3 ms·
I believe that individual vendors (MSTC, FireEye, Talos, etc.) name threat actors differently. If you're interested, I'd highly recommend this page by CrowdStri
by ping00 5y ago
I believe that individual vendors (MSTC, FireEye, Talos, etc.) name threat actors differently. If you're interested, I'd highly recommend this page by CrowdStrike: https://adversary.crowdstrike.com/en-US/ https://adversary.crowdstrike.com/en-US/
It's very interesting to see how humans naturally tend to craft identities for faceless, nameless adversaries, which I think is very interesting from a social standpoint. Also the artwork in the website above is just plain cool IMO :)
Although the vendors share information quite freely, I think there's hesitation on a vendor mutually adopting another vendor's threat actor name because it implies more substantive research on the latter's part, which is usually a no-no in a field like this. Ofc, I'm sure there are exceptions.
edit: I also wanted to give Thai CERT a shout out and add a link to https://www.thaicert.or.th/downloads/files/Threat_Group_Cards_v2.0.pdf https://www.thaicert.or.th/downloads/files/Threat_Group_Card... which is less flashy than the CrowdStrike compendium, but well-detailed
- sdw1 5y agoReally appreciate the Thai CERT link -- I was really interested in seeing that Crowdstrike information presented in a format that's not about to pitch me the Crowdstrike Cinematic Universe or next-gen-Rainbow-6-arena-MMO or whatever they're going for. The glitchy elements/animations made it actually stressful for me to read.
- hdjjhhvvhga 5y ago> It's very interesting to see how humans naturally tend to craft identities for faceless, nameless adversaries, which I think is very interesting from a social standpoint. It's quite simple: you need a name (preferably unique) in order to refer to it in communication.
- staticassertion 5y agoIt's more than that. "FancyBear" is not a random name.