Friday, February 14, 2025
HomeCyber AttackMicrosoft Changed the Method of Naming the Hacker Groups

Microsoft Changed the Method of Naming the Hacker Groups

Published on

SIEM as a Service

Follow Us on Google News

Microsoft has initiated the naming taxonomy for threat actor groups. Over the years, threat actors have evolved massively, leading to confusion about which threat actor was responsible for which threat activity.

To solve this, Microsoft has introduced this naming taxonomy and categorized them based on their origin and activity.

Though threat intelligence has emerged massively, it must still be an organized data resource that can help protect and prioritize based on the hacking groups confronted.

Weather-based Hacking group name taxonomy

Microsoft has relied on weather condition names for naming these hacking groups as this can be easy to remember and spread the word.

Categorization

Microsoft has categorized threat actors into five main groups based on their operations.

  1. Nation-state – These threat actors work on behalf of or are directly supported by a nation/state. They specifically target government agencies, intergovernmental organizations, espionage, financial gain, or as an act of retribution.
  2. Financially Motivated – These threat actors target an organization or an individual as a part of a financial motive. These threat actors/ groups did not seem to be linked with nation-state actors. The best examples of these threat actors are ransomware operators, phishing groups, or other groups with purely money-minded activities.
  3. Private Sector Offensive actors (PSOAs): These are threat actors who were once known as legal organizations but later seemed to have been involved in activities like creating malware, selling weapons and surveillance software to cyber criminals who use them for illegal purposes, or targeting any white-collar individuals. The best example of this kind of threat actor was the QuaDream company which was shut down recently for its malicious activities.
  4. Influence Operations: These are the threat actors that spread misinformation among people to disrupt or manipulate people’s interests. This kind of threat actor is also involved in political manipulations for malicious purposes.
  5. Groups in Development: This category set by Microsoft includes threat actors whose origin and way of operations are yet to be confirmed. In other words, these include threat actors still in developmental phases and involved in small-scale malicious attacks.

Microsoft has also released complete information on their new weather name taxonomy, including the family name, their origin or country of operation, and their category.

Building Your Malware Defense Strategy – Download Free E-Book

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Fake BSOD Attack Launched via Malicious Python Script

A peculiar malicious Python script has surfaced, employing an unusual and amusing anti-analysis trick...

SocGholish Malware Dropped from Hacked Web Pages using Weaponized ZIP Files

A recent wave of cyberattacks leveraging the SocGholish malware framework has been observed using...

Lazarus Group Targets Developers Worldwide with New Malware Tactic

North Korea's Lazarus Group, a state-sponsored cybercriminal organization, has launched a sophisticated global campaign...

North Korean IT Workers Penetrate Global Firms to Install System Backdoors

In a concerning escalation of cyber threats, North Korean IT operatives have infiltrated global...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Fake BSOD Attack Launched via Malicious Python Script

A peculiar malicious Python script has surfaced, employing an unusual and amusing anti-analysis trick...

SocGholish Malware Dropped from Hacked Web Pages using Weaponized ZIP Files

A recent wave of cyberattacks leveraging the SocGholish malware framework has been observed using...

Lazarus Group Targets Developers Worldwide with New Malware Tactic

North Korea's Lazarus Group, a state-sponsored cybercriminal organization, has launched a sophisticated global campaign...