It's very interesting to see how humans naturally tend to craft identities for faceless, nameless adversaries, which I think is very interesting from a social standpoint. Also the artwork in the website above is just plain cool IMO :)
Although the vendors share information quite freely, I think there's hesitation on a vendor mutually adopting another vendor's threat actor name because it implies more substantive research on the latter's part, which is usually a no-no in a field like this. Ofc, I'm sure there are exceptions.
edit: I also wanted to give Thai CERT a shout out and add a link to https://www.thaicert.or.th/downloads/files/Threat_Group_Card... which is less flashy than the CrowdStrike compendium, but well-detailed
It's quite simple: you need a name (preferably unique) in order to refer to it in communication.
The names were classified (Secret perhaps?), but at some point the US Government realized everyone was kinda using these names in conversations, probably not all at the secret level. These names had leaked out too much, they needed new names.
So they decided to rename them with new Secret names, and just kinda let the old names become utilized. They tried to hide the old <-> new name mapping because the new name mapping was classified.
Crowdstrike started as mostly former FBI / NSA employees. They liked using all these names to identify actors. But they realized they didn't want to use classified names. So they came up with their own very boring names (APT1, APT2 ,etc.). While others had always done this internally (Microsoft had names, Google had internal names, etc. etc.), Crowd strike utilized these names very publicly and it just kinda took off.
I think the US Government at some point realized they could just use Crowdstrike names and avoid all of the Classified name mess, so they just utilized crowd strike names as well. So now Crowdstrike names are mostly the go-to. Unless you are micrososft, then you keep using your names....
My guess is Somewhere at Ft Meade an analyst has produced a massive, beautiful chart mapping all this shit together, and her sole job is to keep it updated.
...or this is my best guess anyway.
[1]https://news.ycombinator.com/item?id=28980382
[2]https://www.destinypedia.com/Grimoire:Allies/Rasputin#Ghost_...
They really do though, some RASPUTIN level AI just naming things.
https://en.wikipedia.org/wiki/Cozy_Bear for the sources for each name
For Microsoft specifically, we leverage the periodic table of elements when naming nation states.
The authorities are so incompetent in generating consequences that they have go with the idea that Putin signed off on the action himself, just to deflect
“A dozen intelligence agencies” are all going to have the same evidence: a non-VPN IP address
People are really gullible, remember when even just that turned into a partisan thing a few years ago? lulz. idiots.