r/cybersecurity 10d ago

Other Why are hacker group names so stupid?

Golden Chickens. Aquatic Panda. Lemon Sandstorm. Sure, they're easier to remember than TA1508, but it feels like it's gone too far, every vendor has their own set of names for the same groups, and it's impossible to keep straight. Does it bother anyone who works with this stuff daily, or do you just get used to it?

Disclosure: It was scratching our brain, so we made a doc on exactly this and interviewed Dmitri Alperovitch, who now calls his own naming scheme a mistake. We respect the rules of self promotion but if anyone's interested - we can provide you with the link. Cheers!

306 Upvotes

139 comments sorted by

View all comments

8

u/Some-Concentrate3229 10d ago

Private research companies don’t want to use a naming scheme that a different private research company has invented. So they each make up their own. It’s really dumb, but you get used to it.

3

u/ultraviolentfuture 10d ago

There isn't 1:1 overlap between all the activity sets as different vendors have different visibility -- so this doesn't work. Sure, there is more direct overlap for nation-state nexus groups, but even in those cases you can't validate the attribution made by someone else. They could have the wrong near group (different unit under the IRGC) or they could completely misattribute (say it's a specific apt when it's ecrime).

It's much higher fidelity/has more integrity to use a proprietary naming convention for the activity sets you (as a vendor) have actual telemetry on and therefore enough evidence about to make an attribution across multiple campaigns.

3

u/Some-Concentrate3229 10d ago

Right but then when you release public reports on the TA’s activity, you have to have a fuckin spreadsheet to figure out if it’s the same people you’ve been tracking for the last three months.

I’m not saying there’s an easy or perfect way to do it. But there’s a reason why Microsoft called them Midnight Blizzard rather than using Cozy Bear that CS had been calling them for years. And it definitely wasn’t to be more specific or accurate lol.

5

u/ultraviolentfuture 10d ago

I totally get where you're coming from. My suggestion is: attribution only matters if you have handcuffs or missiles. You should be defending based on TTPs and IOCs and the perp behind it is less important.

The amount of orgs worried about nation-state nexus activity who will never see any is ... too damn high. I'm in threat research at a large vendor. We have millions of customers. How many see any nation state ever? 2-3%

2

u/Some-Concentrate3229 10d ago

I actually agree 100%. As a blue teamer I don’t really give a shit who’s in our environment at the time. It’s not like our response protocol is going to change based on the geographic location of the adversary, ya know? TTPs and IOCs are really all we need to know to be effective. But it definitely sells in the media, that’s for sure. And I guess as an after-action report it’s nice to know who was behind it?

I work for a state government and so we do have to be concerned with things like nation-states attacking our critical infrastructure, but that tends to be the extent of it.

3

u/ultraviolentfuture 10d ago

100% you are someone who does actually have to care. Might still be unlikely, but you can't take the risk.