@@ -6,16 +6,16 @@ ms.service: defender-xdr
6
6
ms.mktglfcycl : secure
7
7
ms.sitesec : library
8
8
ms.localizationpriority : medium
9
- ms.author : vpattnaik
10
- author : diannegali
9
+ ms.author : diannegali
10
+ author : vpattnaik
11
11
manager : dansimp
12
12
audience : ITPro
13
13
ms.collection :
14
14
- m365-security
15
15
- tier2
16
16
ms.topic : conceptual
17
17
search.appverid : met150
18
- ms.date : 06/12 /2024
18
+ ms.date : 08/19 /2024
19
19
---
20
20
21
21
# How Microsoft names threat actors
@@ -54,6 +54,7 @@ Use the following reference table to understand how our previously publicly disc
54
54
55
55
| Threat actor name| Previous name| Origin/Threat| Other names|
56
56
| :---:| :---:| :---:| :---:|
57
+ | Antique Typhoon| Storm-0558| China||
57
58
| Aqua Blizzard| ACTINIUM| Russia| UNC530, Primitive Bear, Gamaredon|
58
59
| Blue Tsunami|| Private sector offensive actor| Black Cube|
59
60
| Brass Typhoon| BARIUM| China| APT41|
@@ -97,7 +98,7 @@ Use the following reference table to understand how our previously publicly disc
97
98
| Night Tsunami| DEV-0336| Private sector offensive actor| NSO Group|
98
99
| Nylon Typhoon| NICKEL| China| ke3chang, APT15, Vixen Panda|
99
100
| Octo Tempest| Storm-0875| Financially motivated| 0ktapus, Scattered Spider, UNC3944|
100
- | Onyx Sleet| PLUTONIUM| North Korea| Silent Chollima, Andariel, DarkSeoul|
101
+ | Onyx Sleet| PLUTONIUM| North Korea| APT45, Silent Chollima, Andariel, DarkSeoul|
101
102
| Opal Sleet| OSMIUM| North Korea| Konni|
102
103
| Peach Sandstorm| HOLMIUM| Iran| APT33, Refined Kitten|
103
104
| Pearl Sleet| DEV-0215 (LAWRENCIUM)| North Korea||
@@ -110,13 +111,15 @@ Use the following reference table to understand how our previously publicly disc
110
111
| Purple Typhoon| POTASSIUM| China| APT10, Cloudhopper, MenuPass|
111
112
| Raspberry Typhoon| RADIUM| China| APT30, LotusBlossom|
112
113
| Ruby Sleet| CERIUM| North Korea||
114
+ | Ruza Flood| Storm-1099| Russia, Influence operations||
113
115
| Salmon Typhoon| SODIUM| China| APT4, Maverick Panda|
114
116
| Sangria Tempest| ELBRUS| Financially motivated| Carbon Spider, FIN7|
115
117
| Sapphire Sleet| COPERNICIUM| North Korea| Genie Spider, BlueNoroff|
116
118
| Seashell Blizzard| IRIDIUM| Russia| APT44, Sandworm|
117
119
| Secret Blizzard| KRYPTON| Russia| Venomous Bear, Turla, Snake|
120
+ | Sefid Flood| Storm-1364| Iran, Influence operations||
118
121
| Silk Typhoon| HAFNIUM| China||
119
- | Smoke Sandstorm| BOHRIUM| Iran||
122
+ | Smoke Sandstorm| BOHRIUM| Iran| UNC1549 |
120
123
| Spandex Tempest| CHIMBORAZO| Financially motivated| TA505|
121
124
| Star Blizzard| SEABORGIUM| Russia| Callisto, Reuse Team|
122
125
| Storm-0062|| China| DarkShadow, Oro0lxy|
@@ -125,23 +128,24 @@ Use the following reference table to understand how our previously publicly disc
125
128
| Storm-0257|| Group in development| UNC1151|
126
129
| Storm-0324|| Financially motivated| TA543, Sagrid|
127
130
| Storm-0381|| Financially motivated||
131
+ | Storm-0501|| Group in development||
132
+ | Storm-0506|| Group in development||
128
133
| Storm-0530|| North Korea| H0lyGh0st|
129
134
| Storm-0539|| Financially motivated| Atlas Lion|
130
- | Storm-0558|| China||
131
135
| Storm-0569|| Financially motivated||
132
136
| Storm-0587|| Russia| SaintBot, Saint Bear, TA471|
133
137
| Storm-0744|| Financially motivated||
134
138
| Storm-0784|| Iran||
135
139
| Storm-0829|| Group in development| Nwgen Team|
136
140
| Storm-0835|| Group in development| EvilProxy|
137
141
| Storm-0842|| Iran||
142
+ | Storm-0844|| Group in development||
138
143
| Storm-0861|| Iran||
139
144
| Storm-0867|| Egypt| Caffeine|
140
145
| Storm-0971|| Financially motivated| (Merged into Octo Tempest)|
141
146
| Storm-0978|| Group in development| RomCom, Underground Team|
142
147
| Storm-1044|| Financially motivated| Danabot|
143
148
| Storm-1084|| Iran| DarkBit|
144
- | Storm-1099|| Russia||
145
149
| Storm-1101|| Group in development| NakedPages|
146
150
| Storm-1113|| Financially motivated||
147
151
| Storm-1133|| Palestinian Authority||
@@ -151,17 +155,22 @@ Use the following reference table to understand how our previously publicly disc
151
155
| Storm-1283|| Group in development||
152
156
| Storm-1286|| Group in development||
153
157
| Storm-1295|| Group in development| Greatness|
154
- | Storm-1364|| Iran||
155
- | Storm-1376|| China, Influence operations||
156
158
| Storm-1516|| Russia, Influence operations||
157
159
| Storm-1567|| Financially motivated| Akira|
158
160
| Storm-1575|| Group in development| Dadsec|
161
+ | Storm-1660|| Iran, Influence operations||
159
162
| Storm-1674|| Financially motivated||
160
163
| Storm-1679|| Russia, Influence operations||
164
+ | Storm-1804|| Iran, Influence operations||
165
+ | Storm-1805|| Iran, Influence operations||
161
166
| Storm-1811|| Financially motivated||
167
+ | Storm-1841|| Russia, Influence operations||
162
168
| Storm-1849|| China| UAT4356|
169
+ | Storm-1852|| Group in development||
170
+ | Storm-2035|| Iran, Influence operations||
163
171
| Strawberry Tempest|| Financially motivated| LAPSUS$|
164
172
| Sunglow Blizzard|| Russia||
173
+ | Taizi Flood| Storm-1376| China, Influence operations| Spamouflage, Dragonbridge|
165
174
| Tomato Tempest| SPURR| Financially motivated| Vatet|
166
175
| Vanilla Tempest| DEV-0832| Financially motivated||
167
176
| Velvet Tempest| DEV-0504| Financially motivated||
0 commit comments