Agentic Botnets via HalluSquatting

Arxiv pdf 2026-07-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

The growing adoption of agentic LLM applications has introduced a new threat previously named as promptware. While prior work has established that adversaries can exploit direct channels to LLM applications to apply promptware (push adversarial prompts) under weak threat models (e.g., by sending emails or calendar invitations to a target), many applications do not provide any direct channels that could be exploited for prompt injection beyond the Internet. This raises a fundamental question: can attackers exploit LLM applications at scale without any direct channels in practical threat models? In this work, we show that the inherent tendency of LLMs to hallucinate resource identifiers can be exploited to amplify untargeted promptware attacks that pull adversarial prompts at scale and could be exploited to establish a botnet. We introduce adversarial hallucination squatting, a technique in which attackers identify trending resources (e.g., popular repositories, popular skills, etc.), compute the LLM distribution of hallucinations on the trending resource names, and preemptively register them to host adversarial prompts (e.g., instructing an LLM to install a bot or running a script that installs a bot). By leveraging the predictability and transferability of hallucinations across foundational LLMs and to application layers, adversaries can significantly amplify the reach of untargeted promptware under weak threat models and establish a botnet by exploiting LLM applications to install a bot on the device that "pulled" the compromised hallucinated resource from the Inter. We empirically demonstrate that hallucinated resource generation occurs at high ratesup to 85% in repository cloning scenarios and up to 100% in skill installationand that these hallucinations transfer between foundational models and different prompts. We demonstrate the practicality of adversarial hallucination squatting against various LLM applications with integrated terminals in their set of tools, including AI coding assistants (Cursor, Cursor CLI, Windsurf, GitHub Copilot, Cline), CLIs (Gemini CLI), and assistants (OpenClaw, ZeroClaw, and NanoClaw), achieving remote tool execution and remote code execution (RCE). We conclude by discussing mitigation strategies and the similarities to typosquatting

Loading executive summary...

LINK COPIED TO CLIPBOARD