Tech

Why do hacking groups get codenames? A cybersecurity explainer

TechCrunch2 h ago
A blue-lit server room filled with data cables
A blue-lit server room filled with data cablesPhoto: Brett Sayles / Pexels

When a ransomware gang or a state-backed espionage group is first detected, cybersecurity companies typically assign it a codename long before its real-world identity is known. The practice can sound arbitrary from the outside, but it follows a surprisingly systematic logic.

Major technology companies each run their own naming systems for the groups their threat intelligence teams track. Google's threat intelligence units have historically used element and metal names for established actors, while assigning temporary "UNC" numeric codes to clusters that have not yet been fully characterized.

Microsoft shifted its entire threat-actor taxonomy to a weather-themed system a few years ago: state-backed groups are named after storm types, while financially motivated criminal groups carry names like "Blizzard." CrowdStrike, for its part, favors combinations of an animal and a national adjective.

The core reason behind these systems is to let defenders quickly recognize the same threat across different reports. A group's technical fingerprint — its tools, targeted sectors, and attack methods — tends to stay stable even when its real-world identity remains unknown for months, or indefinitely.

Experts note that naming also requires a careful balance: codenames need to be identifiable without romanticizing a group or handing it unwanted notoriety. That is one reason some firms avoid using names hackers choose for themselves, opting instead for their own internal taxonomy.

Another major driver is the challenge of attribution. Proving definitively which country or organization is behind an attack is extremely difficult and can carry serious diplomatic weight; using a neutral codename helps companies avoid making direct accusations that could have geopolitical consequences.

Google's recent overhaul is aimed at merging the separate naming systems previously used by its distinct threat intelligence teams — including Mandiant, which Google acquired — reducing confusion for analysts working across both.

The absence of a single industry-wide standard means the same group is often tracked under different names by different companies, which can make it harder for defenders to connect the dots across reports. Some researchers have called for a shared industry standard, though the competitive intelligence market has not converged on one.

Naming systems also carry a public-relations dimension: a memorable codename can help a company's threat report attract more media attention, leading some critics to argue that naming is occasionally shaped by marketing considerations as much as technical need.

Ultimately, the codenames given to hacking groups are more than a curiosity — they are a practical tool that lets defenders communicate quickly about a complex and constantly shifting threat landscape.

This article is an AI-curated summary based on TechCrunch. The illustration is a stock photo by Brett Sayles from Pexels.

Read next