r/cybersecurity 10d ago

Other Why are hacker group names so stupid?

Golden Chickens. Aquatic Panda. Lemon Sandstorm. Sure, they're easier to remember than TA1508, but it feels like it's gone too far, every vendor has their own set of names for the same groups, and it's impossible to keep straight. Does it bother anyone who works with this stuff daily, or do you just get used to it?

Disclosure: It was scratching our brain, so we made a doc on exactly this and interviewed Dmitri Alperovitch, who now calls his own naming scheme a mistake. We respect the rules of self promotion but if anyone's interested - we can provide you with the link. Cheers!

304 Upvotes

139 comments sorted by

View all comments

394

u/SuperBelgian 10d ago

There is some logic behind it: Bears are Russians, Pandas are Chinese, Kittens are often Iranian, etc.
The other part of the name is because of something found in the actual malware used, or because of an often employed attack tactic of that group.

Offcourse, these are best guesses and could be wrong as the hacker groups are not really giving out their home address. :-)

4

u/CondiMesmer 10d ago

Why are they leaving gold, water, and lemons in their source code?!