Research · curated 21 Jul 2026
Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting
First reported · updated · 3 reports google.com
Coverage timeline
Why it matters
HalluSquatting demonstrates that predictable LLM hallucinations of resource identifiers can be weaponized into scalable, untargeted remote code execution across popular agentic applications, requiring no direct injection channel and exploiting a weakness present in every available model.
Researchers from Tel Aviv University, Technion, and Intuit (including Ben Nassi and Stav Cohen) introduce 'HalluSquatting' (adversarial hallucination squatting), a technique in which attackers identify trending resources, predict the resource identifiers that LLMs tend to hallucinate, and preemptively register those hallucinated resources (repos, skills, URLs). When agentic LLM applications hallucinate and call these attacker-controlled identifiers, the technique achieves remote tool execution and remote code execution at scale, enabling scalable, untargeted promptware attacks that could form an agentic botnet without any direct channel to the target.