How Microsoft names threat actors

Microsoft has shifted to a new naming taxonomy for threat actors aligned with the theme of weather. With the new taxonomy, we intend to bring better clarity to customers and other security researchers already confronted with an overwhelming amount of threat intelligence data and offer a more organized, articulate, and easy way to reference threat actors so that organizations can better prioritize and protect themselves.



Nation-state actors based on Microsoft naming

Microsoft categorizes threat actors into five key groups:

Nation-state actors: cyber operators acting on behalf of or directed by a nation/state-aligned program, irrespective of whether for espionage, financial gain, or retribution. Microsoft has observed that most nation state actors continue to focus operations and attacks on government agencies, intergovernmental organizations, non-governmental organizations, and think tanks for traditional espionage or surveillance objectives.

Financially motivated actors: cyber campaigns/groups directed by a criminal organization/person with motivations of financial gain and haven’t been associated with high confidence to a known non-nation state or commercial entity. This category includes ransomware operators, business email compromise, phishing, and other groups with purely financial or extortion motivations.

Private sector offensive actors (PSOAs): cyber activity led by commercial actors that are known/legitimate legal entities, that create and sell cyberweapons to customers who then select targets and operate the cyberweapons. These tools threaten many global human rights efforts, as they have been observed targeting and surveilling dissidents, human rights defenders, journalists, civil society advocates, and other private citizens.

Influence operations: information campaigns communicated online or offline in a manipulative fashion to shift perceptions, behaviors, or decisions by target audiences to further a group or a nation’s interests and objectives.

Groups in development: a temporary designation given to an unknown, emerging, or developing threat activity that allows Microsoft to track it as a discrete set of information until we can reach high confidence about the origin or identity of the actor behind the operation. Once criteria are met, a group in development is converted to a named actor or merged into existing names.

In our new taxonomy, a weather event or family name represents one of the above categories. In the case of nation-state actors, we have assigned a family name to a country of origin tied to attribution, like Typhoon indicates origin or attribution to China. For other actors, the family name represents a motivation. For example, Tempest indicates financially motivated actors. Threat actors within the same weather family are given an adjective to distinguish actor groups with distinct tactics, techniques, and procedures (TTPs), infrastructure, objectives, or other identified patterns. For groups in development, where there is a newly discovered, unknown, emerging, or developing cluster of threat activity, we use a temporary designation of Storm and a four-digit number, allowing us to track it as a unique set of information until we can reach high confidence about the origin or identity of the actor behind the operation.

The table below shows how the new family names map to a sampling of the threat actors that we track.

Actor categoryTypeFamily name
Nation-stateChina
Iran
Lebanon
North Korea
Russia
South Korea
Turkey
Vietnam
Typhoon
Sandstorm
Rain
Sleet
Blizzard
Hail
Dust
Cyclone
Financially motivatedFinancially motivatedTempest
Private sector offensive actorsPSOAsTsunami
Influence operationsInfluence operationsFlood
Groups in developmentGroups in developmentStorm

Use the following reference table below to understand how our previously publicly disclosed old threat actor names translate to our new taxonomy.

Previous nameNew nameOrigin/ThreatOther names
ACTINIUMAqua BlizzardRussiaUNC530, Primitive Bear, Gamaredon
AMERICIUMPink SandstormIranAgrius, Deadwood, BlackShadow, SharpBoys
BARIUMBrass TyphoonChinaAPT41
BISMUTHCanvas CycloneVietnamAPT32, OceanLotus
BOHRIUMSmoke SandstormIran
BROMINEGhost BlizzardRussiaEnergetic Bear, Crouching Yeti
CERIUMRuby SleetNorth Korea
CHIMBORAZOSpandex TempestFinancially motivatedTA505
CHROMIUMCharcoal TyphoonChinaControlX
COPERNICIUMSapphire SleetNorth KoreaGenie Spider, BlueNoroff
CURIUMCrimson SandstormIranTA456, Tortoise Shell
DUBNIUMZigzag HailSouth KoreaDark Hotel, Tapaoux
ELBRUSSangria TempestFinancially motivatedCarbon Spider, FIN7
EUROPIUMHazel SandstormIranCobalt Gypsy, APT34, OilRig
GADOLINIUMGingham TyphoonChinaAPT40, Leviathan, TEMP.Periscope, Kryptonite Panda
GALLIUMGranite TyphoonChina
HAFNIUMSilk TyphoonChina
HOLMIUMPeach SandstormIranAPT33, Refined Kitten
IRIDIUMSeashell BlizzardRussiaSandworm
KNOTWEEDDenim TsunamiPrivate sector offensive actorDSIRF
KRYPTONSecret BlizzardRussiaVenomous Bear, Turla, Snake
LAWRENCIUMPearl SleetNorth Korea
MANGANESEMulberry TyphoonChinaAPT5, Keyhole Panda, TABCTENG
MERCURYMango SandstormIranMuddyWater, SeedWorm, Static Kitten, TEMP.Zagros
NEPTUNIUMCotton SandstormIranVice Leaker
NICKELNylon TyphoonChinake3chang, APT15, Vixen Panda
NOBELIUMMidnight BlizzardRussiaAPT29, Cozy Bear
OSMIUMOpal SleetNorth KoreaKonni
PARINACOTAWine TempestFinancially motivatedWadhrama
PHOSPHORUSMint SandstormIranAPT35, Charming Kitten
PLUTONIUMOnyx SleetNorth KoreaSilent Chollima, Andariel, DarkSeoul
POLONIUMPlaid RainLebanon
RADIUMRaspberry TyphoonChinaAPT30, LotusBlossom
RUBIDIUMLemon SandstormIranFox Kitten, UNC757, PioneerKitten
SEABORGIUMStar BlizzardRussiaCallisto, Reuse Team
SILICONMarbled DustTurkeySea Turtle
SOURGUMCaramel TsunamiPrivate sector offensive actorCandiru
SPURRTomato TempestFinancially motivatedVatet
STRONTIUMForest BlizzardRussiaAPT28, Fancy Bear
TAALCamouflage TempestFinancially motivatedFIN6, Skeleton Spider
THALLIUMEmerald SleetNorth KoreaKimsuky, Velvet Chollima
ZINCDiamond SleetNorth KoreaLabyrinth Chollima, Lazarus
ZIRCONIUMViolet TyphoonChinaAPT31
Previous nameNew nameOrigin/ThreatOther names
DEV-0146Pumpkin SandstormIranZeroCleare
DEV-0193Periwinkle TempestFinancially motivatedWizard Spider, UNC2053
DEV-0196Carmine TsunamiPrivate sector offensive actorQuaDream
DEV-0198 (NEPTUNIUM)Cotton SandstormIranVice Leaker
DEV-0206Mustard TempestFinancially motivatedPurple Vallhund
DEV-0215 (LAWRENCIUM)Pearl SleetNorth Korea
DEV-0227 (AMERICIUM)Pink SandstormIranAgrius, Deadwood, BlackShadow, SharpBoys
DEV-0228Cuboid SandstormIran
DEV-0234Lilac TyphoonChina
DEV-0237Pistachio TempestFinancially motivatedFIN12
DEV-0243Manatee TempestFinancially motivatedEvilCorp, UNC2165, Indrik Spider
DEV-0257Storm-0257Group in developmentUNC1151
DEV-0322Circle TyphoonChina
DEV-0336Night TsunamiPrivate sector offensive actorNSO Group
DEV-0343Gray SandstormIran
DEV-0401Cinnamon TempestFinancially motivatedEmperor Dragonfly, Bronze Starlight
DEV-0500Marigold SandstormIranMoses Staff
DEV-0504Velvet TempestFinancially motivated
DEV-0530Storm-0530North KoreaH0lyGh0st
DEV-0537Strawberry TempestFinancially motivatedLAPSUS$
DEV-0586Cadet BlizzardRussia
DEV-0605Wisteria TsunamiPrivate sector offensive actorCyberRoot
DEV-0665Sunglow BlizzardRussia
DEV-0796Phlox TempestFinancially motivatedClickPirate, Chrome Loader, Choziosi loader
DEV-0832Vanilla TempestFinancially motivated
DEV-0950Lace TempestFinancially motivatedFIN11, TA505

Read our announcement about the new taxonomy for more information: https://aka.ms/threatactorsblog

Putting intelligence into the hands of security professionals

Intel profiles in Microsoft Defender Threat Intelligence bring crucial threat actor insights directly into defenders’ hands so that they can get the context they need as they prepare for and respond to threats.

Additionally, to further operationalize the threat intelligence you get from Microsoft, the Microsoft Defender Threat Intelligence Intel Profiles API provides the most up-to-date threat actor infrastructure visibility in the industry today, enabling threat intelligence and security operations (SecOps) teams to streamline their advanced threat hunting and analysis workflows. Learn more about this API in the documentation: Use the threat intelligence APIs in Microsoft Graph (preview).

Resources

Use the following query on Microsoft 365 Defender and other Microsoft security products supporting the Kusto query language (KQL) to get information about a threat actor using the old name, new name, or industry name:

let TANames = externaldata(PreviousName: string, NewName: string, Origin: string, OtherNames: dynamic)[@"https://raw.githubusercontent.com/microsoft/mstic/master/PublicFeeds/ThreatActorNaming/MicrosoftMapping.json"] with(format="multijson", ingestionMapping='[{"Column":"PreviousName","Properties":{"Path":"$.Previous name"}},{"Column":"NewName","Properties":{"Path":"$.New name"}},{"Column":"Origin","Properties":{"Path":"$.Origin/Threat"}},{"Column":"OtherNames","Properties":{"Path":"$.Other names"}}]'); 
let GetThreatActorAlias = (Name: string) { 
TANames 
| where Name =~ NewName or Name =~ PreviousName or OtherNames has Name 
}; 
GetThreatActorAlias("ZINC")

The following files containing the comprehensive mapping of old threat actor names with their new names are also available:

Read More
Alejandro Wiers

Latest

“Take the Stairs”: Adekunle Gold Shares Advice for Creatives at The Macallan Partnership Celebration

Award-winning singer and songwriter Adekunle Gold has urged creatives to remain committed to their craft, even when recognition feels out of reach, sharing a powerful reflection on patience, excellence and… The post “Take the Stairs”: Adekunle Gold Shares Advice for Creatives at The Macallan Partnership Celebration appeared first on Nigerian Entertainment Today...

Bernie Sanders Backs Justin J. Pearson, House Candidate at the Heart of Tennessee Voting Rights Fight

Pearson challenged the last Tennessee Democrat in the House. Now he’s up against the threat of total GOP control. The post Bernie Sanders Backs Justin J. Pearson, House Candidate at the Heart of Tennessee Voting Rights Fight appeared first on The Intercept...

Multi-agency flood control exercise gains momentum

A large-scale flood control and drainage desilting campaign, spearheaded by Zoomlion Ghana Limited and its partners, has been intensified across Accra as stakeholders step up efforts to prepare the capital ahead of the peak rainy season. The exercise, which involved the National Disaster Management Organisation (NADMO...

Poor road to dump site leaves tricycle operators stranded

Poor road conditions leading to the only waste disposal site at Lower McCarthy Hill in the Weija Gbawe Municipality have left thousands of refuse tricycle operators stranded, disrupting waste collection in parts of Accra. The situation has resulted in long queues of tricycles along the Leprosarium stretch of the Mallam-Kasoa Highway...

Newsletter

Don't miss

“Take the Stairs”: Adekunle Gold Shares Advice for Creatives at The Macallan Partnership Celebration

Award-winning singer and songwriter Adekunle Gold has urged creatives to remain committed to their craft, even when recognition feels out of reach, sharing a powerful reflection on patience, excellence and… The post “Take the Stairs”: Adekunle Gold Shares Advice for Creatives at The Macallan Partnership Celebration appeared first on Nigerian Entertainment Today...

Bernie Sanders Backs Justin J. Pearson, House Candidate at the Heart of Tennessee Voting Rights Fight

Pearson challenged the last Tennessee Democrat in the House. Now he’s up against the threat of total GOP control. The post Bernie Sanders Backs Justin J. Pearson, House Candidate at the Heart of Tennessee Voting Rights Fight appeared first on The Intercept...

Multi-agency flood control exercise gains momentum

A large-scale flood control and drainage desilting campaign, spearheaded by Zoomlion Ghana Limited and its partners, has been intensified across Accra as stakeholders step up efforts to prepare the capital ahead of the peak rainy season. The exercise, which involved the National Disaster Management Organisation (NADMO...

Poor road to dump site leaves tricycle operators stranded

Poor road conditions leading to the only waste disposal site at Lower McCarthy Hill in the Weija Gbawe Municipality have left thousands of refuse tricycle operators stranded, disrupting waste collection in parts of Accra. The situation has resulted in long queues of tricycles along the Leprosarium stretch of the Mallam-Kasoa Highway...

“This is why I don’t attend parties” – Woman leaves guests stunned with her electrifying dance performance at a party (Watch)

A woman turned heads online after revealing why she rarely attends parties: her unique dancing style. She often avoids social gatherings because she believes her dance moves can be embarrassing. She jokingly admitted that there are times she prefers to remain seated and quiet rather than draw attention to herself on the dance floor...

Want Your Business to Be Seen Everywhere? Meet Tonia Ryan, Creator of Fix Your Search

Some people are good at their jobs. Then there is Tonia Ryan, who has turned “getting found online” into something close to magic. She is the creator of Fix Your Search, and if you have ever wondered why some businesses pop up everywhere while others seem invisible...

Grey Business processes $61 million as stablecoins dominate payments

Grey Business enables startups and SMEs to open US Dollar (USD) corporate accounts, send and receive international payments, convert currencies, and transact using stablecoins such as USDC and USDT...

Utah Marketers to Host Free Business Networking Event in Layton on June 24

The custom web design company is hosting free monthly networking events for Northern Utah business leaders, with the next event scheduled for June 24 from 4 to 6 p.m. Utah Marketers is hosting a free local business networking event on June 24 from 4 to 6 p.m. at the company’s Layton office. The event is