Hackers Now Use AI Hallucinations for Fraud
Hackers Now Use AI Hallucinations for Fraud
Unit 42 has published a study on a new fraud technique known as Phantom Squatting, where attackers register fictitious domains generated by artificial intelligence.
Unit 42, one of the world's leading teams in cyberattack investigations and malware analysis, has released a fascinating study on the so-called Phantom Squatting.
As is known, AI tends to invent non-existent URLs, and some domains are generated more frequently. For example, it might produce name_download.com instead of the correct https://name.com.
Attackers have realized that these fictitious addresses can be registered and used for phishing. This is similar to typosquatting, where hackers exploited human errors by registering sites like https://goggle.com.
Moreover, there's no need to lure users; the AI does that for the hackers.
And if you think this is an isolated case, think again: researchers have already identified over 13,000 existing malicious URLs that utilize this principle. There are also about 250,000 unregistered domains that models regularly invent. A true find for fraudsters of all kinds.
Why it matters
AnalysisThis new fraud technique highlights how AI can be leveraged to create threats, complicating user protection. The rise of phishing attacks based on fictitious domains necessitates new security strategies.
Discuss in community
Share your questions and insights with developers