Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting
LLMs and coding agents hallucinate resource identifiers, and many of those hallucinations are predictable. We studied them across models and production coding agents, and showed how an attacker can use them for AI supply-chain attacks.
@misc{spira2026agentic,
title={Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting},
author={Spira, Aya and Cohen, Stav and Feldman, Elad and Bitton, Ron and Wool, Avishai and Nassi, Ben},
year={2026},
eprint={2607.07433},
archivePrefix={arXiv}
}
Code:
You just joined the botnet.
(Just kidding, this is a website. But that's the paper.)