Microsoft and other security experts want a proper naming system for the worst hackers around
- Microsoft announces new threat actor name tracking partnership
- Microsoft and Crowdstrike have already cross-linked over 130 groups
- Tracking groups will now be easier, and help security vendors respond
If you’re struggling to keep track of all the different names each hacking collective, ransomware group, and state-sponsored threat actor has, you’re not alone.
Microsoft and Crowdstrike have announced a new collaboration to help create a unified naming system to track all the worst hacking groups.
The system will help save precious seconds when responding to cyberattacks by providing a unified naming system to be used by authorities, security experts, businesses, and security vendors.
Unified naming for hackers
Currently, if you were trying to track the activities of the Salt Typhoon group, you may also have to be aware of the others names used to track the same group, such as OPERATOR PANDA, GhostEmperor, and FamousSparrow. This inconsistency in naming “can reduce confidence, complicate analysis, and delay response,” Microsoft said.
As part of the collaboration, Microsoft has released a reference guide which not only lays out Microsoft’s naming conventions, but also includes other names given to the most notorious hacking groups by other security vendors.
This guide breaks down nation-state actors into their geographic location using weather-themed names as the suffix, such as Typhoon for China, and Blizzard for Russia.
Other groups, such as influence campaigns (Flood), financially motivated groups (Tempest), and commercial cyberweapon developers (Tsunami), are also tracked using weather event themed names.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Groups that do not have a known affiliation, motivation, or groups that have recently emerged are tracked as Storm.
Google and their Mandiant subsidiary will also be contributing to the mapping of hacking group names, alongside Palo Alto Networks Unit 42.
“Security is a shared responsibility, requiring community-wide efforts to improve defensive measures. We are excited to be teaming up with CrowdStrike and we look forward to others joining us on this journey,” Microsoft said.
You might also like
Microsoft announces new threat actor name tracking partnership Microsoft and Crowdstrike have already cross-linked over 130 groups Tracking groups will now be easier, and help security vendors respond If you’re struggling to keep track of all the different names each hacking collective, ransomware group, and state-sponsored threat actor has, you’re…
Recent Posts
- I tested Sony’s affordable Bravia 5 TV, and it offers a lot of punch for its price tag, throwing serious shade on Sony’s previous mid-range screens
- Apple iTunes still exists, but not the way it used to
- Is the Steam Deck still worth it in 2026?
- This little robot window-cleaner is the best labor-saving device I’ve ever used, and it’s going cheap at Amazon right now
- Grab Kodak’s best-selling compact camera from the past two years for less, with a 30% discount this Labor Day
Archives
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023