Written Content

T1683.001

Sub-technique of T1683 Generate Content.View on attack.mitre.org

About this technique

Adversaries may create or tailor written materials to support targeting and malicious operations. Content may include phishing lures, fraudulent financial communications, fabricated job postings, fabricated employment credentials and documentation, decoy documents, social media persona content, and supporting narratives used to sustain fabricated personas over time. Content may be authored manually, commissioned through third parties, or produced using AI-assisted tools.

Written materials may impersonate legitimate government correspondence, diplomatic communications, or internal organizational documents to support targeting efforts. AI-assisted tools may also be used to tailor content to specific targets, industries, or regions. For example, adversaries may leverage AI to translate content into a target's native language or mimic the communication style of trusted senders.

Written content produced through these methods may be used in support of other techniques, such as Phishing, Spearphishing via Service, Phishing for Information, Internal Spearphishing, Social Engineering, Financial Theft, or Establish Accounts.

Written content does not include malicious code or scripts; for development of malicious code and scripts, see Develop Capabilities.

Detection rules0

Rules on DetectionCode tagged with T1683.001.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups3

Software1

Campaigns0

None recorded.

Procedure examples4

Groups3

Used byProcedure example
GroupAPT-C-36

APT-C-36 has generated email content impersonating official notifications and documents that direct victims to execute malicious payloads.

GroupContagious Interview

Contagious Interview has created fake social media accounts such as LinkedIn and Telegram accounts for their targeting efforts.

GroupTeamPCP

TeamPCP has created Dune-themed GitHub repositories using stolen tokens.

Software1

Used byProcedure example
MalwareKali365

Kali365 has generated tailored branded phishing lures to target victims utilizing a myriad of reputable services and brands that entice users to interact with the content. Kali365 has also been enabled with AI such as Claude Sonnet that evaluates emails and generates tailored responses to facilitate BEC activities.

References2

  1. GTIG AI Threat Tracker Open source
    Google Threat Intelligence Group . (2026, February 12). GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use. Retrieved March 25, 2026.
  2. GenAI Phishing Open source
    Adaptive Team. (2025, August 29). Generative AI Phishing: How to Defend in 2025. Retrieved March 26, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.