/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Hacker group naming schemes, such as Microsoft's new system, are counterproductive for cybersecurity analysis; a government body should set a naming convention

Pumpkin Sandstorm.  Spandex TempestCharming Kitten.  Is this really how we want to name the hackers wreaking havoc worldwide?

Wired Andy Greenberg

Context & Ripple Effects

Days before this critique ran, Microsoft rolled out its weather-themed actor names — typhoons for nation-state groups, sandstorms for others — adding yet another proprietary vocabulary on top of CrowdStrike's animals and everyone else's cats and kittens. The argument lands on a problem with a long paper trail: naming viruses and vulnerabilities has been contested since at least 2018, when thousands of new discoveries a year made standout labels both a branding tool and an analytic liability.

The stakes are not cosmetic. In 2018, researchers only discovered that many 'independent' groups were one operation after opsec slips let them merge a decade of activity under the Winnti Umbrella label — proof that fragmented naming actively hides aggregation. And Washington has tried codifying cyber language before, with the Cyber Incident Severity Schema announced in 2016 but left short on specifics.

First-order effects

  • Analysts correlating reports from Microsoft, CrowdStrike, Google, and Palo Alto Networks must manually reconcile aliases for the same group — Spandex Tempest and Charming Kitten exist because each vendor mints its own name for overlapping activity.
  • Microsoft's scheme makes its own threat intelligence harder to cross-reference against rival trackers, raising the cost of using any single vendor's reporting as ground truth.

Second-order effects

  • Vendor coordination becomes the pressure-release valve: by mid-2025 Microsoft, Google, CrowdStrike, and Palo Alto Networks moved to publish a shared public glossary of state-sponsored groups, effectively conceding that alias proliferation was hurting the whole sector.
  • A credible government convention would shift competitive dynamics in threat intel from who coins the catchiest name to whose detections map fastest onto the official registry.

Third-order effects

  • If a state body standardizes actor naming the way the 2016 severity schema attempted for incident levels, attribution itself becomes more auditable — merged clusters like Winnti Umbrella would surface sooner, and vendor-branded taxonomies risk becoming secondary metadata rather than primary identifiers.
  • The unresolved question is whether governments move faster than vendors' voluntary glossary effort; the 2016 schema shows federal codification can stall on specifics while industry fills the vacuum on its own terms.

The trend: Threat intelligence is drifting from competing vendor-branded naming schemes toward shared registries, with pressure mounting for an official body to arbitrate the taxonomy vendors cannot settle among themselves.

Discussion

  • @zachsdorfman Zach Dorfman on x
    I'm thrilled that someone finally wrote this article, and that it was @a_greenberg. The system is facile and confusing! https://twitter.com/...
  • @wired @wired on x
    Cute pet names like Fancy Bear, Refined Kitten, and Sea Turtle belie the havoc these hacker groups wreak across the world. https://www.wired.com/...
  • @vessonsecurity Vess on x
    As one of the creators of the CARO malware naming scheme, I am one of those who tried to put some order in the malware naming. Spoiler: We failed miserably. Prediction: Trying to do it for the APTs will similarly fail. https://twitter.com/...
  • @erratarob @erratarob on x
    Yes. We need to disambiguate who we are talking about. Numbers are problematic, like ATP1234, because it might easily get confused with APT2134. Which names we choose doesn't matter so much as we have unambiguous names. https://twitter.com/...
  • @howelloneill Patrick Howell O'Neill on x
    All this is true, it's absurd. On top of that, whatever the original reasoning, the systems solve no problems and add unnecessary complexity. if you're gonna get weird, go full hog and create life size threat actor anime robots. Thank you for your service, Crowdstrike. https://tw…
  • @crispinburke Crispin Burke on x
    The hacking organization run by Unit 74455 of Russia's GRU is referred to by the following names: - Voodoo Bear - Sandworm - Iridium - Seashell Blizzard (among others) https://www.wired.com/...
  • @cyb3rops Florian Roth on x
    🥴"[we] dream of a day when a gov body comes up with hacker group naming convention" and „analysts at different companies will never be sure they're looking at the same entities" 1. the dream would be a TI nightmare 2. even if they shared all data, they could still disagree https:…