Has used Bland AI to create conversational pathways tailored to specific scenarios during voice phishing attacks.1
Artificial Intelligence T1588.007
- Tactic
- Resource Development
- Platform
- PRE
- Version
- 1.1
- Created
- 11 March 2024
- Last modified
- 12 May 2026
- Contributor
- Menachem Goldstein
Adversaries may obtain access to generative artificial intelligence tools, such as large language models (LLMs), to aid various techniques during targeting. These tools may be used to inform, bolster, and enable a variety of malicious tasks, including conducting Reconnaissance, creating basic scripts, assisting social engineering, and even developing payloads.[1]
Artificial Intelligence MITRE reference T1588.007
3 groups have been recorded using this technique. Newest first; each entry carries MITRE’s procedure text and a link to the group’s full record. Click a name to filter the rules below.
Has appeared to have used AI to generate images and content to facilitate their campaigns.1
Has deployed LAMEHUG which can can query an LLM to generate and return commands for post compromise activity on targeted systems.1
All 3 groups for this technique
2 campaigns have been recorded using this technique. Listed newest first; dates are year-granularity and attribution is MITRE’s.
During the Anthropic AI-orchestrated Campaign, the adversary obtained access to Claude Code to support cyber intrusion operations.1
During the 2025 Poland Wiper Attacks, the adversaries generated custom script with an LLM.1
All 2 campaigns for this technique
1 software entry is documented implementing this technique. MITRE files each as a tool or as malware; newest first, then by how many groups carry them.
Is believed to have been generated by a large language model (LLM) due to the non-sensical comments in the code.1
All 1 software entries for this technique
Offense vs defense T1588.007
Is defensive coverage keeping up with adversary use? Eight counts, each ranked against all 697 ATT&CK techniques. Attack sits left, defense right, so a shape leaning left means adversaries are better documented here than defenders are equipped. Hover any spoke for its percentile and the share of techniques that have more. The timeline below shows when each side arrived.
Artificial Intelligence detection strategy DET0842
MITRE names one behaviour worth catching for this technique and breaks it into 1 analytic, one per platform. Each carries the log sources it needs and the fields you tune per environment.
Detection of Artificial Intelligence
AN1974 · PRE
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the potential use of generative artificial intelligence (i.e. Phishing, Phishing for Information).
This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.