ATLASAML.T0052.000
ATLAS index
AML.T0052.000

Spearphishing via Social Engineering LLM

Adversaries may turn LLMs into targeted social engineers. LLMs are capable of interacting with users via text conversations. They can be instructed by an adversary to seek sensitive information from a user and act as effective social engineers. They can be targeted towards particular personas defined by the adversary.

Framework
MITRE ATLAS
Maturity
Demonstrated
Platforms
Enterprise
Release
2026.05

Overview

Adversaries may turn LLMs into targeted social engineers. LLMs are capable of interacting with users via text conversations. They can be instructed by an adversary to seek sensitive information from a user and act as effective social engineers. They can be targeted towards particular personas defined by the adversary. This allows adversaries to scale spearphishing efforts and target individuals to reveal private information such as credentials to privileged systems.

Sources

  1. MITRE ATLAS AML.T0052.000: Spearphishing via Social Engineering LLM — MITRE