Friday, November 1, 2024
HomeCyber AttackMicrosoft Changed the Method of Naming the Hacker Groups

Microsoft Changed the Method of Naming the Hacker Groups

Published on

Malware protection

Microsoft has initiated the naming taxonomy for threat actor groups. Over the years, threat actors have evolved massively, leading to confusion about which threat actor was responsible for which threat activity.

To solve this, Microsoft has introduced this naming taxonomy and categorized them based on their origin and activity.

Though threat intelligence has emerged massively, it must still be an organized data resource that can help protect and prioritize based on the hacking groups confronted.

- Advertisement - SIEM as a Service
Weather-based Hacking group name taxonomy

Microsoft has relied on weather condition names for naming these hacking groups as this can be easy to remember and spread the word.

Categorization

Microsoft has categorized threat actors into five main groups based on their operations.

  1. Nation-state – These threat actors work on behalf of or are directly supported by a nation/state. They specifically target government agencies, intergovernmental organizations, espionage, financial gain, or as an act of retribution.
  2. Financially Motivated – These threat actors target an organization or an individual as a part of a financial motive. These threat actors/ groups did not seem to be linked with nation-state actors. The best examples of these threat actors are ransomware operators, phishing groups, or other groups with purely money-minded activities.
  3. Private Sector Offensive actors (PSOAs): These are threat actors who were once known as legal organizations but later seemed to have been involved in activities like creating malware, selling weapons and surveillance software to cyber criminals who use them for illegal purposes, or targeting any white-collar individuals. The best example of this kind of threat actor was the QuaDream company which was shut down recently for its malicious activities.
  4. Influence Operations: These are the threat actors that spread misinformation among people to disrupt or manipulate people’s interests. This kind of threat actor is also involved in political manipulations for malicious purposes.
  5. Groups in Development: This category set by Microsoft includes threat actors whose origin and way of operations are yet to be confirmed. In other words, these include threat actors still in developmental phases and involved in small-scale malicious attacks.

Microsoft has also released complete information on their new weather name taxonomy, including the family name, their origin or country of operation, and their category.

Building Your Malware Defense Strategy – Download Free E-Book

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

LightSpy iOS Malware Enhanced with 28 New Destructive Plugins

The LightSpy threat actor exploited publicly available vulnerabilities and jailbreak kits to compromise iOS...

ATPC Cyber Forum to Focus on Next Generation Cybersecurity and Artificial Intelligence Issues

White House National Cyber Director, CEOs, Key Financial Services Companies, Congressional and Executive Branch...

New PySilon RAT Abusing Discord Platform to Maintain Persistence

Cybersecurity experts have identified a new Remote Access Trojan (RAT) named PySilon. This Trojan...

Konni APT Hackers Attacking Organizations with New Spear-Phishing Tactics

The notorious Konni Advanced Persistent Threat (APT) group has intensified its cyber assault on...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

LightSpy iOS Malware Enhanced with 28 New Destructive Plugins

The LightSpy threat actor exploited publicly available vulnerabilities and jailbreak kits to compromise iOS...

New PySilon RAT Abusing Discord Platform to Maintain Persistence

Cybersecurity experts have identified a new Remote Access Trojan (RAT) named PySilon. This Trojan...

Konni APT Hackers Attacking Organizations with New Spear-Phishing Tactics

The notorious Konni Advanced Persistent Threat (APT) group has intensified its cyber assault on...