows this is already being used as an attack workflow, not just a branding problem.
The practical risk is pre-positioned infrastructure. If employees or internal assistants use AI to find vendor sites or generate links, the output itself can become an attack surface weeks before any visible abuse starts.
3 sources covering this story
'Phantom Squatting': An Emerging AI-Driven Supply Chain Threat
LLMs consistently hallucinate Web domains for legitimate brands that attackers can register for malicious activity in a difficult-to-detect attack vector.
Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware
Unit 42 found 250,000 unowned domains in 2.1M AI-generated links, with attackers already using the pattern for phishing.
Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
Attackers can exploit LLM domain hallucinations through phantom squatting to target supply chains.
Part of the PlainSec briefing for 2026-07-02