Skip to content

Commit 89a7962

Browse files
authored
Update microsoft-threat-actor-naming.md
1 parent ce0748b commit 89a7962

File tree

1 file changed

+5
-5
lines changed

1 file changed

+5
-5
lines changed

defender-xdr/microsoft-threat-actor-naming.md

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ ms.custom:
1717
- cx-ti
1818
ms.topic: conceptual
1919
search.appverid: met150
20-
ms.date: 12/03/2024
20+
ms.date: 12/05/2024
2121
---
2222

2323
# How Microsoft names threat actors
@@ -42,7 +42,7 @@ In our new taxonomy, a weather event or *family name* represents one of the abov
4242

4343
Threat actors within the same weather family are given an adjective to distinguish actor groups with distinct tactics, techniques, and procedures (TTPs), infrastructure, objectives, or other identified patterns. For groups in development, we use a temporary designation of Storm and a four-digit number where there is a newly discovered, unknown, emerging, or developing cluster of threat activity.
4444

45-
The table shows how the new family names map to the threat actors that we track.
45+
The table below shows how the family names map to the threat actors that we track.
4646

4747
|Actor category|Type|Family name|
4848
|:---:|:---:|:---:|
@@ -52,7 +52,7 @@ The table shows how the new family names map to the threat actors that we track.
5252
|Influence operations|Influence operations|Flood|
5353
|Groups in development|Groups in development|Storm|
5454

55-
Use the following reference table to understand how our previously publicly disclosed old threat actor names translate to our new taxonomy.
55+
The table below lists publicly disclosed threat actor names with their previous names, origin or threat type, and corresponding names used by other security vendors.
5656

5757
|Threat actor name|Previous name|Origin/Threat|Other names|
5858
|:---:|:---:|:---:|:---:|
@@ -119,15 +119,15 @@ Use the following reference table to understand how our previously publicly disc
119119
|Sangria Tempest|ELBRUS|Financially motivated|Carbon Spider, FIN7|
120120
|Sapphire Sleet|COPERNICIUM|North Korea|Genie Spider, BlueNoroff|
121121
|Seashell Blizzard|IRIDIUM|Russia|APT44, Sandworm|
122-
|Secret Blizzard|KRYPTON|Russia|Venomous Bear, Turla, Snake|
122+
|[Secret Blizzard](https://www.microsoft.com/en-us/security/blog/2024/12/04/frequent-freeloader-part-i-secret-blizzard-compromising-storm-0156-infrastructure-for-espionage/)|KRYPTON|Russia|Venomous Bear, Turla, Snake|
123123
|Sefid Flood|Storm-1364|Iran, Influence operations||
124124
|Shadow Typhoon|Storm-0062|China|DarkShadow, Oro0lxy|
125125
|Silk Typhoon|HAFNIUM|China||
126126
|Smoke Sandstorm|BOHRIUM|Iran|UNC1549|
127127
|Spandex Tempest|CHIMBORAZO|Financially motivated|TA505|
128128
|[Star Blizzard](https://www.microsoft.com/en-us/security/blog/2023/12/07/star-blizzard-increases-sophistication-and-evasion-in-ongoing-attacks/)|SEABORGIUM|Russia|Callisto, Reuse Team|
129129
|Storm-0133||Iran|LYCEUM, HEXANE|
130-
|Storm-0156||Pakistan||
130+
|[Storm-0156](https://www.microsoft.com/en-us/security/blog/2024/12/04/frequent-freeloader-part-i-secret-blizzard-compromising-storm-0156-infrastructure-for-espionage/)||Pakistan||
131131
|Storm-0216||Financially motivated|Twisted Spider, UNC2198|
132132
|Storm-0257||Group in development|UNC1151|
133133
|Storm-0324||Financially motivated|TA543, Sagrid|

0 commit comments

Comments
 (0)