AML-ATLAS-2026-20 | MITRE ATLAS Mapped 2026 – Top AI Threat Detection: LLM-Powered Spearphishing Social Engineering (AML.T0052.000)

Detects external email or chat messages containing markers typical of Large Language Models (LLMs) combined with urgent language soliciting sensitive information, such as credentials or financial details. The rule correlates these findings with messages from domains that have been recently observed in the environment, indicating potential automated, personalized social engineering campaigns.