Research · curated 21 Jul 2026
Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting
First reported google.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
HalluSquatting shows attackers can compromise AI agents at scale without ever contacting a target, by pre-registering the fake package or URL names that models predictably hallucinate—turning a fundamental model weakness into a botnet-building supply-chain vector.
Researchers from Tel Aviv University, Technion, and Intuit disclosed 'HalluSquatting' (adversarial hallucination squatting), a technique that exploits the predictable tendency of LLMs to hallucinate resource identifiers (repos, skills, URLs) in tool calls. By preemptively registering the hallucinated resources, attackers can achieve scalable, untargeted remote tool execution and remote code execution across popular agentic LLM applications without any direct injection channel, potentially building agentic botnets.