Palo Alto Networks warns about ‘phantom squatting’
Unit 42, the research team of Palo Alto Networks, has warned of “phantom squatting” in new research. AI models regularly make up Web addresses that appear to belong to well-known companies, but in reality do not exist.
With this new attack technique, hackers can register non-existent domain names and thus direct the traffic of users or AI systems to their own infrastructure. The domains can then be used for, among other things, phishing, spreading malware and intercepting data from software and AI workflows.
As AI is used more frequently in software development, the likelihood of phantom squatting increases. Developers are increasingly using AI agents to find documentation, so-called API endpoints and external services, while autonomous AI agents themselves can generate, open and process URLs. As a result, LLMs are increasingly becoming a trusted link within the software supply chain.
AI models can generate credible but non-existent domain names for, for example, a company portal, API or online service. When an attacker registers such a domain in advance, traffic can end up with the attacker without being noticed. Precisely because newly registered domains do not yet have any reputation or threat history, they often remain under the radar of existing security systems.
Unit 42 analysed the output of two different LLMs for 913 international brands.
The researchers carried out 685,339 URL queries, accounting for 2.1 million unique URLs. Of these, 13,229 URLs turned out to be malicious.
Unit 42 discovered around 250,000 AI-invented domains that at that time had not yet been registered.
Unit 42 therefore advises organisations not to automatically trust URLs generated by AI, to verify domains and ownership independently, and to build in additional checks before AI agents access external websites, downloads or APIs.
Emerce





Subscribers 0
Fans 0
Followers 0
Followers