/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft starts naming threat actor groups after weather events, like typhoon, sandstorm, and blizzard; each name represents a nation state or a motivation

Microsoft has started naming hackers after the weather in a new naming taxonomy update.  Hackers will now be named after events like storms …

The Verge Tom Warren

Context & Ripple Effects

Microsoft's threat-intelligence operation already tracked dozens of state-sponsored groups, including many without public labels, making a durable taxonomy important for how its findings are communicated. The new system quickly drew criticism that vendor-specific labels can hinder cross-source analysis, as argued in a critique of competing hacker-name systems.

The issue persisted beyond this rollout: Microsoft later used weather-style labels in reporting on groups including Flax Typhoon, while Microsoft, Google, CrowdStrike, and Palo Alto Networks later moved toward a public glossary for state-sponsored groups.

First-order effects

  • Microsoft's security reporting and customer-facing threat intelligence gain a consistent set of weather-based identifiers, with the names also signaling the actor's state affiliation or motivation.
  • Security teams consuming Microsoft's research must map the new labels to the aliases already used in their own tools, incident records, and external reporting.

Second-order effects

  • Other security vendors and intelligence-sharing partners face added pressure to publish alias mappings so customers can connect Microsoft's assessments with their existing detections and cases.
  • The naming change makes the cost of fragmented attribution more visible: a single actor can be described differently across vendor reports, complicating analyst handoffs and searches.

Third-order effects

  • If major vendors align on shared aliases and mappings, threat attribution can become more interoperable across commercial intelligence feeds; without that alignment, branding-led taxonomies can deepen fragmentation.
  • The later push for a public glossary suggests the market is moving from proprietary naming conventions toward common reference layers for state-sponsored activity.

The trend: Threat intelligence is shifting from vendor-specific actor branding toward shared identity and alias standards that make cross-provider analysis more usable.

Discussion

  • @thetomzone Tom Mckay on x
    this actually sounds really hard to remember? who thought of using synonyms for this? https://www.microsoft.com/... https://twitter.com/...
  • @msftsecintel @msftsecintel on x
    To ease the transition to the new naming taxonomy, we published a JSON file mapping old threat actor names with their new names: https://aka.ms/... We also updated the blog with KQL queries to further help in this transition: https://aka.ms/... https://twitter.com/...
  • @arawnsley Adam Rawnsley on x
    “I caught a blizzard type Pokémon, er, threat actor” https://twitter.com/...
  • @a_greenberg Andy Greenberg on x
    Thanks Microsoft https://learn.microsoft.com/ ... https://twitter.com/...
  • @silascutler Silas on x
    Lets break this down. Yes, it's a pain to track the 10 names for every group, but it's important and I'll break it down. For general consumers, multiple actor names get confusing. The model of tracking clusters of activity or adversaries is a old intelligence practice. 🧵1/5 https…