Research · curated 21 Jul 2026

Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting

Coverage timeline

discovered google.com primary 9 Jul 2026tomshardware.com 13 Aug 2026tomshardware.com

Why it matters

HalluSquatting demonstrates that predictable LLM hallucinations of resource identifiers can be weaponized into scalable, untargeted remote code execution across popular agentic applications, requiring no direct injection channel and exploiting a weakness present in every available model.

Researchers from Tel Aviv University, Technion, and Intuit (including Ben Nassi and Stav Cohen) introduce 'HalluSquatting' (adversarial hallucination squatting), a technique in which attackers identify trending resources, predict the resource identifiers that LLMs tend to hallucinate, and preemptively register those hallucinated resources (repos, skills, URLs). When agentic LLM applications hallucinate and call these attacker-controlled identifiers, the technique achieves remote tool execution and remote code execution at scale, enabling scalable, untargeted promptware attacks that could form an agentic botnet without any direct channel to the target.