Agentic botnets via universal, transferable adversarial HalluSquatting
Research demonstration08 Jul 2026In 'Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting' (arXiv:2607.07433, v1 8 Jul 2026), Aya Spira, Stav Cohen, Elad Feldman, Ron Bitton, Avishai Wool and Ben Nassi — the group behind Morris II — study 'promptware' against agentic LLM applications that expose no direct injection channel beyond the open Internet. Their thesis is that the inherent tendency of LLMs to hallucinate resource identifiers can itself be turned into an exploitable primitive. They introduce 'adversarial hallucination squatting': an attacker identifies trending resources (e.g. popular repositories or agent 'skills'), computes the model's distribution of hallucinated names over those resources, and preemptively registers the most-probable hallucinated names to host adversarial prompts. Because the hallucinations are reported to be predictable and to transfer across foundation models and across different prompts (and down to the application layer), a single pre-registration can reportedly reach many victims under a weak threat model — the untargeted 'botnet' framing, where each application that pulls a compromised hallucinated resource can be induced to install a bot on the host. The authors empirically report hallucinated-resource generation at high rates — up to 85% in repository-cloning scenarios and up to 100% in skill-installation scenarios (figures per the paper's abstract) — and demonstrate the technique against various production LLM applications with integrated terminals in their toolset, achieving remote tool execution and remote code execution. This extends the earlier slopsquatting / package-hallucination line of work from opportunistic name-squatting into a deliberate, quantified, transferable channel — hallucination as an exploitable supply-chain injection primitive rather than incidental noise. Rates, transferability and the RCE demonstrations are as reported by the authors and pertain to their experimental setups; payload/registration details here are illustrative, not operational.
Risks it illustrates
Sources
- Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting — Spira, Cohen, Feldman, Bitton, Wool & Nassi (arXiv:2607.07433, 8 Jul 2026) ↗
- Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack — Aviatrix Threat Research Center (25 Jul 2026) ↗
Practise the risk class — related scenarios
Interactive simulations of the risk class this case illustrates (not a re-enactment of this specific event).
A support chatbot invents a policy — and the company is held to it
An ops agent gets one god-mode credential — and one misread wipes production
A coding agent asks to write ./notes.txt — the file it actually overwrites is your SSH keys
A support email hides instructions — and the assistant obeys them
A text-to-SQL agent runs the model's output straight at the database
A poisoned issue makes the agent lie to the human who approves its actions
Compromise the pipeline that builds agents, and every new worker is born malicious
A fake Sentry error report hijacks a developer's coding agent into running a shell command
The forensic record is itself the attack surface — an agent's log is poisoned, then quietly rewritten
A 'safe' dataset preview turns an upload into code execution on the pipeline's workers
A newsletter the user asked to summarise quietly writes a false 'fact' into the agent's long-term memory — and it detonates weeks later
A shopping page tells the agent to do something the user never asked for
An attacker plants prompt injection in the audit trail — so the LLM that hunts them erases the evidence
A single poisoned document plants a standing instruction that survives every reset
A cost-saving open-weights swap quietly ships a model with its safety surgically removed
A screenshot that's harmless at full size becomes an order once the system shrinks it
A capable third-party model that behaves perfectly — until it sees the trigger
A trusted MCP email tool quietly BCCs every message to an attacker
The eval gate that was supposed to catch the agent is itself the thing being attacked
A poisoned web page hijacks a research agent — and the planner acts on its behalf
A GUI agent clicks 'Continue' — but the screen moved, and it lands on 'Send'
An inbox summary quietly ships a secret to an attacker's server