[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-84994-en":3,"doc-seo-84994-105":29,"detail-sidebar-cat-0-en-105":90},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":13,"seo_description":14,"update_tm":27,"read_time":28},84994,7971461740909,"Levi","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting","Agentic LLM applications introduce a promptware threat where adversarial inputs can induce malware-like behavior inside an application’s context. Prior promptware research relied on direct or indirect injection channels, often in targeted settings. This work shows scalable untargeted promptware is feasible without direct channels by exploiting LLM hallucinations of resource identifiers. It proposes adversarial hallucination squatting: pre-registering trending resource names that LLMs are likely to hallucinate, enabling botnet-style propagation. Experiments report up to 85% repository cloning generation and up to 100% skill installation.","Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal  \nand Transferable Adversarial HalluSquatting  \nAya Spira 1 , Stav Cohen2 , Elad Feldman 1 , Ron Bitton3 , Avishai Wool 1 , Ben Nassi 1   \n1Tel Aviv University, 2Technion, 3Intuit  \narXiv :2607 .07433v 1 [ cs .CR] 8 Jul 2026  \nAbstract—The growing adoption of agentic LLM applications has introduced a new threat previously named as promptware. While prior work has established that adversaries can exploit direct channels to LLM applications to apply promptware (push adversarial prompts) under weak threat models (e.g., by sending emails or calendar invitations to a target), many applications do not provide any direct channels that could be exploited for prompt injection beyond the Internet. This raises a fundamental question: can attackers exploit LLM applications at scale without any direct channels in practical threat models? In this work, we show that the inherent tendency of LLMs to hallucinate resource identifiers can be exploited to amplify untargeted promptware attacks that pull adversarial prompts at scale and could be exploited to establish a botnet. We introduce adversarial hallucination squatting, a technique in which attackers identify trending resources (e.g., popular repositories, popular skills, etc.), compute the LLM distribution of hallucinations on the trending resource names, and preemptively register them to host adversarial prompts (e.g., instructing an LLM to install a bot or running a script that installs a bot). By leveraging the predictability and transferability of hallucinations across foundational LLMs and to application layers, adversaries can significantly amplify the reach ofuntargeted promptware under weak threat models and establish a botnet by exploiting LLM applications to install a bot on the device that \"pulled\" the compromised hallucinated resource from the Inter. We empirically demonstrate that hallucinated resource generation occurs at high rates—up to 85% in repository cloning scenarios and up to 100% in skill installation—and that these hallucinations transfer between foundational models and different prompts. We demonstrate the practicality of adversarial hallucination squatting against various LLM applications with integrated terminals in their set of tools, including AI coding assistants (Cursor, Cursor CLI, Windsurf, GitHub Copilot, Cline), CLIs (Gemini CLI), and assistants (OpenClaw, ZeroClaw, and NanoClaw), achieving remote tool execution and remote code execution (RCE). We conclude by discussing mitigation strategies and the similarities to typosquatting  \n1. Introduction  \nLLM-powered applications increasingly incorporate agentic frameworks that enable them to perform actions such as accessing local files and invoking system APIs.  \nIn parallel with their growing adoption (see [15] and the references within), recent research has highlighted a new class of threats known as Promptware [20] . Promptware refers to inputs (textual, visual, or auditory) deliberately engineered to behave like malware by exploiting an application’s LLM to induce malicious behavior within the application’s context. Ongoing studies have demonstrated various variants of Promptware attacks against real-world systems, including ChatGPT [24], [10], Google Assistant [19], Copilot [3], and various additional applications (seethe blog [25]) . These works demonstrated that Promptware can lead to financial, privacy, and safety impacts.  \nWhile the above-mentioned studies demonstrate that promptware poses a significant risk to LLM applications in production, existing attacks largely assume that adversaries can inject compromised content into the target application. Early promptware attacks were typically achieved via direct prompt injections [9], [29], in which the user is the attacker. Newer demonstrations showed that adversaries can inject malicious instructions into data ingested by the LLM by exploiting application interfaces or commu","cbCaiemDgpSJWqJP","https://ap.wps.com/l/cbCaiemDgpSJWqJP","pdf",720901,1,22,"English","en",105,"# Abstract\n# Introduction\n## Background on Promptware\n## Direct vs Indirect Prompt Injection\n## Motivation for Untargeted Scaling","[{\"question\":\"What problem does this paper address in agentic LLM applications?\",\"answer\":\"It addresses how attackers can scale promptware attacks against agentic LLM apps even when there are no direct injection channels in practical threat models.\"},{\"question\":\"How does adversarial hallucination squatting work?\",\"answer\":\"Attackers identify trending resources, estimate the LLM hallucination distribution over those resource names, and preemptively register them to host adversarial prompts that trigger bot installation or automated scripts.\"},{\"question\":\"What evidence does the paper provide for feasibility and impact?\",\"answer\":\"It demonstrates high hallucinated resource generation rates (up to 85% for repository cloning and up to 100% for skill installation), plus transferability across foundational models and prompts, enabling remote tool execution and remote code execution in multiple applications.\"}]",1784200096,55,{"code":4,"msg":30,"data":31},"ok",{"site_id":24,"language":23,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":85,"head_meta":87,"extra_data":89,"updated_unix":27},"beware-of-agentic-botnets-scalable-untargeted-promptware-attacks-via-universal-and-transferable-adversarial-hallusquatting","",{"@graph":35,"@context":84},[36,53,67],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/beware-of-agentic-botnets-scalable-untargeted-promptware-attacks-via-universal-and-transferable-adversarial-hallusquatting/84994/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":61,"encodingFormat":60,"isAccessibleForFree":62,"interactionStatistic":63},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-16",true,{"@type":64,"interactionType":65,"userInteractionCount":4},"InteractionCounter",{"@type":66},"ViewAction",{"@type":68,"mainEntity":69},"FAQPage",[70,76,80],{"name":71,"@type":72,"acceptedAnswer":73},"What problem does this paper address in agentic LLM applications?","Question",{"text":74,"@type":75},"It addresses how attackers can scale promptware attacks against agentic LLM apps even when there are no direct injection channels in practical threat models.","Answer",{"name":77,"@type":72,"acceptedAnswer":78},"How does adversarial hallucination squatting work?",{"text":79,"@type":75},"Attackers identify trending resources, estimate the LLM hallucination distribution over those resource names, and preemptively register them to host adversarial prompts that trigger bot installation or automated scripts.",{"name":81,"@type":72,"acceptedAnswer":82},"What evidence does the paper provide for feasibility and impact?",{"text":83,"@type":75},"It demonstrates high hallucinated resource generation rates (up to 85% for repository cloning and up to 100% for skill installation), plus transferability across foundational models and prompts, enabling remote tool execution and remote code execution in multiple applications.","https://schema.org",{"og:url":51,"og:type":86,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":88,"canonical":51},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":91},[92,96,100,104,109,114,119,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":93,"show_sort_weight":94,"slug":95},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":97,"show_sort_weight":98,"slug":99},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":101,"show_sort_weight":102,"slug":103},"Exam",70,"exam",{"id":105,"doc_module":4,"doc_module_name":45,"category_name":106,"show_sort_weight":107,"slug":108},5,"Comic",60,"comic",{"id":110,"doc_module":4,"doc_module_name":45,"category_name":111,"show_sort_weight":112,"slug":113},6,"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":45,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":45,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":45,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":45,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":45,"category_name":136,"show_sort_weight":105,"slug":137},19,"General","general"]