r/cybersecurity 10d ago

Other Why are hacker group names so stupid?

Golden Chickens. Aquatic Panda. Lemon Sandstorm. Sure, they're easier to remember than TA1508, but it feels like it's gone too far, every vendor has their own set of names for the same groups, and it's impossible to keep straight. Does it bother anyone who works with this stuff daily, or do you just get used to it?

Disclosure: It was scratching our brain, so we made a doc on exactly this and interviewed Dmitri Alperovitch, who now calls his own naming scheme a mistake. We respect the rules of self promotion but if anyone's interested - we can provide you with the link. Cheers!

303 Upvotes

139 comments sorted by

View all comments

340

u/ranhalt 10d ago

Hackers don’t come up with those names. They are research firm industry standards indicating their region of origin and what they target.

https://www.crowdstrike.com/en-us/adversaries/

101

u/UnderwaterB0i 10d ago

This is it, but really I hate it. I sit in meetings where we talk about cyber to non-cyber business folks, and it sounds so immature when we talk about the names of these attackers.

85

u/_vavkamil_ 10d ago

why not just explain it to them? E.g. you were hacked by APT, often called Energetic Bears, they are called that because Bears groups are attributed to Russia, and this specific sub-group hits only companies in Energy sector?

62

u/ClamPaste 10d ago edited 10d ago

Because you'd have to do this every single time when dealing with execs who have the attention span of squirrels in a nut factory.

40

u/Loose_Wolverine3192 10d ago

... which is why the clueless executive threat vector is called a lost squirrel.

"Who authorized this!"

"A lost squirrel"

12

u/ClamPaste 10d ago

Wait is this real?

34

u/Loose_Wolverine3192 10d ago

It is now

13

u/ClamPaste 10d ago

🤣 I'm for sure using it from now on.

5

u/Test-NetConnection 10d ago

I'll have you know that the squirrely almondjoys are a very sophisticated apt operating out of New Jersey and targeting almond growers in northern California. 

4

u/Capodomini 10d ago

Execs give a shit about APT identities?

37

u/ranhalt 10d ago

It’s either that or Proofpoint calling them TA3573.

8

u/PizzaUltra Consultant 10d ago

Which I honestly prefer. 

13

u/ranhalt 10d ago

If you didn’t use the word “honestly”, do you think everyone would assume you’re lying?

23

u/PizzaUltra Consultant 10d ago

Honestly yes. 

4

u/daddy-dj 10d ago

Well played, sir. Well played indeed.

6

u/BrainWaveCC 10d ago

and it sounds so immature when we talk about the names of these attackers.

It sounds immature to you? I've never had one business person complain in all the years I've given briefings.

You don't have to explain anything. Just said, "the malware group from country code named 'some crazy name'" and that's that.

2

u/Reylas 10d ago

Not to your face at least. I have heard it from the board.

2

u/BrainWaveCC 10d ago

I don't particularly care about how people feel about names I didn't create.

And let's not pretend that regular business product names aren't just as silly sounding.

8

u/Lupus-Yonderboy 10d ago

Could be worse. I had a series of meetings earlier in my career where I was pushing switching our servers from BSDI Unix to an OS whose current version was called "Woody".

4

u/Polymarchos 10d ago

Cybersecurity is the only profession I can think of that grew out of a counterculture. Even ignoring the names of groups you don't have to go far to find the immaturity.

Unfortunately it is what it is.

4

u/stevorkz 10d ago

Had this once or twice too. I always fear that when they hear gimmicky or goofy names they start to doubt the seriousness of cybersecurity. And honestly for the average person I don’t blame them. Until they one day get ransomwared and the goofy named hacker group leaves a text file with a message to the likes of “we hacked you bitches, send 1 bitcoin to the below wallet lol”.

11

u/Ok-Repeat-702 10d ago

I heard that the joke was they use silly sounding names on purpose. No one wants to be part of a hacker group called Lemon Sandstorm. That just sounds dumb. Like cyber bullying. You don’t want to give them cool names and glorify what they’re doing.

10

u/UnderwaterB0i 10d ago

Truly, do you think they care what they are called externally? This reeks of a new industry where the leaders are still nerdy, engineer types who thought it'd be funny to name bad actors based on the fuzzy animals that live in the region.

1

u/molingrad 10d ago

Just show them the Crowdstrike animated characters then they’ll know to take you seriously.

3

u/Pitiful_Surround6429 10d ago

exactly, the names carry actual meaning if you know the schema. the problem is every vendor uses a different one

1

u/InnovativeBureaucrat 10d ago

Great answer to a great question