6 min Security

Should we stop giving cyber threats fancy names?

It's unclear who benefits when your adversary is tracked as 'Cozy Bear'

Should we stop giving cyber threats fancy names?

Midnight Blizzard, Wicked Panda and Sandworm are all cyber threat actors lucky enough to have been given evocative names by security researchers. Needless to say, they are more memorable than the designations APT29, APT41 and APT44 used elsewhere. Okta often uses plainer, numbered labels for the activity it tracks, whereas CrowdStrike, Trend Micro and others use more striking naming schemes. At the annual Oktane conference, we asked: why not do the same? And what are the pitfalls for giving threat actors memorable names?

Katie Nickels, Director at Okta Threat Intelligence, explains why such names catch on. “The value of these groupings is that they’re easier for people to remember. ‘There’s that spider’ versus ‘the group of actors that does XYZ uses this infrastructure’, right? It’s a good rule of thumb.”

That memorability extends to names not bestowed by researchers. Many organizations will know all too well the names used by the criminals targeting them, from ShinyHunters to the rather straight-to-video sounding ‘Evil Corp‘. We’re specifically referring here to names emerging from the security industry, not the brands common to dark web activities.

Why does this matter?

Before we get into the research on this topic, we must ask: why does it (even) matter what we call a threat actor? A name can make a threat easier to discuss, but it can also suggest a more clearly defined group than the evidence actually points to.

This is made more complicated by the fact that threats are rarely easily defined. Okta’s researchers often group activity around attacker infrastructure, using those connections to identify campaigns and warn customers. The result can be a numbered designation rather than a fancy moniker. Brett Winterford, Vice President at Okta Threat Intelligence, does admit this approach has its constraints. “We struggle a little because we give threat actors very boring names. (…) Sometimes our customers are like, ‘Can you please just tell me, is that ShinyHunters?’”

ShinyHunters is a name the attackers use themselves. Winterford thinks that simply going along with it is helping the attackers. “That is a term that is used to strike fear into the heart of someone who’s having to decide whether to pay an extortion demand or not. Why should we be using their marketing terms? That’s my point of view.”

Taxonomic troubles

The counterexample to Okta’s approach is doubtlessly CrowdStrike. The latter highlights how important it is for cyber defenders to track adversaries as specific threats. “Understanding the adversaries most likely to target your business is critical because it helps you focus your resources and better prepare your defenses to defeat them,” the company explains.

We didn’t speak to CrowdStrike for this piece. However, its own material illustrates its approach clearly. From prominent art in its Global Threat Reports to snazzy Adversary Figurines in its Swag Shop, CrowdStrike emphatically highlights just how attractive the naming scheme can be. In said scheme, ‘Panda’ point to a Chinese threat and ‘Bear’ to Russia. Monetary motivation gets the non-national ‘Spider’ moniker, with Scattered Spider perhaps the most well known among them. Given barely anyone will know Scattered Spider’s larger group, ‘The Community’, a name it chose for itself, the external researchers clearly did a better job than the dark web marketeers.

The names aren’t always ‘cool’, but they are at least memorable. This in and of itself is an accomplishment. For vulnerabilities, a memorable name may also help draw attention to them, leading to quicker patching. It just so happens this achievement of giving threat actors fancy names carries a burden. According to research at the University of Edinburgh, branding both of and by threat actors has shaped the cybercrime ecosystem. The most compelling sounding attackers may not be the most relevant to a given organization, but their names may draw attention away from less vividly branded risks. In addition, a loosely federated group whose members share tools or infrastructure can appear to be a coherent, coordinating, scheming gang. Winterford of Okta points out that carefully separated distinctions between groups may later prove to involve some of the same people.

Beyond that, the variety and scope of attackers means we see repetition, suggesting some commonality that isn’t there between cyber threats, and Russian military intelligence being known as ‘Fancy Bear‘ can make its actions sound like those of a cartoon villain.

The main reason

There are blunter criticisms than the concerns raised by academics. Doug Newdick, Consulting Lead at Axenic, proposed in 2020 to opt for ‘lame names’ like Stinky-Breath or AsshatsInc rather than ‘counter-productive’ options like those used by CrowdStrike.

Then again, the branding is clear for all to see. Microsoft can even lay claim to the memorable ‘Midnight Blizzard’, a group which later accessed some of the tech giant’s corporate email accounts. The likes of CrowdStrike and Trend Micro (which uses a more esoteric scheme) can also gain publicity from their hard work thanks to the practice. Okta might seem to have missed a trick here.

We strongly suspect marketing is a major reason security companies choose evocative, descriptive names. Why opt for obscurity or boredom if you can instead be bold and memorable?

Conclusion: towards greater effectiveness

We do wish to emphasize how important it is to track vulnerabilities and methods by some other name than merely a CVE or TTP designation. The former is just a bunch of numbers and the latter is not always the most descriptive. Simply adopting the name of a common malware or ransomware can also help detection. Names like Log4Shell, WannaCry and juice jacking make threats easier to identify and discuss.

There is, therefore, good reason to be creative in cyberspace. But when it comes to the groups behind attacks, branding can draw defenders’ attention toward the most memorable names rather than the most relevant threats. It can also build the reputations of both the criminals and the companies that name them. We needn’t be as conservative as Okta or as eager as CrowdStrike.

Katie Nickels highlights the priority beyond the naming schemes. “What do customers, end users and CISOs really care about? They want to know, ‘Am I impacted? How do I protect against that threat?’ My advice is to think more about the tactics, techniques and procedures, the protections, what might happen during the attack and the outcomes, rather than the exact name.”

And when a threat sounds frightening, she adds, “pair that with remediation.” Explain what attackers do and how customers can protect themselves, and “we won’t be distracted by the shiny new things.”