Threat actor names can sound simple. LockBit. Fancy Bear. BlackCat. Scattered Spider. Anonymous Sudan. Each name gives the impression of a clear group with a defined identity.
In threat intelligence, however, the name is rarely the whole story.
Some names are chosen by attackers. Others are assigned by researchers, security vendors, governments, or public databases. One name may represent a ransomware brand, a hacktivist identity, a research label, a campaign, a malware family, or an activity cluster observed across different incidents.
For security professionals, this distinction is important. Confusing attacker created identities with researcher assigned labels can lead teams to overestimate certainty, miss relationships between aliases, or focus on the name instead of the behavior behind it.
Who Gets to Name a Threat Actor?
Threat actor naming usually starts with either visibility or investigation.
When a group wants attention, it may introduce itself publicly through a leak site, Telegram channel, ransom note, cybercrime forum, or public claim of responsibility. This is common among ransomware groups and hacktivist collectives because recognition can support their goals. The name becomes part of how they communicate, recruit, intimidate, or claim credit.
Researcher assigned names start from a different place. Analysts may see repeated malicious activity across victims, environments, tools, infrastructure, or techniques and need a way to track it. The label helps connect incidents, compare findings, and communicate risk to defenders. . MITRE ATT&CK describes groups as activity clusters tracked by a common name in the security community, and notes that different organizations may use different names for similar activity.
In other words, attacker chosen names are often public identities. Researcher assigned names are often analytical shortcuts for tracking behavior.
When the Name Becomes the Brand
For ransomware groups, a name can carry business value. It can make the group recognizable to victims, affiliates, journalists, and other criminals. A short, memorable name can help a group build credibility in a crowded criminal economy.
Reputation also supports the pressure campaign. If victims believe a group has leaked data before, disrupted large organizations, or followed through on threats, the name can increase fear during negotiations. The brand becomes part of the extortion strategy.
Hacktivist groups use names in a different way. Their names often point to a cause, region, ideology, or target. The goal is not only technical disruption, but public visibility. A name helps frame the attack as a political or social statement and gives supporters, media, and targets a clear identity to follow.
This is why attacker chosen names should be read as messaging, not just identification. The name tells defenders how the group wants to be seen, but the behavior behind the name is what shows how the group operates.
Researcher Assigned Names and Activity Clusters
Researcher assigned names follow a different logic. Analysts use names to turn scattered evidence into something defenders can track, compare, and discuss.
A group name may be based on repeated infrastructure, shared tools, malware families, command and control patterns, IOCs (indicators of compromise), targeting, victimology, or TTPs (tactics, techniques, and procedures). The name gives analysts a way to connect new observations to older activity and communicate those findings to defenders.
This does not always mean researchers know the real people behind the activity. In many cases, the name describes a cluster of behavior rather than a confirmed organization.
Different vendors also use different naming systems. One company may group activity by suspected origin. Another may use themes such as animals, weather, or other internal classifications. The result is a threat intelligence landscape where names help organize activity, while aliases and overlapping labels can create confusion.
APT29 shows how quickly naming can become complicated. A single activity cluster can collect labels from vendors, public reporting, incident response investigations, and threat intelligence databases. Some names refer to the broader actor. Others refer to related campaigns, malware, or activity later connected to the same cluster.
| APT29 related name | Used by or commonly associated source | Relationship to APT29 |
| APT29 (Primary Name) | MITRE ATT&CK, public threat intelligence community | MITRE tracks APT29 as a Russia linked activity cluster and maps related names under “Associated Groups.” |
| Cozy Bear | CrowdStrike and wider public reporting | Commonly used public name for APT29 related activity. |
| The Dukes | F-Secure | Earlier name associated with APT29 related espionage activity. |
| NOBELIUM | Microsoft | Microsoft used NOBELIUM for activity associated with APT29, including SolarWinds related activity. |
| Midnight Blizzard | Microsoft | Current Microsoft weather themed name for the actor formerly tracked as NOBELIUM. |
| UNC2452 | Mandiant | Mandiant used UNC2452 for the SolarWinds related activity cluster and later merged it into APT29. |
| SolarStorm | Palo Alto Networks Unit 42 | Used in reporting around SolarWinds related activity. |
| G0016, BlueBravo, CloudLook, Minidionis, TEMP.Monkeys, ATK 7, Iron Hemlock, UNC3524, Yttrium, NobleBaron, Dark Halo, Cranefly, Iron Ritual, Cloaked Ursa, SilverFish, Grizzly Steppe, Operation “StellarParticle,” CozyCar, Blue Dev 5, CozyDuke, Office Monkeys, StellarParticle, Operation “Office monkeys,” Operation “Ghost,” Solar Phoenix, Group 100, ITG11 | Check Point Exposure Management | Additional names and related labels connected to APT29 in Check Point Exposure Management’s Threat Actor Intelligence. |
Explore how Check Point Exposure Management helps security teams identify exposed assets, exploitable weaknesses, and attack paths before attackers can use them.
Why One Group Can Have Many Names
A single threat actor can appear under several names because different teams see different parts of the same picture. One vendor may observe phishing infrastructure. Another may analyze malware samples. Another may investigate incident response data. Public databases then attempt to map these aliases so defenders can understand when different names may refer to related activity.
Rebrands add another layer. Ransomware groups may change names after law enforcement attention, sanctions, leaks, internal conflict, or damage to their reputation. The new name can create distance from the old brand while allowing the group to continue using familiar tools, partners, or tactics.
Ransomware analysis often includes profiling a group’s ideology, leadership, technologies, TTPs, infrastructure, tool quality, and relationships with other groups. Cross checking code samples can also help analysts assess whether overlap points to a rebrand, an offshoot, or leaked code reused by several groups.
Rebrand, Offshoot, or Reused Code?
Shared code does not automatically prove that two groups are the same. Malware can be sold, leaked, reused, modified, or shared through affiliate programs. The same applies to infrastructure, ransom note templates, negotiation styles, and tooling.
Analysts need context. If a new group uses code linked to an older ransomware operation, researchers may compare timing, infrastructure, victim patterns, affiliates, language, behavior, and public claims. A leaked builder used by several unrelated actors tells a different story than a private toolset carried from one brand to another.
This is where naming becomes careful judgment. The goal is to avoid treating every overlap as proof while still recognizing when a new name is connected to older activity.
From Threat Actor Name to Action
Threat actor names help security teams organize intelligence, follow campaigns, understand targeting, and communicate risk. The name gives defenders a starting point, while the real value comes from the evidence behind it.
Security Professionals need to look past the label and examine the behaviors, tools, vulnerabilities, exposed systems, identities, infrastructure, and attack paths associated with that actor or cluster. A ransomware brand, hacktivist identity, or researcher assigned name becomes useful when it helps security teams understand how the activity could affect their environment.
Exposure management brings threat intelligence into focus. It helps security professionals move from a name to the assets, weaknesses, identities, and paths that could create risk in their own environment. Threat actor names help explain who may be behind the activity. Exposure management shows whether that activity can reach the organization, where it could move next, which fixes should come first, and how to apply those fixes safely.
Schedule a demo to see how Check Point Exposure Management turns threat intelligence into prioritized action.
