Why do hacking groups get codenames? A cybersecurity explainer

When a ransomware gang or a state-backed espionage group is first detected, cybersecurity companies typically assign it a codename long before its real-world identity is known. The practice can sound arbitrary from the outside, but it follows a surprisingly systematic logic.
Major technology companies each run their own naming systems for the groups their threat intelligence teams track. Google's threat intelligence units have historically used element and metal names for established actors, while assigning temporary "UNC" numeric codes to clusters that have not yet been fully characterized.
Microsoft shifted its entire threat-actor taxonomy to a weather-themed system a few years ago: state-backed groups are named after storm types, while financially motivated criminal groups carry names like "Blizzard." CrowdStrike, for its part, favors combinations of an animal and a national adjective.
The core reason behind these systems is to let defenders quickly recognize the same threat across different reports. A group's technical fingerprint — its tools, targeted sectors, and attack methods — tends to stay stable even when its real-world identity remains unknown for months, or indefinitely.
Experts note that naming also requires a careful balance: codenames need to be identifiable without romanticizing a group or handing it unwanted notoriety. That is one reason some firms avoid using names hackers choose for themselves, opting instead for their own internal taxonomy.
Another major driver is the challenge of attribution. Proving definitively which country or organization is behind an attack is extremely difficult and can carry serious diplomatic weight; using a neutral codename helps companies avoid making direct accusations that could have geopolitical consequences.
Google's recent overhaul is aimed at merging the separate naming systems previously used by its distinct threat intelligence teams — including Mandiant, which Google acquired — reducing confusion for analysts working across both.
The absence of a single industry-wide standard means the same group is often tracked under different names by different companies, which can make it harder for defenders to connect the dots across reports. Some researchers have called for a shared industry standard, though the competitive intelligence market has not converged on one.
Naming systems also carry a public-relations dimension: a memorable codename can help a company's threat report attract more media attention, leading some critics to argue that naming is occasionally shaped by marketing considerations as much as technical need.
Ultimately, the codenames given to hacking groups are more than a curiosity — they are a practical tool that lets defenders communicate quickly about a complex and constantly shifting threat landscape.
Read next

Planned Amazon data center could become the biggest climate polluter in the U.S.
As part of a planned Texas data center, Amazon is investing in an on-site power plant that could reportedly become the single largest source of climate pollution in the United States. The development highlights growing concern over the energy demands of AI infrastructure.

What is A* pathfinding, and how do better heuristics speed it up?
A* is one of the most widely used algorithms for finding the shortest path, from video games to robotics. Newly refined "differential heuristics" help the algorithm rule out unpromising routes earlier, meaningfully improving its performance.

New Mexico judge orders Meta to fund $567M youth mental health program
A New Mexico judge has ruled that Meta's platforms constituted a "public nuisance" and ordered the company to fund a $567 million program addressing the youth mental health crisis. The ruling is seen as a significant precedent in the wider wave of lawsuits against social media companies.

How AI hurricane forecasting is buying meteorologists an extra day's warning
DeepMind's open-source WeatherNext model can produce surprisingly accurate forecasts even when fed lower-resolution weather data. The result is giving meteorologists an extra day's lead time on predicting a hurricane's path compared with traditional physics-based models.

Why Microsoft Edge is about to lock out older ad blockers
Microsoft Edge is ending support for the Manifest V2 extensions platform, the same move Google Chrome made earlier this year, which will disable the uBlock Origin ad blocker and others like it. The impact on most users will be limited, but the shift is part of a broader transformation of the browser extension ecosystem.