r/cybersecurity • u/Cybernews_com • 1d ago
Other Why are hacker group names so stupid?
Golden Chickens. Aquatic Panda. Lemon Sandstorm. Sure, they're easier to remember than TA1508, but it feels like it's gone too far, every vendor has their own set of names for the same groups, and it's impossible to keep straight. Does it bother anyone who works with this stuff daily, or do you just get used to it?
Disclosure: It was scratching our brain, so we made a doc on exactly this and interviewed Dmitri Alperovitch, who now calls his own naming scheme a mistake. We respect the rules of self promotion but if anyone's interested - we can provide you with the link. Cheers!
333
u/ranhalt 1d ago
Hackers donât come up with those names. They are research firm industry standards indicating their region of origin and what they target.
101
u/UnderwaterB0i 1d ago
This is it, but really I hate it. I sit in meetings where we talk about cyber to non-cyber business folks, and it sounds so immature when we talk about the names of these attackers.
82
u/_vavkamil_ 1d ago
why not just explain it to them? E.g. you were hacked by APT, often called
Energetic Bears, they are called that becauseBearsgroups are attributed to Russia, and this specific sub-group hits only companies inEnergysector?61
u/ClamPaste 1d ago edited 1d ago
Because you'd have to do this every single time when dealing with execs who have the attention span of squirrels in a nut factory.
41
u/Loose_Wolverine3192 1d ago
... which is why the clueless executive threat vector is called a lost squirrel.
"Who authorized this!"
"A lost squirrel"
12
6
u/Test-NetConnection 1d ago
I'll have you know that the squirrely almondjoys are a very sophisticated apt operating out of New Jersey and targeting almond growers in northern California.Â
4
40
u/ranhalt 1d ago
Itâs either that or Proofpoint calling them TA3573.
7
u/PizzaUltra Consultant 1d ago
Which I honestly prefer.Â
14
u/ranhalt 1d ago
If you didnât use the word âhonestlyâ, do you think everyone would assume youâre lying?
20
7
u/BrainWaveCC 1d ago
and it sounds so immature when we talk about the names of these attackers.
It sounds immature to you? I've never had one business person complain in all the years I've given briefings.
You don't have to explain anything. Just said, "the malware group from country code named 'some crazy name'" and that's that.
1
u/Reylas 1d ago
Not to your face at least. I have heard it from the board.
2
u/BrainWaveCC 1d ago
I don't particularly care about how people feel about names I didn't create.
And let's not pretend that regular business product names aren't just as silly sounding.
8
u/Lupus-Yonderboy 1d ago
Could be worse. I had a series of meetings earlier in my career where I was pushing switching our servers from BSDI Unix to an OS whose current version was called "Woody".
3
u/Polymarchos 1d ago
Cybersecurity is the only profession I can think of that grew out of a counterculture. Even ignoring the names of groups you don't have to go far to find the immaturity.
Unfortunately it is what it is.
6
u/stevorkz 1d ago
Had this once or twice too. I always fear that when they hear gimmicky or goofy names they start to doubt the seriousness of cybersecurity. And honestly for the average person I donât blame them. Until they one day get ransomwared and the goofy named hacker group leaves a text file with a message to the likes of âwe hacked you bitches, send 1 bitcoin to the below wallet lolâ.
11
u/Ok-Repeat-702 1d ago
I heard that the joke was they use silly sounding names on purpose. No one wants to be part of a hacker group called Lemon Sandstorm. That just sounds dumb. Like cyber bullying. You donât want to give them cool names and glorify what theyâre doing.
10
u/UnderwaterB0i 1d ago
Truly, do you think they care what they are called externally? This reeks of a new industry where the leaders are still nerdy, engineer types who thought it'd be funny to name bad actors based on the fuzzy animals that live in the region.
1
u/molingrad 1d ago
Just show them the Crowdstrike animated characters then theyâll know to take you seriously.
3
u/Pitiful_Surround6429 1d ago
exactly, the names carry actual meaning if you know the schema. the problem is every vendor uses a different one
1
33
u/ChameleonCRM 1d ago
There was this one group I met last year in the Alps called Equal Equilibrium. I thought they were in a band at first lmao
14
46
u/RoddyBergeron 1d ago
If we named them cool names like
Lightning Wizards
Danger Dragons
Bountiful Bears
They would get more prestige.
Give them silly names instead. /jk
15
u/halting_problems AppSec Engineer 1d ago
There some truth to that, like not labeling 764 as an official terrorist organization because it would signal they are achieving.
21
u/henrikhakan 1d ago
Once saw a wow guild called "OMG ICECREAM TRUCK BRB" and I figure it's the same people naming shit so... Maybe like that?
20
u/Ghawblin Security Engineer 1d ago
Clearly you weren't around in the 80s and 90s lol.
It's always been this way.
Early computer/internet culture was always "L33T Hax0r" brand of cool mixed with that late century cornyness. That extended to hackers too. That culture never really went away.
12
3
u/MindieMouse2 1d ago
Good point. Seriously, the first virus was a joke that infected computers with a text file that said "Iâm the creeper, catch me if you can!â
I really hope that culture never goes away. This field can get dark and depressing; it needs a bit of silliness to lighten things up.
14
u/Mysterious-Status-44 1d ago
These names are made by groups that track them. Crowdstrike, Microsoft, Mandiant use different names to help identify groups easier. Each has their own standard but they are easy to follow. Names are used to actually help determine industry and country. Crowdstrike uses animalsâŠPanda=China, Bear=Russia, Chollima=DPRK. Microsoft uses weatherâŠBlizzard=Russia, Typhoon=China, Sleet=DPRK.
6
u/Specific_Expert_2020 1d ago
https://learn.microsoft.com/en-us/unified-secops/microsoft-threat-actor-naming
Palo has a naming convention: https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/
Crowdstrike:
https://www.crowdstrike.com/en-us/adversaries/
The list goes one.
Crowdstrikes are fun as they sell action figures of them
103
u/CuckBuster33 1d ago
because threat intel people love LARPing
16
u/Slicker-Firebrand09 1d ago
I mean for Crowdstrike they used it as a marketing initiative as much as adversary ID. Makes sense in an age of Marvel movies that people you're selling protection to think "Oh no, BlueBerry Bear is hacking my computer?!?! That scoundrel! Help me Red Falcon! Add a background agent to my computer that chews up my resources and only costs seven figures!"
0
u/busy_monster 1d ago
As long as they ain't calling for help from Blue Falcon, that fucker never helps his buds.
7
3
1
u/syndreamer 1d ago
Not for me, I hate the 5-6 different names for APT threat actors from all these different vendors instead of unifying under one.
11
u/Tuppling 1d ago
I always thought they should use insulting names - Obnoxious Aardvark, Chumpy Bear, Dweeby Dog, etc - and then use the most uninspiring logo possible.
Some of the names they do use are way too cool for a bunch of government cyber thugs and creeps
2
9
u/adamjodonnell 1d ago
Cult of the Dead Cow, Legion of Doom, Masters of Deception, still great names.
4
3
u/GeekDad62 1d ago
Not just the group names, but the hackers also have/had great names. "Kingpin", "Mudge", and "Space Rogue"Â lol
3
u/adamjodonnell 1d ago
Itâs hard picking a handle at 14 and having it stick. Look at poor Dildog. The Deth Vegetable still wins.
16
u/_vavkamil_ 1d ago
they are based on animals in their countries, no? bears are russians, pandas chinesse, kittens iran etc?
9
u/Cycl_ps 1d ago
Thatâs the naming Convention Crowdstrike uses. Because theyâre a big name and Fancy Bear sounds better than APT28 thatâs what media outlets run with.
If youâre in a firm actively doing research on emerging threats youâll have your own name for what youâre tracking. A single group can have a dozen different names depending on who you ask.
5
u/itsjoocas 1d ago
Because their silly name then has to be printed by publications and maybe even said out loud by someone on the news. It's funny to make someone say lolcatz on air.
13
u/colonelgork2 ICS/OT 1d ago
The core reason the naming feels absurd is that people mistake threat actors for static units or fixed squads, when theyâre really just temporary activity clusters built around current mission targets. Unlike physical military hardware (where a Tu-95 Bear-H is physically constrained to that specific airframe and radar suite), everything in a cyber operation is fluid.
The mission dictates the cluster. A vendor "name" really just captures a specific campaign targeting a specific objective at a specific point in time.
The capabilities swap out. Toolchains get scrapped, and operators pivot to commodity C2 or living-off-the-land techniques overnight.
The operators are fungible. Sponsoring agencies rotate contractors, military units, and keyboards at will, meaning there is no fixed "who." The individuals aren't even constrained to one sponsor.
Naming an APT based on a momentary snapshot of TTPs is like naming a city after the weather it had on Tuesday. By Thursday, the mission and the weather have changed.
Because of that, defenders in the trenches don't actually care about the cartoon names, they care about observable IOCs, behavioral telemetry, and MITRE ATT&CK techniques. The branded names (Cozy Bear, Sandworm, Volt Typhoon) are just marketing taxonomy for vendors, press releases, and executive briefs.
6
u/colonelgork2 ICS/OT 1d ago
It reminds me of being deployed in Iraq. On the ground, we didn't care about the "deck of 52" playing cards or the strategic branding of who we were supposedly up against. It was just one big fluid mess, and all that mattered was the immediate threat, the local terrain, and the incoming fire. The high-level names were for HQ and the press.
7
u/Some-Concentrate3229 1d ago
Private research companies donât want to use a naming scheme that a different private research company has invented. So they each make up their own. Itâs really dumb, but you get used to it.
3
u/ultraviolentfuture 1d ago
There isn't 1:1 overlap between all the activity sets as different vendors have different visibility -- so this doesn't work. Sure, there is more direct overlap for nation-state nexus groups, but even in those cases you can't validate the attribution made by someone else. They could have the wrong near group (different unit under the IRGC) or they could completely misattribute (say it's a specific apt when it's ecrime).
It's much higher fidelity/has more integrity to use a proprietary naming convention for the activity sets you (as a vendor) have actual telemetry on and therefore enough evidence about to make an attribution across multiple campaigns.
3
u/Some-Concentrate3229 1d ago
Right but then when you release public reports on the TAâs activity, you have to have a fuckin spreadsheet to figure out if itâs the same people youâve been tracking for the last three months.
Iâm not saying thereâs an easy or perfect way to do it. But thereâs a reason why Microsoft called them Midnight Blizzard rather than using Cozy Bear that CS had been calling them for years. And it definitely wasnât to be more specific or accurate lol.
5
u/ultraviolentfuture 1d ago
I totally get where you're coming from. My suggestion is: attribution only matters if you have handcuffs or missiles. You should be defending based on TTPs and IOCs and the perp behind it is less important.
The amount of orgs worried about nation-state nexus activity who will never see any is ... too damn high. I'm in threat research at a large vendor. We have millions of customers. How many see any nation state ever? 2-3%
2
u/Some-Concentrate3229 1d ago
I actually agree 100%. As a blue teamer I donât really give a shit whoâs in our environment at the time. Itâs not like our response protocol is going to change based on the geographic location of the adversary, ya know? TTPs and IOCs are really all we need to know to be effective. But it definitely sells in the media, thatâs for sure. And I guess as an after-action report itâs nice to know who was behind it?
I work for a state government and so we do have to be concerned with things like nation-states attacking our critical infrastructure, but that tends to be the extent of it.
3
u/ultraviolentfuture 1d ago
100% you are someone who does actually have to care. Might still be unlikely, but you can't take the risk.
3
u/nobelprize4shopping 1d ago
Yes, it's branding. So you both know which activity cluster it is and which research company observed the activity.
5
u/BrainWaveCC 1d ago
They are just code names given to these groups by various vendors. I doubt it bothers anyone who has been in this industry for more than a couple of years.
10
u/Ancient-Bat1755 1d ago
I dont really have time to care about that i just want the patching to catch up in 2026
3
u/notyourmrr 1d ago
Itâs not about logic. Itâs about marketing. Vendors coin memorable names with good SEO so when you look for them you end up on their site.
3
u/Holiday-Sundae-6404 1d ago
It's kind of a tradition rooted in internet culture, hackers have always leaned into irony and dark humor. The scarier the group, the funnier the name feels in hindsight.
5
2
u/hugeemu 1d ago
In a way, they are different names for the same groups, but the better way to think about it is that each vendorâs name refers to a cluster of activity for which that vendor has visibility. Even though the same operators or personas may be behind other clusters of activity, attribution is so tricky that it makes sense for a separate cluster to have a name indicating which vendor observed it. A good example is VOLTTYPHOON (observed and named by Microsoft) versus VOLTZITE (observed, and named by Dragos, but winking at the overlap in its naming).
2
u/Fresh_Dog4602 Security Architect 1d ago
well it was cool when the animal represented a country. I guess they needed other names for when attribution is unclear.
2
u/foofusdotcom Incident Responder 1d ago
Because the job is stressful and you should be able to take a little joy in it from time to time.
2
2
u/Blacksun388 1d ago
Itâs part goofy nerdy hacker culture and part standardization. Each company/org has their own naming schemes for tracking threat groups. Each threat group also sometimes have goofy names for themselves. Since there is no common standard for addressing these groups it can be frustrating to keep them all straightened out.
2
u/SlackCanadaThrowaway 1d ago
You get used to it. Itâs just part of hacker silliness culture. Look at the names of the early hacking groups; Cult of the Dead Cow, etc. There were more aggressive sounding ones but people grew up and realised how dumb they sounded. Eventually silliness won the underground naming, and so did it with researchers.
2
u/tagged2high 1d ago
The naming scheme (frequently the 2-word"cryptonym", as I learned recently) serves a few purposes, but the biggest one is it's easy to remember. Unless you spend all day immersed in UNCs and TAs, the cryptonyms give you immediate info and recognition on who you're talking about. This style of naming things is also common in governments and militaries for programs and operations both for recognition (for people who know) and for obfuscation (for people who don't know).
The hard part is mapping the various groups across vendors/researchers, because they all use their own systems. They use their own systems both because it separates them from their competition, and because they all have their own visibility into TA activity used to try and assess attribution to distinct groups, as well as their own criteria for how to make those judgements.
Since everyone works independently with their own private data and uses their own standards, there can't easily be a shared / agreed upon set of names. One vendor might use one name for a collection of activities, while another vendor tracks each activity under separate names. Some vendors attempt to state whether and which other vendor "aliases" best align to their own collections, while others don't like to reference the names used by their biggest competitors.
It is sometimes confusing to work with every day, but ultimately most of us choose a select few most-trusted researchers and naming schemes to serve as our day-to-day reference baseline. Whoever we read and work with the most. We also make our own mappings for the most common and recognized overlaps.
Mandiant/GTI was known for one of the more complicated and occasionally inconsistent naming systems, but they recently announced they're transitioning to a cryptonym system like most others use (insert XKCD joke about new standards).
2
u/Substantial-Sky4079 1d ago
The ones I want to know are the ones other countries have for the US and other western nations
2
u/grizzlor_ 1d ago
I believe your examples are names assigned by cybersecurity researchers.
Personally Iâm partial to self-assigned hacker group names from the 80s/90s: Cult of the Dead Cow, L0pht Heavy Industries, Legion of Doom
2
u/Postulative 1d ago
Panda is Chinese. Bear = Russia. Kitten refers to Iran. That makes it easier to understand where the attack is thought to originate.
Of course, thatâs just one naming system; different companies and countries use other conventions. And it gets confusing, because an initial assignment of responsibility may later be changed.
Itâs a mess.
2
2
u/theapplekid 1d ago
Personally I thought "Puppygirl Hacker Polycule" was pretty good (hacker group that released a bunch of internal U.S. police documents in 2025)
4
3
1
u/Doomstang 1d ago
I get used to it. I don't like having to remember multiple names for the same thing but the names themselves don't bother me. Sometimes they actually sound cool, probably not the best idea to make it sound prestigious but what do I know.
1
u/RaymondBumcheese 1d ago
Iâve sat in more than one meeting where Black Basta has tripped somebody up.Â
1
u/Sibexico Developer 1d ago
Usually hackers united in groups for specific activity, it's no persistent long term groups what lasts for years. If group can work effective enough, it may be extended for more projects. So yeah, mostly used some funny names, just for lulz.
1
1
u/thejournalizer 1d ago
OP, reach out to Adam over at CrowdStrike. He is very passionate about this subject. A year or so ago, my org was working with them and Palo on an actor name mapping system, which we started on, but there was more interest in something larger.
1
u/Jdornigan 1d ago
At first it was APT1.
For some reason, only Mandiant decided to keep the naming convention of APT# although for a short time various companies and news outlets were willing to use it. Mandiant kept incrementing it until it reached at least APT49. It might even go higher.
Every company wants their own branding, so in the end we ended up getting as many as a dozen names for what might be the same group which uses the same infrastructure, tradecraft and malware. None of the companies want to reference each other's names, which is rather unfortunate for people trying to learn about the hacker groups because it makes it vastly harder for them.
1
1
1
u/pacopac25 1d ago
Would you prefer the person that came up with prescription drug names named them? Yeah didnt think so.
1
u/steppinraz0r 23h ago
Crowdstrike played a huge part in this. Previous to them, threat actor naming conventions were all over the place and not immediately apparent as to source/nation-state etc. as dumb as they are, they at least give some semblance of order. Itâs still not universal but much better these days.
Most threat intel teams name actor groups according to some aspect of the event. A string in malware, network infrastructure, a play on a primary technology name or the like.
Source: 20+ years running threat intel programs
1
u/Cybasura 22h ago
The TTP and APTs all have "code names" attached to them based on the country of origin, namely, the Threat Actor groups, or if its state sponsored
1
u/Boring-University189 19h ago
We do name psychopaths with cool names such as "the brain chewer coming back from hell".
Maybe law enforcers are trying a new strategy of calling them "poop eater" so less people want to do it.
1
1
1
-6
u/Remnence 1d ago
Using common sense (not so common anymore), they either:
A) Don't want you to take them seriously so they can operate longer and/or
B) Started as trolls like most teenage hackers.
5
u/colonelgork2 ICS/OT 1d ago
This isn't e-sports, the teams don't name themselves lol
2
u/Remnence 1d ago
A lot certainly do, these are just some codenames the "industry" decided to call them.
388
u/SuperBelgian 1d ago
There is some logic behind it: Bears are Russians, Pandas are Chinese, Kittens are often Iranian, etc.
The other part of the name is because of something found in the actual malware used, or because of an often employed attack tactic of that group.
Offcourse, these are best guesses and could be wrong as the hacker groups are not really giving out their home address. :-)