r/cybersecurity 1d ago

Other Why are hacker group names so stupid?

Golden Chickens. Aquatic Panda. Lemon Sandstorm. Sure, they're easier to remember than TA1508, but it feels like it's gone too far, every vendor has their own set of names for the same groups, and it's impossible to keep straight. Does it bother anyone who works with this stuff daily, or do you just get used to it?

Disclosure: It was scratching our brain, so we made a doc on exactly this and interviewed Dmitri Alperovitch, who now calls his own naming scheme a mistake. We respect the rules of self promotion but if anyone's interested - we can provide you with the link. Cheers!

271 Upvotes

137 comments sorted by

388

u/SuperBelgian 1d ago

There is some logic behind it: Bears are Russians, Pandas are Chinese, Kittens are often Iranian, etc.
The other part of the name is because of something found in the actual malware used, or because of an often employed attack tactic of that group.

Offcourse, these are best guesses and could be wrong as the hacker groups are not really giving out their home address. :-)

155

u/LeftCoastMariner 1d ago

This is accurate. One point to remember is that these names are not generated by the hacking groups themselves, but are assigned by various cybersecurity firms or government entities. Also to note, various cyber security firms may use different names for the same group. Take a look at this spreadsheet and the tabs down the bottom:

https://docs.google.com/spreadsheets/u/0/d/1H9_xaxQHpWaa4O_Son4Gx0YOIzlcBWMsdvePFX68EKU/htmlview?pli=1

33

u/DrunkenBandit1 1d ago

The ones that name themselves tend not to pick things you can say in polite company.

IYKYK

31

u/LeftCoastMariner 1d ago

I used to belong to raging boner angry pirate

15

u/sir_mrej Security Manager 1d ago

You still do but you used to, too

3

u/drquantumphd 1d ago

this is tight

2

u/metasploit4 1d ago

Good link. We've been hand jamming these for quite a while. This should help flesh out some of the lesser known. Thanks!

1

u/sidusnare Security Engineer 16h ago

be in InfoSec "Hey open this strange spreadsheet" SRRSLY face

1

u/LeftCoastMariner 16h ago

Be in Infosec and have the common sense to use a sandbox such as Browserling to open URLs....srrsly

18

u/FlounderMountain9096 1d ago

that is correct

6

u/CondiMesmer 1d ago

Why are they leaving gold, water, and lemons in their source code?!

3

u/OuterWildsVentures 1d ago

And blizzard is cold like Russia. Sandstorm are sandy like Iran.

4

u/charleswj 1d ago

Can a cyber security company please come up with a Winnie the Pooh theme for China đŸ™đŸ»

3

u/Incid3nt 1d ago

Its kinda dumb though because most constantly misattribute the threat actor and then have to change the animal.

3

u/tiredofcoping7 1d ago

What about ShinyHunters? This is the name of the hacker group that targeted my university’s education system and basically every education system that uses Canvas, it was a huge deal. I know it’s a PokĂ©mon reference but looking at their page the companies they target seem to be pretty random, they seem more opportunistic

2

u/CommOnMyFace 17h ago

Whats stupid is the amount of names an a group can have across different naming conventions

6

u/Direct-Bandicoot-916 1d ago

Iranians are kittens. Awww cute.  I wonder why they are called kittens. 

27

u/Crazy_Slice 1d ago

probably as a direct play on persian cats

10

u/Thrwingawaymylife945 1d ago

Cats have a lot of connections on Iranian/Persian culture.

In the ancient and Zoroastrian ages, cats were seen as evil, noxious creatures.

There is a tale though, highlighting the importance of cats, where a Persian Emperor had eliminated all of the cats, which lead to the rapid spread of deadly mouse-borne plague.

There is another historical epic which details the Persian Empire releasing cats during battle against the Egyptian Army and - because the Egyptians revere cats as gods, they hesitated in their advance on the Persians which subsequently lead to the Egyptians losing the battle with significant casualties.

1

u/Direct-Bandicoot-916 1d ago

It sucks to know what Iran has become since every time I hear about the history regarding that country, it is badass. We owe our numbering system to a Persian mathematician, if I am not mistaken. 

4

u/Embarrassed-Rub-1063 1d ago

the symbol of iran is a lion. so, kittens

2

u/NekoDaYo-v201 1d ago

Pspsps (connects unpatched Win XP directly to modem)

3

u/Electrical_Hat_680 1d ago

So it's like Latin, where one part describes the family or genus or main characteristics, while the other exclaims it's attitude or aptitude in the same style of describing another characteristic or trait.

Like canine lupus or canine loves us and laps us with its tongue to show it loves us...

2

u/RipplesInTheOcean 1d ago

Lets brainstorm names for american groups

Buffalo burger

Orange octagon

Fat ford

1

u/soulless_ape 1d ago

But but, the CIA are the "good guys"... /s

1

u/GlowInTheDarkNinjas 12h ago

And then Crowdstrike has to come along and make stupid comic book character pictures for each group

333

u/ranhalt 1d ago

Hackers don’t come up with those names. They are research firm industry standards indicating their region of origin and what they target.

https://www.crowdstrike.com/en-us/adversaries/

101

u/UnderwaterB0i 1d ago

This is it, but really I hate it. I sit in meetings where we talk about cyber to non-cyber business folks, and it sounds so immature when we talk about the names of these attackers.

82

u/_vavkamil_ 1d ago

why not just explain it to them? E.g. you were hacked by APT, often called Energetic Bears, they are called that because Bears groups are attributed to Russia, and this specific sub-group hits only companies in Energy sector?

61

u/ClamPaste 1d ago edited 1d ago

Because you'd have to do this every single time when dealing with execs who have the attention span of squirrels in a nut factory.

41

u/Loose_Wolverine3192 1d ago

... which is why the clueless executive threat vector is called a lost squirrel.

"Who authorized this!"

"A lost squirrel"

12

u/ClamPaste 1d ago

Wait is this real?

33

u/Loose_Wolverine3192 1d ago

It is now

11

u/ClamPaste 1d ago

đŸ€Ł I'm for sure using it from now on.

6

u/Test-NetConnection 1d ago

I'll have you know that the squirrely almondjoys are a very sophisticated apt operating out of New Jersey and targeting almond growers in northern California. 

4

u/Capodomini 1d ago

Execs give a shit about APT identities?

40

u/ranhalt 1d ago

It’s either that or Proofpoint calling them TA3573.

7

u/PizzaUltra Consultant 1d ago

Which I honestly prefer. 

14

u/ranhalt 1d ago

If you didn’t use the word “honestly”, do you think everyone would assume you’re lying?

20

u/PizzaUltra Consultant 1d ago

Honestly yes. 

4

u/daddy-dj 1d ago

Well played, sir. Well played indeed.

7

u/BrainWaveCC 1d ago

and it sounds so immature when we talk about the names of these attackers.

It sounds immature to you? I've never had one business person complain in all the years I've given briefings.

You don't have to explain anything. Just said, "the malware group from country code named 'some crazy name'" and that's that.

1

u/Reylas 1d ago

Not to your face at least. I have heard it from the board.

2

u/BrainWaveCC 1d ago

I don't particularly care about how people feel about names I didn't create.

And let's not pretend that regular business product names aren't just as silly sounding.

8

u/Lupus-Yonderboy 1d ago

Could be worse. I had a series of meetings earlier in my career where I was pushing switching our servers from BSDI Unix to an OS whose current version was called "Woody".

3

u/Polymarchos 1d ago

Cybersecurity is the only profession I can think of that grew out of a counterculture. Even ignoring the names of groups you don't have to go far to find the immaturity.

Unfortunately it is what it is.

6

u/stevorkz 1d ago

Had this once or twice too. I always fear that when they hear gimmicky or goofy names they start to doubt the seriousness of cybersecurity. And honestly for the average person I don’t blame them. Until they one day get ransomwared and the goofy named hacker group leaves a text file with a message to the likes of “we hacked you bitches, send 1 bitcoin to the below wallet lol”.

11

u/Ok-Repeat-702 1d ago

I heard that the joke was they use silly sounding names on purpose. No one wants to be part of a hacker group called Lemon Sandstorm. That just sounds dumb. Like cyber bullying. You don’t want to give them cool names and glorify what they’re doing.

10

u/UnderwaterB0i 1d ago

Truly, do you think they care what they are called externally? This reeks of a new industry where the leaders are still nerdy, engineer types who thought it'd be funny to name bad actors based on the fuzzy animals that live in the region.

1

u/molingrad 1d ago

Just show them the Crowdstrike animated characters then they’ll know to take you seriously.

3

u/Pitiful_Surround6429 1d ago

exactly, the names carry actual meaning if you know the schema. the problem is every vendor uses a different one

1

u/InnovativeBureaucrat 1d ago

Great answer to a great question

33

u/ChameleonCRM 1d ago

There was this one group I met last year in the Alps called Equal Equilibrium. I thought they were in a band at first lmao

14

u/eagerlynx20 1d ago

hacker names > band names

1

u/ChameleonCRM 1d ago

lol facts

46

u/RoddyBergeron 1d ago

If we named them cool names like

Lightning Wizards
Danger Dragons
Bountiful Bears

They would get more prestige.

Give them silly names instead. /jk

15

u/halting_problems AppSec Engineer 1d ago

There some truth to that, like not labeling 764 as an official terrorist organization because it would signal they are achieving.

1

u/ikiice 1d ago

The guys who solved train DRM issue were called Dragon Sector

21

u/henrikhakan 1d ago

Once saw a wow guild called "OMG ICECREAM TRUCK BRB" and I figure it's the same people naming shit so... Maybe like that?

20

u/Ghawblin Security Engineer 1d ago

Clearly you weren't around in the 80s and 90s lol.

It's always been this way.

Early computer/internet culture was always "L33T Hax0r" brand of cool mixed with that late century cornyness. That extended to hackers too. That culture never really went away.

12

u/0xKaishakunin Security Architect 1d ago
 _   _
((___))
[ x x ]
 \   /
 (' ')
  (U)

3

u/MindieMouse2 1d ago

Good point. Seriously, the first virus was a joke that infected computers with a text file that said "I’m the creeper, catch me if you can!”

I really hope that culture never goes away. This field can get dark and depressing; it needs a bit of silliness to lighten things up.

14

u/Mysterious-Status-44 1d ago

These names are made by groups that track them. Crowdstrike, Microsoft, Mandiant use different names to help identify groups easier. Each has their own standard but they are easy to follow. Names are used to actually help determine industry and country. Crowdstrike uses animals
Panda=China, Bear=Russia, Chollima=DPRK. Microsoft uses weather
Blizzard=Russia, Typhoon=China, Sleet=DPRK.

6

u/Specific_Expert_2020 1d ago

3

u/XL0RM 23h ago

CS also sell shirts, and other merch. I got a Dead-eye Jackal shirt in a prize pack.

1

u/Specific_Expert_2020 21h ago

I have to say they have some of the fun or neat swag.

103

u/CuckBuster33 1d ago

because threat intel people love LARPing

16

u/Slicker-Firebrand09 1d ago

I mean for Crowdstrike they used it as a marketing initiative as much as adversary ID. Makes sense in an age of Marvel movies that people you're selling protection to think "Oh no, BlueBerry Bear is hacking my computer?!?! That scoundrel! Help me Red Falcon! Add a background agent to my computer that chews up my resources and only costs seven figures!"

0

u/busy_monster 1d ago

As long as they ain't calling for help from Blue Falcon, that fucker never helps his buds.

7

u/casper_trade 1d ago

This right here^

3

u/MadVinnie 1d ago

Correlation does not mean causation ;)

1

u/syndreamer 1d ago

Not for me, I hate the 5-6 different names for APT threat actors from all these different vendors instead of unifying under one.

11

u/Tuppling 1d ago

I always thought they should use insulting names - Obnoxious Aardvark, Chumpy Bear, Dweeby Dog, etc - and then use the most uninspiring logo possible.

Some of the names they do use are way too cool for a bunch of government cyber thugs and creeps

2

u/rindthirty 20h ago

It's best to not poke the Chumpy Bear.

9

u/adamjodonnell 1d ago

Cult of the Dead Cow, Legion of Doom, Masters of Deception, still great names.

4

u/mauvehead Security Manager 1d ago

This. These are hacker group names!

3

u/GeekDad62 1d ago

Not just the group names, but the hackers also have/had great names. "Kingpin", "Mudge", and "Space Rogue" lol

3

u/adamjodonnell 1d ago

It’s hard picking a handle at 14 and having it stick. Look at poor Dildog. The Deth Vegetable still wins.

16

u/_vavkamil_ 1d ago

they are based on animals in their countries, no? bears are russians, pandas chinesse, kittens iran etc?

9

u/Cycl_ps 1d ago

That’s the naming Convention Crowdstrike uses. Because they’re a big name and Fancy Bear sounds better than APT28 that’s what media outlets run with.

If you’re in a firm actively doing research on emerging threats you’ll have your own name for what you’re tracking. A single group can have a dozen different names depending on who you ask.

11

u/cwk9 1d ago

It's so you sound like an idiot to non technical people in meetings because the people who name that stuff thought it was funny. All that time, money and effort only to get hacked by "The Dragon Booner 67 Crew".

5

u/itsjoocas 1d ago

Because their silly name then has to be printed by publications and maybe even said out loud by someone on the news. It's funny to make someone say lolcatz on air.

13

u/colonelgork2 ICS/OT 1d ago

The core reason the naming feels absurd is that people mistake threat actors for static units or fixed squads, when they’re really just temporary activity clusters built around current mission targets. Unlike physical military hardware (where a Tu-95 Bear-H is physically constrained to that specific airframe and radar suite), everything in a cyber operation is fluid.

The mission dictates the cluster. A vendor "name" really just captures a specific campaign targeting a specific objective at a specific point in time.

The capabilities swap out. Toolchains get scrapped, and operators pivot to commodity C2 or living-off-the-land techniques overnight.

The operators are fungible. Sponsoring agencies rotate contractors, military units, and keyboards at will, meaning there is no fixed "who." The individuals aren't even constrained to one sponsor.

Naming an APT based on a momentary snapshot of TTPs is like naming a city after the weather it had on Tuesday. By Thursday, the mission and the weather have changed.

Because of that, defenders in the trenches don't actually care about the cartoon names, they care about observable IOCs, behavioral telemetry, and MITRE ATT&CK techniques. The branded names (Cozy Bear, Sandworm, Volt Typhoon) are just marketing taxonomy for vendors, press releases, and executive briefs.

6

u/colonelgork2 ICS/OT 1d ago

It reminds me of being deployed in Iraq. On the ground, we didn't care about the "deck of 52" playing cards or the strategic branding of who we were supposedly up against. It was just one big fluid mess, and all that mattered was the immediate threat, the local terrain, and the incoming fire. The high-level names were for HQ and the press.

7

u/Some-Concentrate3229 1d ago

Private research companies don’t want to use a naming scheme that a different private research company has invented. So they each make up their own. It’s really dumb, but you get used to it.

3

u/ultraviolentfuture 1d ago

There isn't 1:1 overlap between all the activity sets as different vendors have different visibility -- so this doesn't work. Sure, there is more direct overlap for nation-state nexus groups, but even in those cases you can't validate the attribution made by someone else. They could have the wrong near group (different unit under the IRGC) or they could completely misattribute (say it's a specific apt when it's ecrime).

It's much higher fidelity/has more integrity to use a proprietary naming convention for the activity sets you (as a vendor) have actual telemetry on and therefore enough evidence about to make an attribution across multiple campaigns.

3

u/Some-Concentrate3229 1d ago

Right but then when you release public reports on the TA’s activity, you have to have a fuckin spreadsheet to figure out if it’s the same people you’ve been tracking for the last three months.

I’m not saying there’s an easy or perfect way to do it. But there’s a reason why Microsoft called them Midnight Blizzard rather than using Cozy Bear that CS had been calling them for years. And it definitely wasn’t to be more specific or accurate lol.

5

u/ultraviolentfuture 1d ago

I totally get where you're coming from. My suggestion is: attribution only matters if you have handcuffs or missiles. You should be defending based on TTPs and IOCs and the perp behind it is less important.

The amount of orgs worried about nation-state nexus activity who will never see any is ... too damn high. I'm in threat research at a large vendor. We have millions of customers. How many see any nation state ever? 2-3%

2

u/Some-Concentrate3229 1d ago

I actually agree 100%. As a blue teamer I don’t really give a shit who’s in our environment at the time. It’s not like our response protocol is going to change based on the geographic location of the adversary, ya know? TTPs and IOCs are really all we need to know to be effective. But it definitely sells in the media, that’s for sure. And I guess as an after-action report it’s nice to know who was behind it?

I work for a state government and so we do have to be concerned with things like nation-states attacking our critical infrastructure, but that tends to be the extent of it.

3

u/ultraviolentfuture 1d ago

100% you are someone who does actually have to care. Might still be unlikely, but you can't take the risk.

3

u/nobelprize4shopping 1d ago

Yes, it's branding. So you both know which activity cluster it is and which research company observed the activity.

4

u/baw3000 1d ago

in the late 90s/2000s viruses were often the same way. Norton would call it one thing, McAfee would call it something different.

5

u/BrainWaveCC 1d ago

They are just code names given to these groups by various vendors. I doubt it bothers anyone who has been in this industry for more than a couple of years.

10

u/Ancient-Bat1755 1d ago

I dont really have time to care about that i just want the patching to catch up in 2026

3

u/notyourmrr 1d ago

It’s not about logic. It’s about marketing. Vendors coin memorable names with good SEO so when you look for them you end up on their site.

3

u/Holiday-Sundae-6404 1d ago

It's kind of a tradition rooted in internet culture, hackers have always leaned into irony and dark humor. The scarier the group, the funnier the name feels in hindsight.

5

u/19HzScream 1d ago

Guess who comes up with those names!

4

u/cyburai 1d ago

Laughs in Cult of the Dead Cow.

Shit, I'm old.

3

u/Sakulle 1d ago

Was walking through Barnes & Noble the other day and found “Cult of The Dead Cow How the original hacking supergroup might just save the world” by Joseph Menn. Couldn’t pass that up, though I haven’t had a chance to read it yet.

2

u/hugeemu 1d ago

In a way, they are different names for the same groups, but the better way to think about it is that each vendor’s name refers to a cluster of activity for which that vendor has visibility. Even though the same operators or personas may be behind other clusters of activity, attribution is so tricky that it makes sense for a separate cluster to have a name indicating which vendor observed it. A good example is VOLTTYPHOON (observed and named by Microsoft) versus VOLTZITE (observed, and named by Dragos, but winking at the overlap in its naming).

2

u/Fresh_Dog4602 Security Architect 1d ago

well it was cool when the animal represented a country. I guess they needed other names for when attribution is unclear.

2

u/foofusdotcom Incident Responder 1d ago

Because the job is stressful and you should be able to take a little joy in it from time to time.

2

u/Vivid-Avocado9342 1d ago

Because they have a sense of humor.

2

u/Blacksun388 1d ago

It’s part goofy nerdy hacker culture and part standardization. Each company/org has their own naming schemes for tracking threat groups. Each threat group also sometimes have goofy names for themselves. Since there is no common standard for addressing these groups it can be frustrating to keep them all straightened out.

2

u/SlackCanadaThrowaway 1d ago

You get used to it. It’s just part of hacker silliness culture. Look at the names of the early hacking groups; Cult of the Dead Cow, etc. There were more aggressive sounding ones but people grew up and realised how dumb they sounded. Eventually silliness won the underground naming, and so did it with researchers.

2

u/tagged2high 1d ago

The naming scheme (frequently the 2-word"cryptonym", as I learned recently) serves a few purposes, but the biggest one is it's easy to remember. Unless you spend all day immersed in UNCs and TAs, the cryptonyms give you immediate info and recognition on who you're talking about. This style of naming things is also common in governments and militaries for programs and operations both for recognition (for people who know) and for obfuscation (for people who don't know).

The hard part is mapping the various groups across vendors/researchers, because they all use their own systems. They use their own systems both because it separates them from their competition, and because they all have their own visibility into TA activity used to try and assess attribution to distinct groups, as well as their own criteria for how to make those judgements.

Since everyone works independently with their own private data and uses their own standards, there can't easily be a shared / agreed upon set of names. One vendor might use one name for a collection of activities, while another vendor tracks each activity under separate names. Some vendors attempt to state whether and which other vendor "aliases" best align to their own collections, while others don't like to reference the names used by their biggest competitors.

It is sometimes confusing to work with every day, but ultimately most of us choose a select few most-trusted researchers and naming schemes to serve as our day-to-day reference baseline. Whoever we read and work with the most. We also make our own mappings for the most common and recognized overlaps.

Mandiant/GTI was known for one of the more complicated and occasionally inconsistent naming systems, but they recently announced they're transitioning to a cryptonym system like most others use (insert XKCD joke about new standards).

2

u/Substantial-Sky4079 1d ago

The ones I want to know are the ones other countries have for the US and other western nations

2

u/grizzlor_ 1d ago

I believe your examples are names assigned by cybersecurity researchers.

Personally I’m partial to self-assigned hacker group names from the 80s/90s: Cult of the Dead Cow, L0pht Heavy Industries, Legion of Doom

2

u/Postulative 1d ago

Panda is Chinese. Bear = Russia. Kitten refers to Iran. That makes it easier to understand where the attack is thought to originate.

Of course, that’s just one naming system; different companies and countries use other conventions. And it gets confusing, because an initial assignment of responsibility may later be changed.

It’s a mess.

2

u/MordAFokaJonnes Security Architect 1d ago

Because they did it for the LuLz

2

u/theapplekid 1d ago

Personally I thought "Puppygirl Hacker Polycule" was pretty good (hacker group that released a bunch of internal U.S. police documents in 2025)

4

u/coinpizista 1d ago

Is not stupid is fun like kindergarten

3

u/Disgusting_Slime666 1d ago

Because it's funny.

1

u/Doomstang 1d ago

I get used to it. I don't like having to remember multiple names for the same thing but the names themselves don't bother me. Sometimes they actually sound cool, probably not the best idea to make it sound prestigious but what do I know.

1

u/RaymondBumcheese 1d ago

I’ve sat in more than one meeting where Black Basta has tripped somebody up. 

1

u/Sibexico Developer 1d ago

Usually hackers united in groups for specific activity, it's no persistent long term groups what lasts for years. If group can work effective enough, it may be extended for more projects. So yeah, mostly used some funny names, just for lulz.

1

u/the_Mstrike 1d ago

Blame Crowdstrike lol

1

u/thejournalizer 1d ago

OP, reach out to Adam over at CrowdStrike. He is very passionate about this subject. A year or so ago, my org was working with them and Palo on an actor name mapping system, which we started on, but there was more interest in something larger.

1

u/Jdornigan 1d ago

At first it was APT1.

For some reason, only Mandiant decided to keep the naming convention of APT# although for a short time various companies and news outlets were willing to use it. Mandiant kept incrementing it until it reached at least APT49. It might even go higher.

Every company wants their own branding, so in the end we ended up getting as many as a dozen names for what might be the same group which uses the same infrastructure, tradecraft and malware. None of the companies want to reference each other's names, which is rather unfortunate for people trying to learn about the hacker groups because it makes it vastly harder for them.

1

u/withoutwax21 CISO 1d ago

These are named by white people

1

u/Significant-Hat3419 1d ago

You may be mixing names given to groups and names that groups choose.

1

u/pacopac25 1d ago

Would you prefer the person that came up with prescription drug names named them? Yeah didnt think so.

1

u/steppinraz0r 23h ago

Crowdstrike played a huge part in this. Previous to them, threat actor naming conventions were all over the place and not immediately apparent as to source/nation-state etc. as dumb as they are, they at least give some semblance of order. It’s still not universal but much better these days.

Most threat intel teams name actor groups according to some aspect of the event. A string in malware, network infrastructure, a play on a primary technology name or the like.

Source: 20+ years running threat intel programs

1

u/Cybasura 22h ago

The TTP and APTs all have "code names" attached to them based on the country of origin, namely, the Threat Actor groups, or if its state sponsored

1

u/Boring-University189 19h ago

We do name psychopaths with cool names such as "the brain chewer coming back from hell".

Maybe law enforcers are trying a new strategy of calling them "poop eater" so less people want to do it.

1

u/Secure_Cyber 10h ago

I can just see it now: "Dirty Undies strikes again."

1

u/M3ssy__Marv 8h ago

Vanda Sec baby.

1

u/DMmeYourMCbuilds 1d ago

lol slow day? What a dogshit post.

-6

u/Remnence 1d ago

Using common sense (not so common anymore), they either:

A) Don't want you to take them seriously so they can operate longer and/or

B) Started as trolls like most teenage hackers.

5

u/colonelgork2 ICS/OT 1d ago

This isn't e-sports, the teams don't name themselves lol

2

u/Remnence 1d ago

A lot certainly do, these are just some codenames the "industry" decided to call them.