Has created Dune-themed GitHub repositories using stolen tokens.1
- Tactic
- Resource Development
- Platform
- PRE
- Version
- 1.0
- Created
- 25 March 2026
- Last modified
- 12 May 2026
Adversaries may create or tailor written materials to support targeting and malicious operations. Content may include phishing lures, fraudulent financial communications, fabricated job postings, fabricated employment credentials and documentation, decoy documents, social media persona content, and supporting narratives used to sustain fabricated personas over time.[1][2] Content may be authored manually, commissioned through third parties, or produced using AI-assisted tools.
Written Content MITRE reference T1683.001
3 groups have been recorded using this technique. Newest first; each entry carries MITRE’s procedure text and a link to the group’s full record. Click a name to filter the rules below.
Has created fake social media accounts such as LinkedIn and Telegram accounts for their targeting efforts.1
Has generated email content impersonating official notifications and documents that direct victims to execute malicious payloads.1
All 3 groups for this technique
1 software entry is documented implementing this technique. MITRE files each as a tool or as malware; newest first, then by how many groups carry them.
Has generated tailored branded phishing lures to target victims utilizing a myriad of reputable services and brands that entice users to interact with the content.1234 Kali365 has also been enabled with AI such as Claude Sonnet that evaluates emails and generates tailored responses to facilitate BEC activities.4
All 1 software entries for this technique
Offense vs defense T1683.001
Is defensive coverage keeping up with adversary use? Eight counts, each ranked against all 697 ATT&CK techniques. Attack sits left, defense right, so a shape leaning left means adversaries are better documented here than defenders are equipped. Hover any spoke for its percentile and the share of techniques that have more. The timeline below shows when each side arrived.
Written Content detection strategy DET0917
MITRE names one behaviour worth catching for this technique and breaks it into 1 analytic, one per platform. Each carries the log sources it needs and the fields you tune per environment.
Detection of Written Content
AN2060 · PRE
Much of this takes place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls. Efforts should focus on designing defenses that are not reliant on atomic indicators.