@@ -17,7 +17,7 @@ ms.custom:
1717- cx-ti
1818ms.topic : conceptual
1919search.appverid : met150
20- ms.date : 09/25 /2024
20+ ms.date : 12/03 /2024
2121---
2222
2323# How Microsoft names threat actors
@@ -121,12 +121,13 @@ Use the following reference table to understand how our previously publicly disc
121121| Seashell Blizzard| IRIDIUM| Russia| APT44, Sandworm|
122122| Secret Blizzard| KRYPTON| Russia| Venomous Bear, Turla, Snake|
123123| Sefid Flood| Storm-1364| Iran, Influence operations||
124+ | Shadow Typhoon| Storm-0062| China| DarkShadow, Oro0lxy|
124125| Silk Typhoon| HAFNIUM| China||
125126| Smoke Sandstorm| BOHRIUM| Iran| UNC1549|
126127| Spandex Tempest| CHIMBORAZO| Financially motivated| TA505|
127128| [ Star Blizzard] ( https://www.microsoft.com/en-us/security/blog/2023/12/07/star-blizzard-increases-sophistication-and-evasion-in-ongoing-attacks/ ) | SEABORGIUM| Russia| Callisto, Reuse Team|
128- | Storm-0062|| China| DarkShadow, Oro0lxy|
129129| Storm-0133|| Iran| LYCEUM, HEXANE|
130+ | Storm-0156|| Pakistan||
130131| Storm-0216|| Financially motivated| Twisted Spider, UNC2198|
131132| Storm-0257|| Group in development| UNC1151|
132133| Storm-0324|| Financially motivated| TA543, Sagrid|
@@ -137,14 +138,15 @@ Use the following reference table to understand how our previously publicly disc
137138| Storm-0539|| Financially motivated| Atlas Lion|
138139| Storm-0569|| Financially motivated||
139140| Storm-0587|| Russia| SaintBot, Saint Bear, TA471|
140- | Storm-0744 || Financially motivated ||
141+ | Storm–0593 || Group in development ||
141142| Storm-0784|| Iran||
142143| Storm-0829|| Group in development| Nwgen Team|
143144| Storm-0835|| Group in development| EvilProxy|
144145| Storm-0842|| Iran||
145146| Storm-0844|| Group in development||
146147| Storm-0861|| Iran||
147148| Storm-0867|| Egypt| Caffeine|
149+ | [ Storm-0940] ( https://www.microsoft.com/en-us/security/blog/2024/10/31/chinese-threat-actor-storm-0940-uses-credentials-from-password-spray-attacks-from-a-covert-network/ ) || China||
148150| Storm-0971|| Financially motivated| (Merged into Octo Tempest)|
149151| [ Storm-0978] ( https://www.microsoft.com/en-us/security/blog/2023/07/11/storm-0978-attacks-reveal-financial-and-espionage-motives/ ) || Group in development| RomCom, Underground Team|
150152| Storm-1044|| Financially motivated| Danabot|
@@ -167,17 +169,21 @@ Use the following reference table to understand how our previously publicly disc
167169| Storm-1804|| Iran, Influence operations||
168170| Storm-1805|| Iran, Influence operations||
169171| [ Storm-1811] ( https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/ ) || Financially motivated||
170- | Storm-1841 || Russia, Influence operations ||
172+ | Storm-1837 || Russia||
171173| Storm-1849|| China| UAT4356|
172174| Storm-1852|| Group in development||
175+ | Storm-1919|| Group in development||
173176| Storm-2035|| Iran, Influence operations||
177+ | Storm-2049|| Group in development||
178+ | [ Storm-2077] ( https://www.microsoft.com/en-us/security/blog/2024/11/22/microsoft-shares-latest-intelligence-on-north-korean-and-chinese-threat-actors-at-cyberwarcon/#storm-2077 ) || China| TAG-100|
174179| Strawberry Tempest|| Financially motivated| LAPSUS$|
175180| Sunglow Blizzard|| Russia||
176181| Taizi Flood| Storm-1376| China, Influence operations| Spamouflage, Dragonbridge|
177182| Tomato Tempest| SPURR| Financially motivated| Vatet|
178183| [ Vanilla Tempest] ( https://www.microsoft.com/en-us/security/blog/2022/10/25/dev-0832-vice-society-opportunistic-ransomware-campaigns-impacting-us-education-sector/ ) | DEV-0832| Financially motivated||
179184| Velvet Tempest| DEV-0504| Financially motivated||
180185| Violet Typhoon| ZIRCONIUM| China| APT31|
186+ | Volga Flood| Storm-1841| Russia, Influence operations||
181187| [ Volt Typhoon] ( https://www.microsoft.com/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques ) || China| BRONZE SILHOUETTE, VANGUARD PANDA|
182188| Wine Tempest| PARINACOTA| Financially motivated| Wadhrama|
183189| Wisteria Tsunami| DEV-0605| Private sector offensive actor| CyberRoot|
0 commit comments