AI Agents Vulnerable to Botnet Attacks via Hallucination Exploitation

Key Points
- TEL AVIV — Researchers from Tel Aviv University, Technion, and Intuit have demonstrated a technique that could allow attackers to turn AI agents into botnets by exploiting the same hallucinations that cause chatbots to generate incorrect information.
- The attack method, introduced in a paper titled "Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting," works by predicting which fake resources AI models are likely to create, registering those names, and embedding malicious instructions within them. If an AI agent later retrieves the hallucinated resource, it may treat the attacker-controlled content as legitimate.
- Researchers found that AI-generated resource hallucinations occurred at rates as high as 85 percent in repository cloning scenarios and 100 percent in skill installation tests. The team evaluated the technique against multiple AI coding assistants and agents, including Cursor, GitHub Copilot, Gemini CLI, and OpenClaw.
The threat emerges as AI assistants move beyond answering questions and gain the ability to interact directly with computers—accessing files, searching the web, writing code, and running commands. Those capabilities create security gaps when agents act on retrieved information without confirming whether the source is genuine.
How Hallucination Squatting Works
Read Next

Fed Chair Communication Strategy Raises Transparency Questions
9 days ago

Dow Jones Futures Trigger Sell Signal; Apple Earnings, Iran News, Fed Meeting Loom
10 days ago
Known as adversarial hallucination squatting or "HalluSquatting," the attack parallels existing cyberattack tactics. The researchers wrote that "the growing adoption of agentic LLM applications has introduced a new threat previously named as promptware." HalluSquatting is similar to typosquatting, a technique where attackers register domain names resembling legitimate websites or software packages to trick users into visiting malicious sites. Instead of exploiting human typing mistakes, HalluSquatting targets mistakes made by AI models.
Researchers warned the technique could allow attackers to build AI-enabled botnets—networks of infected computers or devices controlled remotely by an attacker. Botnets are commonly used in cyberattacks including denial-of-service attacks, cryptocurrency mining, malware distribution, and ransomware campaigns.
Related coverage: Fed Chair Communication Strategy Raises Transparency Questions
The researchers noted that "ongoing studies have demonstrated various variants of Promptware attacks against real-world systems, including ChatGPT, Google Assistant, Copilot, and various additional applications." These previous studies demonstrated that promptware attacks can lead to financial, privacy, and safety impacts.
This research follows a pattern of recent discoveries about AI agent vulnerabilities. In April, Google researchers detailed malicious websites designed to hijack AI agents through indirect prompt injection attacks, including attempts to steal passwords, delete files, and manipulate payments. A separate study on the "CopyPasta" attack showed how hidden prompts inside developer files could manipulate AI coding assistants into spreading malicious code.
Additionally, in June, an OpenClaw user reported facing more than 6,000 attempts from attackers attempting to trick the AI agent into leaking sensitive information. These incidents underscore the expanding attack surface as AI agents gain autonomous capabilities.
Why this matters: As organizations increasingly deploy AI agents with the ability to execute code and access systems, hallucination-based attacks could enable large-scale compromises of development infrastructure and connected systems without requiring direct access to the AI models themselves.
Market Outlook
Security teams will likely implement repository verification mechanisms and sandboxing for AI agent operations within the next 12-18 months. AI model developers may update training approaches to reduce hallucination rates in resource generation, though complete elimination remains technically challenging given current model architectures.
Sources: AP, Reuters, ESPN, Bloomberg, BBC and other international news outlets.
Disclaimer: This article is for informational purposes only. Content is based on publicly available news sources.
Markets Desk
The NewsOracle Markets Desk covers stock markets, cryptocurrency, economic policy and breaking financial news from Wall Street and global exchanges.
Latest coverage: Cybersecurity


