Sublime layers enriched detections, contextual machine learning analysis, and autonomous AI agents to stem the tide of oncoming, ever-evolving AI attacks.

The reality of AI email attacks

You know attackers are using AI. It’s all over the tech headlines, professional networks, and influencer channels. But what does “attackers are using AI” mean to you?


If you’re a government, multinational enterprise, or you handle the data or finances of either, you could be the target of a sophisticated, AI-powered attack delivered by an APT (advanced persistent threat) or nation-state actor. These attacks will feature fleets of autonomous agents with deep intelligence gleaned through years of designed recon and espionage using custom tooling that’s not generally available to the general public. The tools and intelligence aren’t new, but the speed and scale of agents is. But your intelligence and security teams have seen this coming and have stockpiled their own autonomous agents, custom tooling, and in-depth intelligence.


But most organizations aren’t large enough to be the target of nation-state threat actors, so how are the attacks and scams you’re actually facing being enhanced by AI? Adversaries are using AI the same way AI companies are advising you to use it. They’re creating tailored, self-improving workflows that are designed to attack at scale and with ever increasing efficacy. Just like APTs, virtually every adversary and scammer now has access to a fleet of agentic attackers that operate 24x7.

In this guide, we’ll take a look at what makes AI especially useful for attackers, an example workflow for an AI-operated attack campaign, and how Sublime is using defensive AI to not just keep up, but to get ahead of novel attacks.

Attackers use AI without guardrails

Every attacker has access to the same powerful AI tools as the rest of us, but they’re not limited by AI guardrails, the cost of tokens, or ethical constraints.

Agents

Autonomous AI agents (e.g. OpenClaw, Hermes) are powerful orchestrators for creating fully automated workflows. Once a series of prompts has been developed, these agents can run 
on their own and automatically adjust their workflows based on thresholds and conditionals provided by their user. With autonomous agents, attacks can be continuous and self-improving.Additionally, attackers are well-suited to clear the hurdles that agents can present:

  • Complexity:
    Agents are installed via CLI and can prove difficult to configure for non-technical users. Adversaries are technically savvy, many being overeducated and underemployed, and are used to implementing new technologies into their workflows. 
If they can use a phishing kit, they can use an agent.

  • Cost:
    Agents will burn through tokens unless otherwise instructed. Throttling token usage, though, will impair the user’s ability to use them fully autonomously. Adversaries will compromise accounts or use stolen funds for model tokens. Account compromise and financial misconduct are old standards for attackers. Using them to get access to AI is just the latest reason to use them.

Models

Frontier AI models (e.g. Claude, ChatGPT) are fast and capable. They operate in large data centers with top-shelf hardware. But these hosted models also operate with safety guardrails that can make them difficult to use for delivering attacks. These safeguards are meant to protect average users from harming themselves or others.

Adversaries can easily get around this by operating an unrestricted model locally, including jailbroken models on the dark web that can come pre-trained on attack TTPs. By using a combination of models, they can run allowed operations on cloud models for speed and restricted operations on local LLMs to bypass guardrails – all with the agent orchestrating the piping of data from one to the other.

Skills

Along with restrictions around illegal operations, cloud AI models are also restricted from accessing certain sites. For example, LinkedIn does not allow access directly from LLMs, making it difficult for the average AI user to scrape the professional network.

Agents, though, can be augmented with skills. Skills are specifically designed for a specific task or group of tasks. In the case of the above example, there are multiple skills available on marketplaces built to log into LinkedIn, these can be purchased with stolen funds, and an adversary wouldn’t care about violating LinkedIn’s terms of service (ToS).

Adversarial pentesting

Defenders need to stop every attack, but adversaries only need to get one through. With AI, adversaries can perform penetration tests and recon operations at speed and scale, automatically turning analytics into insights for honing further attacks. This creates an iterative attack cycle, meaning defenders must also be constantly evolving.

AI attack example: Skip-level credential phishing

Let’s take a look at how adversaries can put their unfair AI advantages to use in an example attack. In this scenario, an adversary is building and delivering a skip-level credential phishing attack. The term “skip-level” refers to a manager or director a few levels above the target.

In skip-level attacks, adversaries impersonate a boss’ boss (or higher up the ladder) in order to leverage authority while bypassing familiarity. A target will have an easier time seeing through an impersonation of their direct manager due to the amount of 1:1 interaction they have. This makes the manager’s manager a better option for impersonation. There is likely less 1:1 interaction with the target, as well as a greater power imbalance to dissuade the target from pushing back on a request.

PHASE 1: Attack Development

1.1 Setting up the agent

The attacker spins up an AI agent and attaches multiple LLMs and skills.

Models: They connect multiple cloud and local LLMs. As mentioned above, the cloud LLMs are more performant, but the local LLMs offer unrestricted usage. By connecting multiple, they can use the different models to verify the work in each step before proceeding.

Skills: They add all the skills required for the attack (e.g. professional network scraping (LinkedIn), social media scraping, autoresearch, etc.)

1.2 Building an org chart

AI agent scrapes the web, social media, and professional sites to build an org chart of the target company. By having a detailed org chart, the agent can more easily and accurately identify the employee to target and the skip-level manager to impersonate.

1.3 Identify a target employee

Scammers often target HR, Finance, and Sales for attacks due to the financial information they often have access to. Using the org chart, the agent then looks for lower-level employees to target. The agent can use various criteria for weighting the decision, such as frequency of posting on professional networks, as that could be an indicator that the target is attempting to be recognized for accomplishments or ideas. An attacker may assume that an employee trying to gain visibility with leadership is more likely to respond to an urgent request from a senior manager.

1.4 Identify a skip-level manager to impersonate

Now that a target is identified, the AI agent can consider options for the skip-level manager. They would likely be two or more levels higher than the target, but not so high that it would raise suspicion (e.g. CEO). The manager should also post enough on professional sites, social networks, or personal blogs so that the agent can scrape their content and teach itself to impersonate their writing style. Additionally, the agent may want to see minimal contact between the manager and the target, indicating a lack of familiarity.

1.5 Generate the skip-level credential phishing email

Using the information scraped for impersonation, the agent creates a phishing email in the voice of the manager. The message is:


  • Urgent:
    The skip-level manager has an important meeting in 15 minutes and needs access to a financial spreadsheet.
  • Believable:
    The spreadsheet is on the target’s manager’s personal cloud storage, but the skip-level manager saw that the target also had edit access.
  • Malicious:
    The link to the spreadsheet is actually a convincing adversary-in-the-middle (AITM) credential phishing page that is designed to look like a normal login screen for the cloud storage provider (e.g. Google Workspace or Microsoft 365). When the target clicks the link, they’ll enter their credentials and then a Document Shared confirmation screen will appear.

PHASE 2: ATTACK DELIVERY

2.1 Lookalike domain

The AI agent spins up a lookalike domain for impersonation purposes. If the target company is at targetcompany[.]com, the lookalike could be target-company[.]com, targetcompany[.]co, targetcornpany[.]com, etc.

2.2 First-time sender evasion

The AI agent sends an innocuous, non-attack email to the target employee. By successfully delivering a non-malicious message from the lookalike domain, the attacker is attempting to lower the guard of email security systems that use a “first-time sender” signal during risk scoring. This email could be as simple as:

2.3 Attack via phishing kit or Phishing-as-a-Service (PhaaS) infrastructure

The AI agent uses a phishing kit (e.g. Tycoon2FA) or a PhaaS (e.g. EvilProxy) to deliver the attack. The malicious link in the message will point to the AITM infrastructure. This could include a redirect from the lookalike domain.

PHASE 3: ATTACK ITERATION

3.1 Analysis

The AI agent collects and analyzes click data from phishing kit/PhaaS log files for all ongoing attacks. It groups successes and failures, looking for commonalities in the messages of each set. It creates a knowledge base of proven best practices for future attacks.

3.2 Iteration

Using a skill or package that encompasses autoresearch-like capabilities, the AI agent uses analysis results to evolve evasion tactics, hone targeting, adjust timing, and improve engagement in future attacks.

  • What language worked best?
  • What roles were more open to clicks?
  • What choices in 1.3 and 1.4 were most effective?

The agent restarts the attack cycle with fresh insights.

This should all look familiar to security practitioners. What attackers are doing with AI isn’t new, it’s just been operationalized in a way that had in the past been reserved for advanced attackers. AI is giving every attacker the chance to do advanced tailoring and be around the clock persistent.

Defending against AI attacks with Sublime

One-size-fits-all security isn’t compatible with targeted, self-improving AI attacks. Modern defenses need to be context-aware, tailored, and rapidly adaptive. On top of all that, they need to be able to run autonomously to stay ahead of attackers.

This is how Sublime is built. Sublime’s multi-layer email security adapts itself to your specific organization, learns from every attack, and closes coverage gaps autonomously – and it does it all right out of the box.

While modern AI security systems are designed to handle AI attacks, they run into their own issue: the agentic AI trilemma. Agentic AI cannot be applied to directly solve high volume, low latency, high efficacy problems across all use cases. If agents are applied to solve all three, then costs become prohibitive. This means “throw more agents at it” isn’t the right solution.


With purely agentic security systems, you’ll see shortcuts built into systems to reduce agent workload. For example, some solutions will apply decision making shortcuts, where as soon as a message is considered malicious, it’s put in quarantine with no further analysis. While this tactic will reduce agent latency, it will also reduce the amount of security intelligence that can be learned from properly analyzing the email. This intel shortcut hurts in the long run.


Rather than attempt to ignore inherent constraints or create suboptimal workarounds, Sublime is designed to use AI agents with precision and intentionality. We do this by layering our security with high-speed detections and machine learning algorithms to reduce the load on agents without sacrificing intelligence. By decreasing the volume of messages sent to agentic AI, Sublime is able to maximize efficacy while minimizing latency.

Layer 1: High-level detections

The first layer of security uses high-level detections to determine if an email is safe, malicious, or somewhere in between. These detections are written in Message Query Language (MQL), our purpose-built domain-specific language (DSL) for transparent, explainable email security. When new organization-specific detections are created by an AI agent (see Layer 3), they are written in MQL so security teams have full visibility into the security process.


Detections use both standard and ML-powered enrichments to apply a non-final severity verdict from low to critical. Enrichments include:

  • ML-powered:
    Link analysis, computer vision, optical character recognition (OCR), natural language understanding (NLU), email classification, entity recognition, topic modeling, and more.

  • Non-ML:
    File analysis, file explosion, organizational context, sender profiles, and more.

Detections provide high-speed, high-volume triage with efficacy that allows for false positives due to the non-final nature of its verdicts. This layer ensures that true negatives do not receive any further analysis.

Layer 2: Attack Score

Emails that match a high-level detection are then run through our Attack Score feature. Attack Score is also built on MQL, and it leverages machine learning to analyze hundreds of signals extracted from various parts of an email to surface common attack patterns and unusual activity. These signals are derived from:

  • Headers
  • Attachment metadata
  • Link analysis
  • Past sender behavior
  • Organization-specific context
  • Content understanding
  • Authentication checks and more

After analysis is complete, an email is assigned an Attack Score verdict that drives triage:

  • Benign: return to inbox
  • Malicious: send to quarantine
  • Spam: send to spam
  • Graymail: send to promotions
  • Suspicious: send to AI agent for further analysis
  • Unknown: send to AI agent for further analysis

By using detections to reduce the volume of messages sent to Attack Score, we’re able to make final determinations with high levels of certainty at low levels of latency. Since both layers are built on MQL, the decision making process is transparent, explainable, and rich with security intelligence.In the case that an email receives a verdict in which certainty is known to be low (suspicious and unknown), it is then sent to an AI agent for further analysis.

With Sublime, most AI attacks are stopped before they ever reach a defensive AI agent. This decrease in volume is how we avoid the agentic AI trilemma.

Layer 3: AI Agents

ASA (Autonomous Security Analyst)

Messages with a suspicious or unknown verdict are then passed to ASA, an AI agent that has access to all of the MQL, enrichments, tools, and knowledge within Sublime. Unlike many AI agents, ASA doesn’t just perform analysis, it also provides a thorough explanation of how it came to its conclusion.

ASA offers configurable autonomy ranging from human-in-the-loop to full autonomy, meaning organizations can incrementally build trust with ASA before letting it run without oversight. Over 99% of messages that are sent to ASA are given a final verdict without the need for human assistance, dramatically decreasing the amount of work that lands in front of a human security analyst.

Learn about ASA

ADÉ (Autonomous Detection Engineer)

If ASA determines that an email is malicious and there is no high-level detection to catch it, it passes the email and its analysis to ADÉ. Using ASA’s analysis, ADÉ writes, tests, iterates, and backtests a new detection for the novel attack.

Just like ASA, ADÉ provides options for autonomy and explanations for the decisions it makes. Most teams use ADÉ with a human in the loop for final detection approval for some time prior to giving ADÉ full autonomy.


Learn about ADÉ

Fast, effective, self-improving AI security 
at scale

By decreasing the volume of messages sent to AI agents, we are able to keep up with the speed and scale of AI attacks. And by using AI agents to autonomously harden our detections, we’re able to keep up with the rapid iteration and evolution brought to us by agentic AI attacks.

Sublime shifts the agentic advantage from attackers to defenders. Our agents are autonomous, our coverage adapts quickly with organization-specific tailoring, and our layered defenses mean speed at scale without sacrificing intelligence opportunities. On top of that, every decision our platform makes – from detection to agentic analysis – is transparent, explainable, and auditable thanks to MQL and AI reasoning output.

AI is changing email attacks. Sublime is changing the defense. Get a live demo to see how.

Back to Resources