Skip to content
Unlisted Report logoUnlisted ReportSubscribe
News

How Hacker Group Names Work: Blizzard, Typhoon, Spider

Ever wonder why hacker groups are called Spider, Blizzard, or Typhoon? We decode the naming schemes used by Microsoft, CrowdStrike, and other firms.

By · Published · 11 min read

A complex digital flowchart with interconnected nodes, each labeled with a symbolic icon representing a different hacker group naming convention like a bear, a spider, and a storm cloud.

Why are some hackers called Blizzard and others Spider? These names, known as threat actor monikers, are assigned by cybersecurity researchers to track groups of attackers. Different security firms use their own distinct naming conventions, often based on themes like weather, animals, or elements, to categorize adversaries by their origin, motive, and tactics.

Why Naming Conventions Matter

A single hacking group, like Russia's APT29, can be known simultaneously as Cozy Bear (from CrowdStrike), Nobelium (from Microsoft, now deprecated), and The Dukes (from various others). This can create a "tower of Babel" effect in threat intelligence reporting, where it's not always clear if two reports are discussing the same attacker. So why do it?

Despite the potential for confusion, these naming systems are essential. They provide an internal shorthand for researchers to organize vast amounts of data about an adversary's infrastructure, malware, victimology, and operational patterns—collectively known as Tactics, Techniques, and Procedures (TTPs). A name like "Wizard Spider" represents a massive, interconnected database of indicators of compromise, attack timelines, and defensive strategies. While the names differ, the underlying TTPs are often mapped to a common standard, like the one in MITRE ATT&CK explained for beginners. This framework provides a universal language for describing *how* attackers operate, even if we call them by different names.

Microsoft's Weather Report: A New Taxonomy

For years, Microsoft used chemical elements to name state-sponsored groups (e.g., Strontium for Russia, Barium for China). In 2023, the company overhauled its system, introducing a new taxonomy to better reflect the modern threat landscape. The new system is more structured and aims to provide more context at a glance.

Microsoft now assigns a family name based on the type of threat actor. Nation-state groups are given weather-themed names, which are tied to specific countries. A temporary "Storm" designation with a number is used for emerging or unknown clusters of activity. As researchers learn more, a Storm group might be graduated to a more permanent name or merged with an existing actor.

CategoryTheme/TypeCountry & Name Examples
Nation-StateWeatherBlizzard (Russia), Typhoon (China), Sandstorm (Iran), Sleet (North Korea)
Financially MotivatedUnique Name (e.g., "Tempest")Octo Tempest, Blackberry Tempest
Private Sector Offensive Actors (PSOAs)Unique NameParakeet, Caramel Tsunami
In Development / UncategorizedStorm-####Storm-1175, Storm-0978

This system allows Microsoft to track new threats quickly while maintaining a structured long-term catalog. The specific names also evolve; Russia's infamous APT28, once called Strontium, is now tracked by Microsoft as "Forest Blizzard." We see this in action when a group like the one in Russia's Star Blizzard swaps ClickFix for RedFlick evolves its toolset to evade detection, forcing researchers to update their tracking.

CrowdStrike's Adversary Zoo

Perhaps the most famous naming convention comes from CrowdStrike, which populates a veritable "adversary zoo." Their system is simple and memorable: `[Adjective] [Animal]`. The animal signifies the group's suspected country of origin, while the adjective distinguishes it from other groups from the same region.

  • Bear (Russia): The most infamous residents of the zoo. Fancy Bear (APT28) and Cozy Bear (APT29) are linked to Russian intelligence services and were behind major attacks, including the 2016 DNC hack.
  • Panda (China): Groups attributed to China. Deep Panda has been linked to espionage targeting various US industries, while Pirate Panda is known for its campaigns against Vietnamese government institutions.
  • Kitten (Iran): Adversaries believed to be operating from Iran. Charming Kitten (aka APT35) is known for its sophisticated social engineering and phishing campaigns targeting academics, activists, and government officials.
  • Chollima (North Korea): Named after a mythical winged horse from Korean folklore. This category includes groups like Lazarus Group (tracked as Stardust Chollima by CrowdStrike), which is responsible for massive cryptocurrency heists and the WannaCry ransomware attack.
  • Spider (e-Crime): This is the most important exception. Spiders are not tied to a nation-state. This category is reserved for financially motivated criminal groups, regardless of their location. It includes some of the most prolific ransomware gangs and initial access brokers. For example, Wizard Spider is the group behind Conti and Ryuk ransomware, while Scattered Spider is known for its social engineering attacks targeting corporate help desks. The sheer volume of financially motivated crime means the "Spider" family is one of the largest and most active, responsible for a significant portion of attacks that drove ransomware to a record high in August 2026.

A Rosetta Stone of Hacker Names

Microsoft and CrowdStrike are just two of many firms with their own systems. Understanding a few others helps to build a "Rosetta Stone" for decoding threat intelligence reports.

Mandiant (Google Cloud) Mandiant's system is one of the oldest and most influential. They use numbered "Advanced Persistent Threat" (APT) and "Financial" (FIN) designations. - **APT##:** Reserved for state-sponsored or state-aligned espionage groups. APT1 was the landmark report that publicly attributed a major hacking campaign to a specific unit of China's People's Liberation Army. APT28 and APT29 are the Russian groups mentioned earlier. - **FIN##:** Used for financially motivated groups, like the operators of point-of-sale malware or ransomware. FIN7 is a well-known group that has targeted the retail and hospitality sectors for years. - **UNC####:** Stands for "Uncategorized." This is a temporary designation for a new cluster of activity that has not yet been formally identified or linked to a known APT or FIN group. Many UNC groups eventually graduate to a formal name.

Secureworks Secureworks uses a system based on metallic elements, called "Threat Groups" (TGs). - **GOLD:** Financially motivated groups. - **NICKEL:** Groups originating from China. - **COBALT:** Groups originating from Russia. - **BRONZE:** Groups from other nations or whose origin is less certain.

Dragos As a specialist in Industrial Control Systems (ICS) and operational technology (OT) security, Dragos has its own unique scheme. They name groups after fictional teams from media or minerals, reflecting their focus on the critical infrastructure sector. Names like **XENOTIME**, **ALLANITE**, and **PARISITE** are associated with highly specialized groups capable of disrupting physical industrial processes, a far different goal than stealing data or money.

The Attribution Puzzle

While these names provide a useful framework, attribution is one of the hardest problems in cybersecurity. Hackers are masters of deception and actively work to mislead researchers. They use false flags, such as planting foreign-language comments in their malware or routing attacks through servers in other countries, to throw investigators off their trail.

Furthermore, the lines between groups are often blurry. Groups merge, split, rebrand, or go dormant. Sometimes, one group will lease or sell its tools to another, a model known as "access-as-a-service." A single piece of malware might be used by a dozen different actors. This is why threat intelligence professionals emphasize that a name like "Cozy Bear" refers to a *cluster of activity*—a shared set of tools, infrastructure, and behaviors—rather than a confirmed list of specific human beings sitting in a room together. The long-term tracking of these clusters, despite name changes, is a core function of threat intelligence.

How to Use This Information

For anyone who isn't a full-time threat hunter, memorizing dozens of hacker names is unnecessary. The key is to understand what these names represent and how to use that context to improve your own security posture.

When you see a news story about an attack by "Typhoon" or "Fancy Bear," the name itself is less important than the context it provides. Is it a state-sponsored espionage group (Bear, Typhoon) or a financially motivated criminal gang (Spider, Gold)? This tells you about their likely objective: are they after state secrets and intellectual property, or are they trying to encrypt your files for a ransom?

Instead of getting lost in the names, focus on defending against the underlying techniques. The vast majority of attacks, regardless of who perpetrates them, rely on a common set of initial access vectors. Your best defense is a strong foundation of security hygiene:

  • Prompt Patching: Apply security updates for your operating systems and applications as soon as they are available. Many sophisticated groups get their initial foothold by exploiting old, known vulnerabilities.
  • Strong Authentication: The single most effective step you can take is to learn how to set up two-factor authentication properly on all your critical accounts, from email and banking to social media.
  • Phishing Awareness: Train yourself and your employees to be skeptical of unsolicited emails, texts, and phone calls. Most major breaches start with a single click on a malicious link.
  • Robust Backups: In a world of ransomware, having recent, tested, and offline backups is your ultimate safety net.

Ultimately, the complex world of hacker group names is a fascinating look into the cat-and-mouse game played between attackers and defenders. For the defenders, it's a critical tool for tracking threats. For the rest of us, it's a reminder that behind every breach is a determined adversary, and the best response is not to learn their name, but to secure the doors and windows they're trying to get through.

Read next