← All stories
● Covered by 1 source · 1 reportMedium impact

AI-Generated Domains Used in Phishing Attacks via Phantom Squatting

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Attackers buy AI-generated domains for phishing.
  • Phantom squatting takes advantage of AI hallucinations.
  • Unit 42 identified 13,229 known malicious domains.

Phantom Squatting Explained

Phantom squatting occurs when attackers register web addresses invented by AI language models. These domains are perceived as trustworthy because they have no prior history or reputation, allowing cybercriminals to host phishing pages that lure unsuspecting users.

The Research Findings

Palo Alto Networks' Unit 42 studied two AI models that were queried with 685,339 questions about top brands across various sectors. The models created 2.1 million links, with 13,229 already flagged as malicious. Furthermore, around 250,000 generated domains had no registered owners, making them prime targets for phishing schemes.

Exploiting AI Limitations

The effectiveness of phantom squatting is due to the lack of historical data for newly registered domains. As these domains don’t have a history of malicious behavior, they bypass traditional security measures. Moreover, AI models can repeatedly generate the same fake domains, making it easier for attackers to predict and exploit.

Real-World Cases

Unit 42 documented instances where AI models invented specific domains resembling legitimate services. One notable case involved a fake domain mimicking a national postal service's online platform, which was registered by an attacker shortly after the AI suggested it, underscoring the speed at which these tactics can be implemented.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Attackers are purchasing domains created by AI models before anyone else, leveraging misplaced trust from users. This tactic, termed 'phantom squatting' by Palo Alto Networks' Unit 42, poses significant risks as AI-generated links can mislead users into visiting malicious sites.