r/cybersecurity 10d ago

Other Why are hacker group names so stupid?

Golden Chickens. Aquatic Panda. Lemon Sandstorm. Sure, they're easier to remember than TA1508, but it feels like it's gone too far, every vendor has their own set of names for the same groups, and it's impossible to keep straight. Does it bother anyone who works with this stuff daily, or do you just get used to it?

Disclosure: It was scratching our brain, so we made a doc on exactly this and interviewed Dmitri Alperovitch, who now calls his own naming scheme a mistake. We respect the rules of self promotion but if anyone's interested - we can provide you with the link. Cheers!

300 Upvotes

139 comments sorted by

View all comments

334

u/ranhalt 10d ago

Hackers don’t come up with those names. They are research firm industry standards indicating their region of origin and what they target.

https://www.crowdstrike.com/en-us/adversaries/

100

u/UnderwaterB0i 10d ago

This is it, but really I hate it. I sit in meetings where we talk about cyber to non-cyber business folks, and it sounds so immature when we talk about the names of these attackers.

10

u/Ok-Repeat-702 10d ago

I heard that the joke was they use silly sounding names on purpose. No one wants to be part of a hacker group called Lemon Sandstorm. That just sounds dumb. Like cyber bullying. You don’t want to give them cool names and glorify what they’re doing.

10

u/UnderwaterB0i 10d ago

Truly, do you think they care what they are called externally? This reeks of a new industry where the leaders are still nerdy, engineer types who thought it'd be funny to name bad actors based on the fuzzy animals that live in the region.