financetom
Business
financetom
/
Business
/
'Forest Blizzard' vs 'Fancy Bear' - cyber companies hope to untangle weird hacker nicknames
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
'Forest Blizzard' vs 'Fancy Bear' - cyber companies hope to untangle weird hacker nicknames
Jun 2, 2025 9:48 AM

WASHINGTON (Reuters) -Microsoft, CrowdStrike, Palo Alto and Alphabet's Google on Monday said they would create a public glossary of state-sponsored hacking groups and cybercriminals, in a bid to ease confusion over the menagerie of unofficial nicknames for them.

Microsoft and CrowdStrike said they hoped to potentially bring other industry partners and the U.S. government into the effort to identify Who's Who in the murky world of digital espionage.

"We do believe this will accelerate our collective response and collective defense against these threat actors," said Vasu Jakkal, corporate vice president, Microsoft Security.

How meaningful the effort ends up being remains to be seen.

Cybersecurity companies have long assigned coded names to hacking groups, as attributing hackers to a country or an organization can be difficult and researchers need a way to describe who they are up against. 

Some names are dry and functional, like the "APT1" hacking group exposed by cybersecurity firm Mandiant or the "TA453" group tracked by Proofpoint. Others have more color and mystery, like the "Earth Lamia" group tracked by TrendMicro or the "Equation Group" uncovered by Kaspersky. 

Crowdstrike's evocative nicknames - "Cozy Bear" for a set of Russian hackers, or "Kryptonite Panda" for a set of Chinese ones - have tended to be the most popular, and others have also adopted the same kind of offbeat monikers. 

In 2016, for example, the company Secureworks - now owned by Sophos - began using the name "Iron Twilight" for the Russian hackers it previously tracked as "TG-4127." Microsoft itself recently revamped its nicknames, moving away from staid, element-themed ones like "Rubidium" to weather-themed ones like "Lemon Sandstorm" or "Sangria Tempest."

But the explosion of whimsical aliases has already led to overload. When the U.S. government issued a report about hacking attempts against the 2016 election, it sparked confusion by including 48 separate nicknames attributed to a grab bag of Russian hacking groups and malicious programs, including "Sofacy," "Pawn Storm," "CHOPSTICK," "Tsar Team," and "OnionDuke."

Michael Sikorski, the chief technology officer for Palo Alto's threat intelligence unit, said the initiative was a "game-changer."  

"Disparate naming conventions for the same threat actors create confusion at the exact moment defenders need clarity," he said. 

Juan-Andres Guerrero-Saade, a top researcher at the cybersecurity firm SentinelOne, was skeptical of the effort, saying the cold reality of the cybersecurity industry was that companies hoarded information. 

Unless that changed, he said, "this is branding-marketing-fairy dust sprinkled on top of business realities."

But CrowdStrike Senior Vice President of counter adversary operations, Adam Meyers, said the move had already delivered a win by helping his analysts connect a group Microsoft called "Salt Typhoon" with one CrowdStrike dubbed "Operator Panda."

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Lufthansa to consider raising stake in ITA to 90%, CEO says
Lufthansa to consider raising stake in ITA to 90%, CEO says
Jul 3, 2024
ROME (Reuters) - Lufthansa will consider raising its stake in Italy's ITA Airways to 90%, starting from early next year, the CEO of the German airline said in an interview published on Thursday. Carsten Spohr was speaking after his company won EU antitrust approval to buy 41% of state-owned ITA for 325 million euros ($350 million). For us, the option...
Norwegian Air lowers 2024 profit forecast
Norwegian Air lowers 2024 profit forecast
Jul 3, 2024
COPENHAGEN, July 4 (Reuters) - Norwegian Air on Thursday lowered its operating profit forecast for 2024 to between 2.1 billion and 2.6 billion crowns ($199.07 million - 246.47 million), citing lower-than-expected traffic demand in the second quarter, among other factors. A higher than projected wage settlement for pilots after new collective bargaining agreements, as well as aircraft delivery delays from...
How Raiffeisen's bet on Russia took it to the brink
How Raiffeisen's bet on Russia took it to the brink
Jul 3, 2024
VIENNA (Reuters) - For more than four months, U.S. envoys delivered increasingly shrill warnings to Austria's Raiffeisen Bank International to scrap a deal they said had links to one of Russia's most powerful oligarchs. In May, Washington's patience snapped. In a written ultimatum that landed on May 8 at the bank, its supervisor the European Central Bank and Austria's government,...
Analysis-EU's airline deal demands fuel doubts over further attempts
Analysis-EU's airline deal demands fuel doubts over further attempts
Jul 3, 2024
LONDON (Reuters) - It took a year of wrangling with the European Commission for Germany's Lufthansa to gain approval to buy 41% of Italy's ITA Airways, and only after it accepted big concessions. While the deal expands Lufthansa's footprint in the lucrative southern European market, the combined group will have to cede some routes and slots to rivals for it...
Copyright 2023-2026 - www.financetom.com All Rights Reserved