Mass-BCC Legal-Lure Phishing: BCC Delivery with Legal Threat Subject (T1566.002)

Detects potential phishing campaigns by identifying bulk inbound emails sent to generic recipient aliases (e.g., info@, support@) or to empty recipient fields, combined with subject lines referencing urgent legal or compliance matters (e.g., lawsuits, subpoenas, copyright infringement). The rule uses statistical analysis to flag high-volume emails and correlates them across shared body content patterns to identify coordinated mass-mailing campaigns.