How Microsoft names threat actors

Microsoft has shifted to a new naming taxonomy for threat actors aligned with the theme of weather. With the new taxonomy, we intend to bring better clarity to customers and other security researchers already confronted with an overwhelming amount of threat intelligence data and offer a more organized, articulate, and easy way to reference threat actors so that organizations can better prioritize and protect themselves.



Nation-state actors based on Microsoft naming

Microsoft categorizes threat actors into five key groups:

Nation-state actors: cyber operators acting on behalf of or directed by a nation/state-aligned program, irrespective of whether for espionage, financial gain, or retribution. Microsoft has observed that most nation state actors continue to focus operations and attacks on government agencies, intergovernmental organizations, non-governmental organizations, and think tanks for traditional espionage or surveillance objectives.

Financially motivated actors: cyber campaigns/groups directed by a criminal organization/person with motivations of financial gain and haven’t been associated with high confidence to a known non-nation state or commercial entity. This category includes ransomware operators, business email compromise, phishing, and other groups with purely financial or extortion motivations.

Private sector offensive actors (PSOAs): cyber activity led by commercial actors that are known/legitimate legal entities, that create and sell cyberweapons to customers who then select targets and operate the cyberweapons. These tools threaten many global human rights efforts, as they have been observed targeting and surveilling dissidents, human rights defenders, journalists, civil society advocates, and other private citizens.

Influence operations: information campaigns communicated online or offline in a manipulative fashion to shift perceptions, behaviors, or decisions by target audiences to further a group or a nation’s interests and objectives.

Groups in development: a temporary designation given to an unknown, emerging, or developing threat activity that allows Microsoft to track it as a discrete set of information until we can reach high confidence about the origin or identity of the actor behind the operation. Once criteria are met, a group in development is converted to a named actor or merged into existing names.

In our new taxonomy, a weather event or family name represents one of the above categories. In the case of nation-state actors, we have assigned a family name to a country of origin tied to attribution, like Typhoon indicates origin or attribution to China. For other actors, the family name represents a motivation. For example, Tempest indicates financially motivated actors. Threat actors within the same weather family are given an adjective to distinguish actor groups with distinct tactics, techniques, and procedures (TTPs), infrastructure, objectives, or other identified patterns. For groups in development, where there is a newly discovered, unknown, emerging, or developing cluster of threat activity, we use a temporary designation of Storm and a four-digit number, allowing us to track it as a unique set of information until we can reach high confidence about the origin or identity of the actor behind the operation.

The table below shows how the new family names map to a sampling of the threat actors that we track.

Actor categoryTypeFamily name
Nation-stateChina
Iran
Lebanon
North Korea
Russia
South Korea
Turkey
Vietnam
Typhoon
Sandstorm
Rain
Sleet
Blizzard
Hail
Dust
Cyclone
Financially motivatedFinancially motivatedTempest
Private sector offensive actorsPSOAsTsunami
Influence operationsInfluence operationsFlood
Groups in developmentGroups in developmentStorm

Use the following reference table below to understand how our previously publicly disclosed old threat actor names translate to our new taxonomy.

Previous nameNew nameOrigin/ThreatOther names
ACTINIUMAqua BlizzardRussiaUNC530, Primitive Bear, Gamaredon
AMERICIUMPink SandstormIranAgrius, Deadwood, BlackShadow, SharpBoys
BARIUMBrass TyphoonChinaAPT41
BISMUTHCanvas CycloneVietnamAPT32, OceanLotus
BOHRIUMSmoke SandstormIran
BROMINEGhost BlizzardRussiaEnergetic Bear, Crouching Yeti
CERIUMRuby SleetNorth Korea
CHIMBORAZOSpandex TempestFinancially motivatedTA505
CHROMIUMCharcoal TyphoonChinaControlX
COPERNICIUMSapphire SleetNorth KoreaGenie Spider, BlueNoroff
CURIUMCrimson SandstormIranTA456, Tortoise Shell
DUBNIUMZigzag HailSouth KoreaDark Hotel, Tapaoux
ELBRUSSangria TempestFinancially motivatedCarbon Spider, FIN7
EUROPIUMHazel SandstormIranCobalt Gypsy, APT34, OilRig
GADOLINIUMGingham TyphoonChinaAPT40, Leviathan, TEMP.Periscope, Kryptonite Panda
GALLIUMGranite TyphoonChina
HAFNIUMSilk TyphoonChina
HOLMIUMPeach SandstormIranAPT33, Refined Kitten
IRIDIUMSeashell BlizzardRussiaSandworm
KNOTWEEDDenim TsunamiPrivate sector offensive actorDSIRF
KRYPTONSecret BlizzardRussiaVenomous Bear, Turla, Snake
LAWRENCIUMPearl SleetNorth Korea
MANGANESEMulberry TyphoonChinaAPT5, Keyhole Panda, TABCTENG
MERCURYMango SandstormIranMuddyWater, SeedWorm, Static Kitten, TEMP.Zagros
NEPTUNIUMCotton SandstormIranVice Leaker
NICKELNylon TyphoonChinake3chang, APT15, Vixen Panda
NOBELIUMMidnight BlizzardRussiaAPT29, Cozy Bear
OSMIUMOpal SleetNorth KoreaKonni
PARINACOTAWine TempestFinancially motivatedWadhrama
PHOSPHORUSMint SandstormIranAPT35, Charming Kitten
PLUTONIUMOnyx SleetNorth KoreaSilent Chollima, Andariel, DarkSeoul
POLONIUMPlaid RainLebanon
RADIUMRaspberry TyphoonChinaAPT30, LotusBlossom
RUBIDIUMLemon SandstormIranFox Kitten, UNC757, PioneerKitten
SEABORGIUMStar BlizzardRussiaCallisto, Reuse Team
SILICONMarbled DustTurkeySea Turtle
SOURGUMCaramel TsunamiPrivate sector offensive actorCandiru
SPURRTomato TempestFinancially motivatedVatet
STRONTIUMForest BlizzardRussiaAPT28, Fancy Bear
TAALCamouflage TempestFinancially motivatedFIN6, Skeleton Spider
THALLIUMEmerald SleetNorth KoreaKimsuky, Velvet Chollima
ZINCDiamond SleetNorth KoreaLabyrinth Chollima, Lazarus
ZIRCONIUMViolet TyphoonChinaAPT31
Previous nameNew nameOrigin/ThreatOther names
DEV-0146Pumpkin SandstormIranZeroCleare
DEV-0193Periwinkle TempestFinancially motivatedWizard Spider, UNC2053
DEV-0196Carmine TsunamiPrivate sector offensive actorQuaDream
DEV-0198 (NEPTUNIUM)Cotton SandstormIranVice Leaker
DEV-0206Mustard TempestFinancially motivatedPurple Vallhund
DEV-0215 (LAWRENCIUM)Pearl SleetNorth Korea
DEV-0227 (AMERICIUM)Pink SandstormIranAgrius, Deadwood, BlackShadow, SharpBoys
DEV-0228Cuboid SandstormIran
DEV-0234Lilac TyphoonChina
DEV-0237Pistachio TempestFinancially motivatedFIN12
DEV-0243Manatee TempestFinancially motivatedEvilCorp, UNC2165, Indrik Spider
DEV-0257Storm-0257Group in developmentUNC1151
DEV-0322Circle TyphoonChina
DEV-0336Night TsunamiPrivate sector offensive actorNSO Group
DEV-0343Gray SandstormIran
DEV-0401Cinnamon TempestFinancially motivatedEmperor Dragonfly, Bronze Starlight
DEV-0500Marigold SandstormIranMoses Staff
DEV-0504Velvet TempestFinancially motivated
DEV-0530Storm-0530North KoreaH0lyGh0st
DEV-0537Strawberry TempestFinancially motivatedLAPSUS$
DEV-0586Cadet BlizzardRussia
DEV-0605Wisteria TsunamiPrivate sector offensive actorCyberRoot
DEV-0665Sunglow BlizzardRussia
DEV-0796Phlox TempestFinancially motivatedClickPirate, Chrome Loader, Choziosi loader
DEV-0832Vanilla TempestFinancially motivated
DEV-0950Lace TempestFinancially motivatedFIN11, TA505

Read our announcement about the new taxonomy for more information: https://aka.ms/threatactorsblog

Putting intelligence into the hands of security professionals

Intel profiles in Microsoft Defender Threat Intelligence bring crucial threat actor insights directly into defenders’ hands so that they can get the context they need as they prepare for and respond to threats.

Additionally, to further operationalize the threat intelligence you get from Microsoft, the Microsoft Defender Threat Intelligence Intel Profiles API provides the most up-to-date threat actor infrastructure visibility in the industry today, enabling threat intelligence and security operations (SecOps) teams to streamline their advanced threat hunting and analysis workflows. Learn more about this API in the documentation: Use the threat intelligence APIs in Microsoft Graph (preview).

Resources

Use the following query on Microsoft 365 Defender and other Microsoft security products supporting the Kusto query language (KQL) to get information about a threat actor using the old name, new name, or industry name:

let TANames = externaldata(PreviousName: string, NewName: string, Origin: string, OtherNames: dynamic)[@"https://raw.githubusercontent.com/microsoft/mstic/master/PublicFeeds/ThreatActorNaming/MicrosoftMapping.json"] with(format="multijson", ingestionMapping='[{"Column":"PreviousName","Properties":{"Path":"$.Previous name"}},{"Column":"NewName","Properties":{"Path":"$.New name"}},{"Column":"Origin","Properties":{"Path":"$.Origin/Threat"}},{"Column":"OtherNames","Properties":{"Path":"$.Other names"}}]'); 
let GetThreatActorAlias = (Name: string) { 
TANames 
| where Name =~ NewName or Name =~ PreviousName or OtherNames has Name 
}; 
GetThreatActorAlias("ZINC")

The following files containing the comprehensive mapping of old threat actor names with their new names are also available:

Read More
Alejandro Wiers

Latest

Sleater-Kinney and Liz Phair Unite for Co-Headlining Tour

Music Sleater-Kinney and Liz Phair are hitting the road...

Foodies! Get Ready to Feast at GTCO Food and Drink Festival 2026

Music Food lovers, it is almost that time again....

Shazmicsoul – Next 2 U Ft Floyd Rhythmic

MusicDOWNLOAD MP3 SONG...

Newsletter

Don't miss

Sleater-Kinney and Liz Phair Unite for Co-Headlining Tour

Music Sleater-Kinney and Liz Phair are hitting the road...

Foodies! Get Ready to Feast at GTCO Food and Drink Festival 2026

Music Food lovers, it is almost that time again....

Shazmicsoul – Next 2 U Ft Floyd Rhythmic

MusicDOWNLOAD MP3 SONG...

“Fame Has Downsides” – Davido Opens Up on Painful Family Struggles

MusicDavido has spoken about the negative side of...

Jury acquits 2 business executives of bribing Navy admiral for government contract

A federal jury has acquitted two business executives of charges that they conspired to bribe a retired four-star U.S. Navy admiral, who is now serving a six-year prison sentence for his conviction on corruption charges By MICHAEL KUNZELMAN Associated Press WASHINGTON -- A federal jury has acquitted two business executives of charges that they conspired

US Business Leaders Optimistic About China Cooperation, Emphasize Importance of Chinese Market

© 2026 China Money Network. All Rights Reserved. Disclaimer: The views, opinions, forecasts, and statements made by our hosts and guests are the personal views of those respective individuals and may or may not be either endorsed or accepted by China Money Network Limited or the companies with which these individuals are employed.

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they