7 ms·
Kinda off topic, but I'm wondering who names these threat actors?
by zelag 5y ago
Kinda off topic, but I'm wondering who names these threat actors?
- connordoner 5y agoI’d love to know this too!
- rvnx 5y agoMarketing managers and security researchers in private companies giving them names. The same reason high-profile exploits have nickname (heartbleed for example). https://en.wikipedia.org/wiki/Cozy_Bear https://en.wikipedia.org/wiki/Cozy_Bear for the sources for each name
- ConcernedCoder 5y agoI'm sure marketing knows it's easier to sell remediation for "heartbleed" rather than "smurfkiss"
- rvnx 5y agoWell, it's explained here for Microsoft: https://www.microsoft.com/security/blog/2021/10/25/microsoft-digital-defense-report-shares-new-insights-on-nation-state-attacks/ https://www.microsoft.com/security/blog/2021/10/25/microsoft...
- Arrath 5y agoI was idly thinking while reading the Journalist & Pegasus story from a few days ago[1], that some of the names for these exploits and groups, like KISMET, NOBELIUM, and HIPPOCRENE FACTOR especially, sound like codenames from a Destiny Lore Card[2] or something. Must be a fun exercise to brainstorm some of them up, if nothing else. [1]https://news.ycombinator.com/item?id=28980382 https://news.ycombinator.com/item?id=28980382 [2]https://www.destinypedia.com/Grimoire:Allies/Rasputin#Ghost_Fragment:_Rasputin_3 https://www.destinypedia.com/Grimoire:Allies/Rasputin#Ghost_...
- Grimm1 5y agoI just got off the Destiny subreddit, why must you drag me back in! They really do though, some RASPUTIN level AI just naming things.
- ping00 5y agoI believe that individual vendors (MSTC, FireEye, Talos, etc.) name threat actors differently. If you're interested, I'd highly recommend this page by CrowdStrike: https://adversary.crowdstrike.com/en-US/ https://adversary.crowdstrike.com/en-US/ It's very interesting to see how humans naturally tend to craft identities for faceless, nameless adversaries, which I think is very interesting from a social standpoint. Also the artwork in the website above is just plain cool IMO :) Although the vendors share information quite freely, I think there's hesitation on a vendor mutually adopting another vendor's threat actor name because it implies more substantive research on the latter's part, which is usually a no-no in a field like this. Ofc, I'm sure there are exceptions. edit: I also wanted to give Thai CERT a shout out and add a link to https://www.thaicert.or.th/downloads/files/Threat_Group_Cards_v2.0.pdf https://www.thaicert.or.th/downloads/files/Threat_Group_Card... which is less flashy than the CrowdStrike compendium, but well-detailed
- sdw1 5y agoReally appreciate the Thai CERT link -- I was really interested in seeing that Crowdstrike information presented in a format that's not about to pitch me the Crowdstrike Cinematic Universe or next-gen-Rainbow-6-arena-MMO or whatever they're going for. The glitchy elements/animations made it actually stressful for me to read.
- hdjjhhvvhga 5y ago> It's very interesting to see how humans naturally tend to craft identities for faceless, nameless adversaries, which I think is very interesting from a social standpoint. It's quite simple: you need a name (preferably unique) in order to refer to it in communication.
- staticassertion 5y agoIt's more than that. "FancyBear" is not a random name.
- Igelau 5y agoRandomly pulled from list of Beyblades and marijuana strains, it would appear.
- vmception 5y agoIts just individuals deploying their code over clearnet with computers they found on darknet RDP marketplaces The authorities are so incompetent in generating consequences that they have go with the idea that Putin signed off on the action himself, just to deflect “A dozen intelligence agencies” are all going to have the same evidence: a non-VPN IP address People are really gullible, remember when even just that turned into a partisan thing a few years ago? lulz. idiots.
- mox1 5y agoInitially this started internally at the US Government. Probably mostly the NSA, but then the vernacular spread. Kinda useful when having conversations to say "Cranky Frog" and not "China special operations group 304 PLA #122" The names were classified (Secret perhaps?), but at some point the US Government realized everyone was kinda using these names in conversations, probably not all at the secret level. These names had leaked out too much, they needed new names. So they decided to rename them with new Secret names, and just kinda let the old names become utilized. They tried to hide the old <-> new name mapping because the new name mapping was classified. Crowdstrike started as mostly former FBI / NSA employees. They liked using all these names to identify actors. But they realized they didn't want to use classified names. So they came up with their own very boring names (APT1, APT2 ,etc.). While others had always done this internally (Microsoft had names, Google had internal names, etc. etc.), Crowd strike utilized these names very publicly and it just kinda took off. I think the US Government at some point realized they could just use Crowdstrike names and avoid all of the Classified name mess, so they just utilized crowd strike names as well. So now Crowdstrike names are mostly the go-to. Unless you are micrososft, then you keep using your names.... My guess is Somewhere at Ft Meade an analyst has produced a massive, beautiful chart mapping all this shit together, and her sole job is to keep it updated. ...or this is my best guess anyway.
- fname 5y agoThis might help: https://www.securityweek.com/whats-threat-group-name-inside-look-intricacies-nation-state-attribution https://www.securityweek.com/whats-threat-group-name-inside-... For Microsoft specifically, we leverage the periodic table of elements when naming nation states.
- Jyaif 5y agoNobelium is an incredibly stupid name. They might as well go all in and name them "plutonium" or "anthrax".
- The-Bus 5y agoBest thing to do is give them non-threatening names like Beige Team or Fanny Pack.
- slowhand09 5y agoLocutus of Borg probably...