Photo by cliff1126
Picture this: you wake up to breaking news that a major healthcare network has been crippled, critical government secrets have been siphoned, and millions of dollars have vanished. The ruthless mastermind behind this digital devastation? A group known as… Charming Kitten.
Welcome to the Threat Actor Naming Paradox.
If you read the headlines, you might think the world’s most dangerous digital syndicates are actually a line of plush toys or cast members from a fantasy RPG. But beneath these cuddly monikers are elite military intelligence units and ruthless cybercrime cartels. Here is the amusing—and deeply ironic—truth about how the cybersecurity industry names its worst enemies.
Table of contents
Open Table of contents
The Ironic Truth of “Cuddly” Cyber Threats
In threat intelligence, the most ruthless nation-state hackers and ransomware cartels are frequently assigned names that sound like stuffed animals or D&D characters. The cuter the mascot, often the more sophisticated the threat.
| Group | Origin | The “Innocent” Reality |
|---|---|---|
| Fancy & Cozy Bear | Russia | Elite military intelligence (APT28/APT29). Behind 2016 DNC hacks and the SolarWinds supply chain attack. |
| Wicked & Gothic Panda | China | Massive IP theft. Wicked Panda (APT41) does state espionage by day, financial cybercrime by night. |
| Charming Kitten | Iran | State-sponsored (APT35) targeting journalists and dissidents via elaborate social engineering. |
| Velvet Chollima | North Korea | Named after a mythical winged horse; aggressively targets healthcare and finance to fund the regime. |
While it is easy to chuckle at names like “Cozy Bear,” these groups possess military-grade capabilities, zero-day exploits, and unlimited government funding. They are the apex predators of the digital world.
The Naming Game: Zoo Keepers vs. Weathermen
Without a “Supreme Court of Hackers,” cybersecurity firms race to name groups first. This creates a chaotic “Rosetta Stone” problem where a single Russian GRU unit is simultaneously known as Fancy Bear (CrowdStrike), APT28 (Mandiant), Forest Blizzard (Microsoft), Sofacy (Kaspersky), and Sednit (ESET).
Here is how the major industry players classify their targets:
- House CrowdStrike (The Zoo Keepers): Popularized the adversary animal system for marketing. Bear (Russia), Panda (China), Kitten (Iran), Chollima (North Korea), Tiger (India), Crane (South Korea), Spider (Cybercrime), and Jackal (Hacktivists).
- House Microsoft (The Weathermen): Overhauled naming to chaotic weather events. Blizzard (Russia), Typhoon (China), Sandstorm (Iran), Sleet (North Korea), and Tempest (Cybercrime).
- House Mandiant (The Scientists): Uses clinical alphanumeric codes (
APTfor state-sponsored,UNCfor uncategorized,FINfor financial) to avoid glamorizing criminals. - The Rest: Secureworks uses Metals (e.g., Gold Drake); Palo Alto Networks uses Space themes (e.g., Stardust Chollima).
Threat intelligence analysts often have to keep a mapping document open just to translate alerts between vendors. If your firewall blocks a “Panda” but your EDR alerts on a “Typhoon,” you are actually fighting the exact same Chinese threat actor!
The Complex Science of Attribution
Attribution distinguishes between simply naming a group (like dubbing a bank robber “Scattered Spider”) and actual identification (the US officially attributing attacks to GRU Unit 26165 via indictment).
Investigations span three levels:
- Tactical: What happened (e.g., SUNBURST malware deployment).
- Operational: How it happened (e.g., attacking on Tuesdays via Singapore IP addresses).
- Strategic: Who is behind it (e.g., Fancy Bear / GRU).
Attribution is notoriously difficult because hackers use “False Flags.” A North Korean unit might use Chinese malware code mimicking a “Panda,” or hijack infrastructure in Brazil to attack Japan.
Because of these deception tactics, researchers rely on a strict confidence scale:
- Low Confidence: Distractions found, like out-of-place Russian text in the code.
- Moderate Confidence: Tools and timing align with previous known operations.
- High Confidence: Infrastructure, targets, and stolen data point directly to a specific military unit or syndicate.
MITRE ATT&CK: The Universal “True” Name
As a non-profit “Switzerland” of cybersecurity, MITRE avoids marketing names entirely. They opt for a clinical approach that high-level Security Operations Centers (SOCs) prefer for its sheer actionability.
- Group IDs (G-Numbers): Threats receive codes like
G0007. This master record lists all aliases (Pawn Storm, Strontium) to confirm different alerts point to the exact same threat. - Software (S-Numbers): Tools are tracked separately, separating the people from the weapons. For example,
S0002(Mimikatz) orS0154(Cobalt Strike). - Campaigns (C-Numbers): Tracks specific events, like
C0025(2016 Ukraine Electric Power Attack), even before the actor is fully identified.
Pro Tip for Defenders
By switching your terminology from “Kitten” to “G0087 (APT39),” defenders can instantly access the 50+ specific tactical techniques they need to hunt for and block within the MITRE framework.
Conclusion
At the end of the day, whether your network is being besieged by a Panda, a Blizzard, or a Stardust Chollima, the malware hurts just the same.
While the cybersecurity marketing machine continues its turf war over who gets to name the next big Advanced Persistent Threat (APT), the professionals on the front lines don’t care about the mascot—they care about the tactics. By translating these chaotic names into actionable MITRE ID numbers, defenders can strip away the cute disguise and get back to what matters: keeping the network secure.
Over to you:
Which threat actor naming convention do you prefer? Are you on Team Animal, Team Weather, or Team Numbers?
