How Microsoft names threat actors
learn.microsoft.com
learn.microsoft.com
A level 7 gnome warlock with a ring of true sight and the wand of absolute freezing => Russia has hacked payroll and is encrypting your savings.
A level 4 half-orc paladin wielding the singing sword of ix => Iran has created a new chat bot that is data mining the entire world.
Then it will be very silly, a much better kind of silly.
Still, I agree that half silly is the worst (at least to me), it sounds like "corporate-allowed fun" which ruins the point.
- No mention of USA?
- This seems like needless redirection.
- Why tho?
Perhaps I’m hopelessly naive but I wonder if they all answer each other.
For business related reasons, Microsoft can’t call out threats of US origin. But obviously the researchers on the ground still care about those attacks very much.
One solution is to create an opaque reference scheme where Typhoon actually means China and Sandstorm actually means Iran.
Then you can sprinkle in new terms that aren’t explicitly defined anywhere. Something can be called Sunshine and, even though it’s not documented anywhere, everyone seems to know what it means.
And the agency in turn sends them a cake.
Also yea, the NSA listened to Merkels phone.
"Nation-state actor" is another hilarious one. For some strange reason everybody in the computer security industry decided to misuse the term (https://www.e-education.psu.edu/geog128/node/534) because... it sounds cool or scary or something. Why? Certainly doesn't signal anything positive about their understanding of geopolitics. If they'd just communicate like normal people then they would be taken more seriously. It all just reeks of snake oil salesman behavior, where words are not used to communicate and create mutual understanding, but to confuse and conjure the appearance of authority and grandiosity.
Also closes with this banger of a paragraph: Until then, well, just watch out for Periwinkle Tempest. Last year, Periwinkle Tempest launched crippling ransomware attacks across the entire nation of Costa Rica, leading the country's government to declare a national emergency. Periwinkle Tempest are some of the most dangerous hackers in the world. Periwinkle Tempest. Seriously.
Best you can do is learn to laugh at these people. Don't do it too contemptuously though, they might send your site's data along to their own aggregators. That would cost you an entire domain name.
Basically, Microsoft Threat Intelligence (formerly RiskIQ) craws the web, sends automated abuse complaints and backs them up with people who cannot even speak English, much less understand the context of their task. For independent publishers, the sword of Damocles is dangling. They can easily have your entire domain flagged and nuked from search. See also: "Google Safe Browsing".
for example, when new information comes to light that attributes the attack to someone different, instead of updating meta data you either have the name remain wrongly attributing it or you change the name and cause a load of confusion.
https://attack.mitre.org/groups/G0050/
I've been in situations where I would find attribution to an actor for something I am looking into but I had no idea $randomvendor was talking about the same actor $anothervendor had quite a bit of concerning write ups on until much later on.
This is pretty old-school military jargon and is simple enough that the public could get a general idea.
Not sure I agree with the use of spiders or jackals though. Spiders don't quite make sense for financial motivation/greed(unless the reference is pure "web" related). Jackals aren't well known outside of myth to be tricksters. Perhaps these animals make more sense from an ignorant American perspective:
Financial gain/greed - Rat
Hacktivism - Octopus
https://www.crowdstrike.com/blog/naming-adversaries-and-why-...
This specific theme sounds like it will increase the amount of cumulative errors given how closely related some of these names are.
The country-based "family names" are meant to represent groups that are (suspected) to be state-sponsored.