CTI Academy
Log in Create account

Threat Actor Naming, Decoded: Why APT29, Cozy Bear, and Midnight Blizzard Are One Problem

By CTI Academy Team

Threat actor naming is why one group answers to APT29, Cozy Bear and Midnight Blizzard. How each vendor names, what aliases hide, and how to cite them.

On 24 July 2026, Google Threat Intelligence Group threw out its own naming system. APT28 became LAKE RELIC. APT29 became ICE RELIC. APT41 became SPIRE CASTLE. FIN7 became WILD COMET. The APT numbering that Mandiant popularised, that every CTI syllabus on earth teaches, that sits in thousands of published reports, was replaced with two-word cryptonyms.

Count what that did to one group. Sandworm was Sandworm. Then Mandiant graduated it to APT44 in April 2024. Now Google calls it SANDWORM RELIC. Three names in twenty-eight months, from a single vendor, for an actor that never changed.

Google's own rename table showing APT28 becoming LAKE RELIC and APT29 becoming ICE RELIC, beside the category word key

Google's published rename table, filtered to the actors named in this article, with the category words that carry the attribution. Screenshot from Google Threat Intelligence Group's announcement.

Threat actor naming is the tax every analyst pays for working in an industry where no two companies see the same thing. It is also one of the first things that trips people up when they start doing cyber threat intelligence properly, because the names look like facts and behave like opinions.

This piece is the decoder: what each vendor's naming scheme actually encodes, a cross-vendor table for the eighteen actors you will meet most, why the aliases are approximations rather than equations, and how to write about actors without quietly asserting something you cannot defend.

What Threat Actor Naming Is

Threat actor naming is the practice of assigning a label to a cluster of intrusion activity that a vendor believes was carried out by one group. The name is attached to the cluster, not to a person, an office, or a government. Each vendor names from its own telemetry, so the same real-world operators can pick up a dozen different labels, and two vendors can draw the cluster boundaries in different places entirely.

That last sentence is the whole problem in miniature. A name is a claim about where one group's activity ends and another's begins, and vendors make that claim from different evidence.

MITRE says so plainly on its own Groups page. Its "Associated Groups" field, renamed from "Aliases", carries the warning that it does "not represent these names as exact overlaps" and encourages analysts to do additional research, because organisations' group definitions "may partially overlap" and "may disagree on specific activity."

Read that caveat twice. The most widely used cross-reference in the field explicitly declines to say that its aliases are equalities.

Nine vendor names for APT29 laid out in a grid, from Midnight Blizzard to COZY BEAR to ICE RELIC

Nine labels, one set of Russian SVR intrusion activity. The count is not the interesting part. The fact that each label was drawn from different telemetry is.

How to Read Any Vendor's Name in Ten Seconds

Most naming schemes are two-part: a category word that encodes origin or motivation, and a distinguishing word. Learn the category words and you can read a name you have never seen before.

Vendor Scheme Category word encodes Examples
Microsoft Weather Country or motivation Blizzard (Russia), Typhoon (China), Sandstorm (Iran), Sleet (North Korea), Tempest (financially motivated), Flood (influence operations), Storm-#### (not yet attributed)
CrowdStrike Animal Nation or criminal nexus Bear (Russia), Panda (China), Kitten (Iran), Chollima (North Korea), Spider (eCrime)
Google / Mandiant Cryptonym since July 2026 Second word is the category RELIC (Russia), CASTLE (China), ION (Iran), NEPTUNE (North Korea), COMET (cybercriminal). UNC#### survives for early-stage clusters
Palo Alto Unit 42 Constellation Country or crime type Ursa (Russia), Taurus (China), Pisces (North Korea), Serpens (Iran), Libra (cybercrime), Scorpius (ransomware)
Secureworks Metal Country or motivation IRON (Russia), BRONZE (China), COBALT (Iran), NICKEL (North Korea), GOLD (cybercrime)
Trend Micro Element plus creature Motivation, not country Earth (espionage), Water (financial), Fire (destructive), Wind (hacktivism)
Dragos Mineral, ending -ITE ICS-focused groups ELECTRUM, KAMACITE, VOLTZITE
Proofpoint TA### Nothing, sequential TA422, TA427, TA453

Two traps in that table are worth calling out.

The first is Trend Micro. "Earth" is a motivation, not a country, and creatures are chosen specifically to avoid tying a name to any nation. Analysts misread Earth Estries as a geographic claim constantly. It is not one.

The second is that the same token can mean opposite things at different vendors. ZINC was North Korea in Microsoft's retired element scheme. ZINC is India at Secureworks, whose full metal table is published and almost never cited. If you are pasting a name across tools, the token alone will not save you.

The Cross-Vendor Table

Eighteen actors, the names each vendor uses, and what each one is actually known for. Blank cells mean no published name was found from that vendor, which is information rather than an omission.

Common name Microsoft CrowdStrike Mandiant / Google Secureworks Unit 42 Origin Known for
APT29 Midnight Blizzard (ex-NOBELIUM) COZY BEAR APT29, UNC2452, now ICE RELIC IRON RITUAL, IRON HEMLOCK Cloaked Ursa Russia, SVR SolarWinds SUNBURST, long-dwell cloud and identity intrusions
APT28 Forest Blizzard (ex-STRONTIUM) FANCY BEAR APT28, FROZENLAKE, now LAKE RELIC IRON TWILIGHT Fighting Ursa Russia, GRU unit 26165 DNC 2016, industrial-scale credential phishing
Sandworm Seashell Blizzard (ex-IRIDIUM) VOODOO BEAR APT44, now SANDWORM RELIC IRON VIKING Razing Ursa Russia, GRU unit 74455 Ukraine grid blackouts, NotPetya, Olympic Destroyer
APT41 Brass Typhoon (ex-BARIUM) WICKED PANDA APT41, now SPIRE CASTLE BRONZE ATLAS   China Espionage and for-profit crime from one infrastructure
APT10 Purple Typhoon (ex-POTASSIUM) STONE PANDA APT10 BRONZE RIVERSIDE   China, MSS Tianjin Operation Cloud Hopper, via managed service providers
Volt Typhoon Volt Typhoon (ex-DEV-0391) VANGUARD PANDA UNC3236 BRONZE SILHOUETTE Insidious Taurus China Living-off-the-land pre-positioning in US critical infrastructure
Salt Typhoon Salt Typhoon OPERATOR PANDA UNC5807 or UNC2286, disputed     China Long-dwell telecom and ISP backbone compromises
Silk Typhoon Silk Typhoon (ex-HAFNIUM) MURKY PANDA       China ProxyLogon mass exploitation, later cloud trust abuse
Lazarus Group Diamond Sleet (ex-ZINC) LABYRINTH CHOLLIMA TEMP.Hermit, UNC577 NICKEL ACADEMY Selective Pisces North Korea, RGB Sony Pictures wiper, WannaCry
Kimsuky Emerald Sleet (ex-THALLIUM) VELVET CHOLLIMA APT43 NICKEL KIMBALL Sparkling Pisces North Korea, RGB Persona-driven spear phishing of policy experts
APT38 Sapphire Sleet STARDUST CHOLLIMA APT38, UNC1069 NICKEL GLADSTONE Alluring Pisces North Korea, RGB Bank of Bangladesh SWIFT heist, crypto theft
Scattered Spider Octo Tempest SCATTERED SPIDER UNC3944 GOLD HARVEST Muddled Libra eCrime, US and UK Help-desk social engineering, SIM swapping, MFA fatigue
FIN7 Sangria Tempest (ex-ELBRUS) CARBON SPIDER FIN7, now WILD COMET GOLD NIAGARA   eCrime Point-of-sale card theft, later ransomware affiliate work
Charming Kitten Mint Sandstorm (ex-PHOSPHORUS) CHARMING KITTEN APT35, APT42 COBALT ILLUSION Agent Serpens Iran, likely IRGC Long-running persona social engineering against journalists and academics
MuddyWater Mango Sandstorm (ex-MERCURY) STATIC KITTEN TEMP.Zagros, UNC3313 COBALT ULSTER Boggy Serpens Iran, MOIS Legitimate remote management tooling abuse
APT34 Hazel Sandstorm (ex-EUROPIUM) HELIX KITTEN APT34 COBALT GYPSY Evasive Serpens Iran, MOIS-linked DNS tunnelling, webshells, partner supply chain pivots
LockBit no Microsoft name published BITWISE SPIDER   GOLD MYSTIC Flighty Scorpius eCrime, Russian-speaking The LockBit ransomware-as-a-service scheme
Akira Storm-1567 PUNK SPIDER   GOLD SAHARA Howling Scorpius eCrime Double extortion via single-factor VPN access

Scattered Spider is the row most people arrive looking for, because it is the one that breaks search. We wrote about the group's social engineering without dwelling on its names, and it shows up again in our breakdown of the four types of threat intelligence as an example of the same cluster carrying three labels. Microsoft's own public feed resolves the tangle in one line: Octo Tempest, with other names "SCATTERED SPIDER, 0ktapus."

Volt Typhoon is worth a second look too, because the name encodes something the technique does not. Microsoft, CrowdStrike and Secureworks all publish a name for it, but what actually makes it hard to catch is its living-off-the-land tradecraft, which leaves almost nothing for a name to attach to.

How a Cluster Earns a Name

Names look arbitrary from outside. They are not. Most vendors publish a threshold, and the published thresholds are stricter than the discourse suggests.

Unit 42 documents the most explicit ladder in the industry. Activity starts as a CL- cluster needing at least two related events. Promotion to a TGR- temporary group requires at least six months of observation, full Diamond Model mapping, and procedure-level detail rather than ATT&CK technique-level detail. Only then does a constellation name get assigned, and only at high confidence with all four Diamond vertices populated.

Microsoft runs the same idea under a different label. Storm-#### is the holding pen. A group stays there until high confidence is reached about origin or identity, at which point it is either converted to a named actor or merged into an existing name.

Mandiant's criterion, from its own account of the process, has two conditions: understanding the actor's operations across every phase of the attack lifecycle, and associating that activity with a state-aligned programme or a criminal operation. Clustering alone is not enough. You need the sponsor link.

Two promotion ladders side by side, Unit 42 CL to TGR to constellation name, and Microsoft Storm to named actor

Both vendors withhold the label until the evidence carries it. The thresholds are published, and they are stricter than the discourse suggests.

This matters for how you read a name. "Volt Typhoon" is a much stronger claim than "Storm-1567", and both are much weaker claims than "GRU unit 26165."

The Third of the Catalogue Nobody Names

Here is a number you will not find in a vendor blog post, because we counted it ourselves from Microsoft's public mapping feed on 19 September 2026.

Of 170 entries, 54 are still Storm-####. That is 31.8 percent of Microsoft's published catalogue sitting in the unattributed holding pen. The named remainder breaks down as Typhoon 35, Sandstorm 17, Tempest 16, Sleet 12, Blizzard 11, with the rest spread across smaller families.

Nearly a third of the catalogue is a vendor saying, in public, that it does not yet know who this is.

That is the healthiest thing in the entire naming system, and it is the part the industry never discusses. Re-run the count before you quote it, because the feed updates continuously.

One more thing surfaced in that count, and it is a caution about treating any single file as canonical. Microsoft's own list is inconsistent in how thoroughly it records aliases. Forest Blizzard carries twelve other names in the feed. Seashell Blizzard carries nine. Midnight Blizzard carries four, namely NOBELIUM, COZY BEAR, UNC2452 and APT29, while MITRE's page for the same actor lists roughly triple that. Thirty-seven of the 170 entries carry no aliases at all.

MITRE's APT29 page listing fourteen associated groups beside Microsoft's feed entry listing four

The two sources most analysts treat as authoritative, side by side, on the same actor. Neither is wrong, and they do not agree.

Why "APT29 = Midnight Blizzard" Is an Approximation

The strongest evidence that aliases are not equalities comes from the flagship artefact built to align them.

In June 2025, Microsoft and CrowdStrike published a joint mapping and released it as a spreadsheet. We downloaded and parsed that file on 19 September 2026. It contains 84 populated CrowdStrike-to-Microsoft pairs. Those 84 pairs resolve to 84 distinct Microsoft names but only 73 distinct CrowdStrike names.

The gap is where the argument lives. Seven CrowdStrike names map to more than one Microsoft actor:

CrowdStrike name Microsoft actors it maps to
LABYRINTH CHOLLIMA Citrine Sleet, Diamond Sleet, Jade Sleet, Moonstone Sleet
IMPERIAL KITTEN Crimson Sandstorm, Cuboid Sandstorm, Smoke Sandstorm
VELVET CHOLLIMA Emerald Sleet, Opal Sleet, Ruby Sleet
WICKED PANDA Brass Typhoon, Leopard Typhoon
EMISSARY PANDA Circle Typhoon, Linen Typhoon
INDRIK SPIDER Manatee Tempest, Mustard Tempest
WIZARD SPIDER Periwinkle Tempest, Storm-0230

LABYRINTH CHOLLIMA on the left connected to four Microsoft names, Citrine, Diamond, Jade and Moonstone Sleet

The clearest counter-example to "alias means equals", and it comes from the file built to align the two schemes.

Where CrowdStrike sees one North Korean adversary, Microsoft sees four. Neither is wrong. They are drawing boundaries from different telemetry, and the alignment document records the disagreement rather than resolving it.

Unit 42 splits the same DPRK space its own way, into Selective Pisces, Slow Pisces, Jumpy Pisces, Gleaming Pisces, Alluring Pisces and Sparkling Pisces, and states outright in its DPRK assessment that "Lazarus has been used in public reporting as an umbrella term." When you write "Lazarus," you are naming a category, not a group. The Bitget hack of September 2026 is a live example: the headlines said Lazarus, while the cluster analysts actually point to is TraderTraitor, and even that is unconfirmed.

Salt Typhoon shows the same fracture live. Trend Micro folds GhostEmperor and FamousSparrow into Earth Estries. ESET treats GhostEmperor and FamousSparrow as two distinct groups. Recorded Future tracks it as RedMike. CrowdStrike's page records the Mandiant cluster as UNC5807; Trend Micro records it as UNC2286. Pick a name and you have picked a side in an unsettled argument.

The academic measurement backs this up at scale. "Hesperus is Phosphorus", from Universidad Carlos III de Madrid, analysed 13,371 CTI reports spanning 17 vendor taxonomies and 3,287 threat actor names. The paper's title is the point. Hesperus and Phosphorus are the evening star and the morning star, known for centuries as two things before anyone worked out they were both Venus. The difference is that in threat intelligence, sometimes they really are two planets.

The Alignment Attempt, and What Actually Happened

On 2 June 2025 Microsoft and CrowdStrike announced a collaboration to bring clarity to threat actor naming. Both companies were careful about the promise. Microsoft's post states: "This effort is not about creating a single naming standard." CrowdStrike's companion post is where the headline figure comes from, and it is worth quoting in full because the qualifier usually gets dropped:

"While a single universal naming standard is not practical and may not be possible, defenders shouldn't have to spend countless cycles trying to delineate if COZY BEAR is the same as APT29, or UNC2452, or Midnight Blizzard."

CrowdStrike reported that more than 80 adversaries had been deconflicted through the effort. Our parse of the published file found 84 pairs, which matches.

Then look at what happened next, because this is the part the coverage missed.

Microsoft's announcement said: "This initial taxonomy mapping is a collaboration between Microsoft and CrowdStrike. Google/Mandiant and Palo Alto Networks Unit 42 will also be contributing to this effort."

Fourteen months later, Google shipped an entirely new naming system of its own.

And the joint artefact has not moved. The spreadsheet CrowdStrike publishes still carries an HTTP Last-Modified date of 3 June 2025, the day after launch, and still holds exactly the same 84 pairs. Microsoft's unilateral list, by contrast, is alive: its reference page was updated on 10 September 2026 and its spreadsheet carries a Last-Modified of 18 September 2026.

The collaboration produced a snapshot. One company has maintained its own list ever since, one company left the joint file frozen, and a third answered the fragmentation problem by adding a fourth taxonomy.

There is a serious counter-argument, and it deserves airtime. Writing in Just Security, Jen Easterly and Marci McCarthy Martin reject the industry's framing directly: "The oft-repeated claim that a single universal naming system is 'not practical' or 'not possible' simply isn't credible." Their argument is that what is missing is not feasibility but collective will, and that vendor cryptonyms function partly as marketing.

Both things can be true. The telemetry differences are real, and so is the commercial incentive to own a name that ends up in every headline.

What the Numbers Do Not Say

Here is where honesty costs us a statistic.

Everyone asserts that naming confusion wastes analyst time. Nobody has measured it. We went looking for a survey putting hours, dollars or error rates on the problem and found nothing usable. CrowdStrike says "countless cycles." Just Security says naming chaos can "delay response times and create confusion across SOCs, incident response teams, and executive leadership." Forrester called it operational drag. Those are all qualitative.

So treat any confident number about the cost of naming confusion as invented until someone publishes the methodology. What we can measure is the shape of the problem: 3,287 names across 17 taxonomies in the academic dataset, 84 alignment pairs collapsing to 73 on one side, 31.8 percent of one vendor's catalogue unattributed. Those are real. The hours are not.

How to Handle Names in Your Own Work

The practical guidance is short, and it is mostly about refusing to flatten things.

Name the vendor with the name. Not "APT29 did this" but "the actor Microsoft tracks as Midnight Blizzard, which CrowdStrike tracks as COZY BEAR." It reads heavier. It is also the only version that survives a reader checking your work. Mandiant models the right hedge verb in its APT42 reporting, saying the group "partially coincides with" public reporting on TA453, Yellow Garuda, ITG18, Phosphorus and Charming Kitten. Partially coincides. Not equals.

Record the source alongside the alias. An alias without a provenance is a rumour with a capital letter. This is the same discipline as marking your reporting correctly, which we covered in the Traffic Light Protocol guide.

Use a machine-readable alias source, and read its confidence tags. The MISP threat actor galaxy is the best public one. The important design decision is that MISP does not assert that X equals Y. Its relationships carry estimative-language tags, so an alias link can be "likely" or "almost certain" rather than flatly true. Browse it at misp-galaxy.org.

Separate the confidence in the cluster from the confidence in the sponsor. These are different judgments and vendors routinely assert one while hedging the other. Mandiant will state an actor's existence flatly and attach "moderate confidence" only to the claim about who runs it. If you are writing this kind of language yourself, the mechanics are in our guide to writing a threat intel report people act on.

Do not inherit another organisation's attribution. CrowdStrike's position, stated in congressional testimony on SolarWinds, is that it would not accept another organisation's attribution determination without independently verifying it. You probably cannot verify at that level. You can still mark inherited attribution as inherited.

Watch for merges, because a merge rewrites your detections. When Mandiant folded UNC2452 into APT29 in April 2022, the published write-up included a section on the ATT&CK techniques added as a result. A name change is a content change. Current ATT&CK carries 191 intrusion sets with six revoked through merges and nine deprecated, and in version 12 MITRE deprecated seven entries that turned out to be campaigns rather than groups. The taxonomy corrects itself, and your notes should follow.

When Governments Name Instead

Government advisories invert the whole model, and the inversion is instructive.

A joint advisory published in May 2025 by 11 nations and 21 agencies makes the military unit the primary key: the 85th Main Special Service Center, military unit 26165. Vendor cryptonyms appear in a table headed "Cybersecurity Industry Tracking," relegated to cross-reference. Authoring agencies state that they are not adopting any particular commercial naming convention.

Then the reverse happens. The FBI publishes a Cyber's Most Wanted poster titled "APT 41 GROUP", naming five individuals. A vendor cryptonym became the headline on a federal wanted notice.

So the hierarchy is not "government names are better." It is that government naming answers a different question. Vendors name activity clusters. Indictments name people. When both exist for the same operation, the unit designation is the more precise fact and the cryptonym is the more searchable one.

Where the Reps Come From

You can memorise this entire article and still freeze the first time a report lands on your desk using three names you have never seen for a group you have tracked for a year. Recognising a naming collision in a live investigation is a different skill from reading a table about one.

That is the gap the Hunter track is built to close. The path works the way the job works: you get the reporting, the conflicting labels and the pressure, and you practise writing the assessment that survives review. Theory teaches you what a cryptonym encodes. Reps teach you what to do at 16:40 when two vendors disagree and someone needs an answer.

Start with the Threat Actor Profiling & Attribution learning path.

Frequently Asked Questions

Why does the same threat actor have so many different names?

Because each vendor names from its own telemetry. A company sees a slice of an actor's activity through its own customers and sensors, clusters that slice, and labels it. Another company sees a different slice and draws a different boundary. There is no central authority assigning names, and vendors have both analytic and commercial reasons to keep their own scheme.

Is APT29 the same as Cozy Bear and Midnight Blizzard?

They refer to the same broad set of activity, attributed to Russia's SVR, but "the same" is doing more work than it should. Microsoft's own feed lists COZY BEAR and APT29 as other names for Midnight Blizzard. MITRE lists roughly three times as many aliases and explicitly declines to call them exact overlaps. Treat them as strongly overlapping clusters rather than identical entities.

What does Storm-#### mean in Microsoft's naming?

It is a temporary designation for an activity group that Microsoft has not yet attributed. A group stays in Storm-#### until high confidence is reached about its origin or identity, at which point it is converted to a named actor or merged into an existing name. As of September 2026, 54 of the 170 entries in Microsoft's public feed are still Storm-####.

Did Microsoft and CrowdStrike agree on one naming standard?

No, and both said so at launch. Their June 2025 collaboration produced a mapping between their two schemes, not a shared standard. CrowdStrike's post states that a single universal naming standard "is not practical and may not be possible." The published joint file has not been updated since 3 June 2025.

Why did Google rename APT29 to ICE RELIC?

On 24 July 2026 Google Threat Intelligence Group replaced APT, FIN and TEMP prefixes with two-word cryptonyms in which the second word encodes origin or type: RELIC for Russia, CASTLE for China, ION for Iran, NEPTUNE for North Korea, COMET for cybercriminal. Google states that when no prior public term exists, the first word is randomly generated to remove bias, then vetted by analysts. UNC numbering survives for early-stage clusters.

Which vendor's naming scheme should I use?

Whichever one your organisation's tooling and reporting already speaks, used consistently, with the vendor named alongside it. The mistake is not picking the wrong scheme. The mistake is switching between schemes inside one document, or writing a name without saying whose name it is.

Where can I look up threat actor aliases?

MITRE ATT&CK's Groups pages are the best starting point for named groups. Microsoft publishes a machine-readable mapping feed as JSON. The MISP threat actor galaxy is the most complete public alias source and, unlike most, tags its alias relationships with estimative language rather than asserting equality. ETDA's threat group cards attribute each alias to the vendor that coined it.

Does naming confusion actually cause operational harm?

It clearly causes friction, but nobody has quantified it. Vendors describe "countless cycles" lost and commentators describe delayed response times, and none of those claims come with a methodology. Be suspicious of any specific figure. The measurable part is the scale of the fragmentation itself, not its cost.

Sources

Continue with the Threat Actor Profiling & Attribution Learning Path

Start Learning Path

Related Articles

Read more at CTI Academy Blog