@@ -17,7 +17,7 @@ ms.custom:
1717- cx-ti
1818ms.topic : article
1919search.appverid : met150
20- ms.date : 6/2 /2025
20+ ms.date : 7/10 /2025
2121---
2222
2323# How Microsoft names threat actors
@@ -74,13 +74,14 @@ The following table lists publicly disclosed threat actor names with their origi
7474| Cinnamon Tempest| China, Financially motivated| DEV-0401, HighGround|
7575| Circle Typhoon| China| DEV-0322, EMISSARY PANDA, APT6, APT27|
7676| [ Citrine Sleet] ( https://www.microsoft.com/en-us/security/blog/2024/08/30/north-korean-threat-actor-citrine-sleet-exploiting-chromium-zero-day/ ) | North Korea| Storm-0139, Storm-1222, LABYRINTH CHOLLIMA|
77+ | Copper Typhoon| China| Tonto Team, Earth Akhlut, Sharp-R|
7778| Cotton Sandstorm| Iran| NEPTUNIUM, HAYWIRE KITTEN, Vice Leaker|
7879| [ CovertNetwork-1658] ( https://www.microsoft.com/en-us/security/blog/2024/10/31/chinese-threat-actor-storm-0940-uses-credentials-from-password-spray-attacks-from-a-covert-network/ ) | Covert network| ORB07|
7980| Crescent Typhoon| China| CESIUM|
8081| Crimson Sandstorm| Iran| CURIUM, IMPERIAL KITTEN, Tortoise Shell, HOUSEBLEND, TA456|
8182| Cuboid Sandstorm| Iran| DEV-0228, IMPERIAL KITTEN|
8283| [ Denim Tsunami] ( https://www.microsoft.com/en-us/security/blog/2022/07/27/untangling-knotweed-european-private-sector-offensive-actor-using-0-day-exploits/ ) | Austria, Private sector offensive actor| DEV-0291|
83- | [ Diamond Sleet] ( https://www.microsoft.com/en-us/security/blog/tag/ diamond-sleet-zinc / ) | North Korea| ZINC, LABYRINTH CHOLLIMA, Black Artemis, Lazarus|
84+ | [ Diamond Sleet] ( https://www.microsoft.com/en-us/security/blog/2023/11/22/ diamond-sleet-supply-chain-compromise-distributes-a-modified-cyberlink-installer / ) | North Korea| ZINC, LABYRINTH CHOLLIMA, Black Artemis, Lazarus|
8485| Emerald Sleet| North Korea| THALLIUM, VELVET CHOLLIMA, RGB-D5, Black Banshee, Kimsuky, Greendinosa|
8586| Fallow Squall| Singapore| PLATINUM, PARASITE, RUBYVINE, GINGERSNAP|
8687| [ Flax Typhoon] ( https://www.microsoft.com/en-us/security/blog/2023/08/24/flax-typhoon-using-legitimate-software-to-quietly-access-taiwanese-organizations/ ) | China| Storm-0919, ETHEREAL PANDA|
@@ -89,11 +90,12 @@ The following table lists publicly disclosed threat actor names with their origi
8990| Gingham Typhoon| China| GADOLINIUM, KRYPTONITE PANDA, TEMP.Periscope, Leviathan, JJDoor, APT40, Feverdream|
9091| Granite Typhoon| China| GALLIUM, PHANTOM PANDA|
9192| Gray Sandstorm| Iran| DEV-0343|
92- | Hazel Sandstorm| Iran| EUROPIUM, HELIX KITTEN, COLBALT GYPSY, Crambus, OilRig, APT34|
93- | Heart Typhoon| China| HELIUM, AURORA PANDA, APT17, Hidden Lynx, ATG3, Red Typhon , KAOS, TG-8153, SportsFans, DeputyDog, Tailgater|
93+ | Hazel Sandstorm| Iran| EUROPIUM, HELIX KITTEN, COBALT GYPSY, Crambus, OilRig, APT34|
94+ | Heart Typhoon| China| HELIUM, AURORA PANDA, APT17, Hidden Lynx, ATG3, Red Typhoon , KAOS, TG-8153, SportsFans, DeputyDog, Tailgater|
9495| Hexagon Typhoon| China| HYDROGEN, NUMBERED PANDA, Calc Team, Red Anubis, APT12, DNS-Calc, HORDE|
9596| Houndstooth Typhoon| China| HASSIUM, DRAGNET PANDA, isoon, deepclif|
9697| Jade Sleet| North Korea| Storm-0954, LABYRINTH CHOLLIMA|
98+ | [ Jasper Sleet] ( https://www.microsoft.com/en-us/security/blog/2025/06/30/jasper-sleet-north-korean-remote-it-workers-evolving-tactics-to-infiltrate-organizations/ ) | North Korea| Storm-0287|
9799| Lace Tempest| Financially motivated| DEV-0950|
98100| Lemon Sandstorm| Iran| RUBIDIUM, PIONEER KITTEN|
99101| Leopard Typhoon| China| LEAD, WICKED PANDA, TG-2633, TG-3279, Mana, KAOS, Red Diablo, Winnti Group|
0 commit comments