Unit 42: language models invent domains that attackers then register
Unit 42 has published research on what it calls phantom squatting: language models generate domain names that look plausible but do not exist, and attackers can register them for phishing, malware delivery or command-and-control traffic. The researchers tested 913 brands across 685,339 prompts, produced 2.1 million URLs, identified 13,229 malicious URLs the models had already generated, and found roughly 250,000 unregistered hallucinated domains. In one case an attacker registered a hallucinated postal-service marketplace domain and deployed a phishing kit 23 days after Unit 42's system predicted the pattern.
What this means for your organisation
When staff and automated workflows treat addresses from a language model as reliable, the trust is placed in the wrong spot. The risk grows the more your organisation lets AI agents fetch content or run code without a human in the loop. It is also a brand problem: customers can be sent to domains resembling yours that you never registered.
Berigo recommends
- Validate URLs produced by AI tooling before they are used, particularly inside automated workflows.
- Constrain what AI agents and coding assistants are permitted to fetch and execute on their own.
- Monitor newly registered domains resembling your organisation's name and trademarks.
- Cover the handling of model-generated references in your AI usage policy.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch