Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector

Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector

Unit 42 found that LLMs routinely hallucinate plausible web domains for real brands, and adversaries are registering those nonexistent domains to intercept traffic in a tactic they call phantom squatting. The research documented 13,229 confirmed malicious URLs, about 250,000 unregistered phantom domains, and real-world cases including the Montana Empire phishing kit and a malicious APK campaign tied to a national postal service. #Unit42 #MontanaEmpire #PaloAltoNetworks #AIcodingassistant

Keypoints

  • Unit 42 identified phantom squatting, where attackers register hallucinated domains generated by LLMs.
  • The research analyzed 913 global brands and 685,339 prompts, producing 2.1 million URLs.
  • Of those URLs, 13,229 were confirmed malicious and 41,313 were high risk.
  • About 809,455 URLs resolved to non-existent domains, collapsing into roughly 250,000 unique phantom domains.
  • Attackers can register these domains before defenders react, creating a zero-reputation bypass.
  • A notable case showed an attacker using an AI coding assistant to build the Montana Empire phishing kit.
  • The study also uncovered a malicious APK campaign impersonating a national postal delivery service.

MITRE Techniques

  • [T1583.001 ] Acquire Infrastructure: Domains – Adversaries register hallucinated domains before defenders react, creating attacker-controlled infrastructure (‘preemptively register it’ and ‘register those most valuable for attacks’).
  • [T1566.002 ] Phishing: Spearphishing Link – The attacker uses a fraudulent domain and AI-generated URL recommendations to lure victims to credential-harvesting pages (‘authoritative recommendation to navigate directly to attacker-controlled infrastructure’).
  • [T1056.001 ] Keylogging / Input Capture: Keylogging-like Credential Capture – The phishing kit includes credential capture and OTP relay functionality to harvest user secrets (‘manual one-time password (OTP) relay and victim adjudication’).
  • [T1105 ] Ingress Tool Transfer – Victims are induced to download a malicious APK and related payloads from attacker-controlled infrastructure (‘download a malicious Android application package (APK) file’).
  • [T1190 ] Exploit Public-Facing Application – The kit deploys web-facing phishing and login interfaces on fraudulent sites to capture credentials (‘credential-harvesting portals and brand-impersonation sites’).
  • [T1027 ] Obfuscated Files or Information – The article describes redacted indicators and cloaked infrastructure used to evade detection (‘redirect cloaking’ and ‘serving benign content to automated crawlers’).
  • [T1090 ] Proxy: External Proxy – Telegram-based C2 and relays are used for attacker control and forwarding victim data (‘a Telegram-based C2 interface for real-time credential exfiltration’).
  • [T1071.001 ] Application Layer Protocol: Web Protocols – The attacker relies on HTTP/HTTPS web requests to phishing pages and API endpoints (‘execute HTTP requests against URLs the models themselves generate’).

Indicators of Compromise

  • [SHA256 hash ] Montana Empire phishing kit archive – eb07edaa2786cfddfa4c15526168f2200d85300aee0a8f253b32d2462a7b0bcd, and other 0 items
  • [SHA256 hash ] Malicious Android APK – 2202a30daad9928ef47cca5f4ab04ce083692a94428e386fa01c2dd44557e34b, and other 0 items
  • [Domain ] Phantom squatting detections and phishing infrastructure – [redacted]post-app[.]com, [redacted]-login[.]com, and other 3 items
  • [URL ] Montana Empire kit and related files – hxxp[:]//[redacted][.]com/[redacted].zip, hxxp[:]//[redacted][.]com/mentalite.php, and other 3 items
  • [URL ] APK delivery page – hxxp[:]//[redacted]post-app[.]com/[redacted]post.apk, and other 0 items
  • [Filename ] Malicious archives and app package – [redacted].zip, [redacted]post.apk, and other 0 items


Read more: https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/