Hacker Group Names Are Now Absurdly Out of Control

Goofiness aside, the new system is counterproductive for actual cybersecurity analysis, Lee argues. Given that Microsoft’s threat intelligence is some of the best in the world, analysts and customers across the industry will have to actually revise their databases—and even some of their products—to match Microsoft’s new naming scheme, he says. And the revised system now locks in educated guesses about the national loyalties of hackers with no indication of the analysts’ degree of confidence in those assessments, Lee adds.

What if a hacker group thought to be part of a nation’s intelligence agency turns out to be a hacker-for-hire contractor? Or cybercriminals temporarily conscripted to work on behalf of a government? “Assessments change over time,” Lee says. “Like, ‘We told you it was Dirty Mustard and now it’s Swirling Tempest,’ and you’re like, what the fuck?” (Lee’s own firm, Dragos, admittedly gives hacker groups mineral names that are often confusingly similar to Microsoft’s old system. But at least Dragos has never called anyone Gingham Typhoon.)

When I reached out to Microsoft about its new naming scheme, the head of its Threat Intelligence Center, John Lambert, explained the rationale behind the change: Microsoft’s new names are more distinct, memorable, and searchable. In contrast to Lee’s point about choosing neutral names, the Microsoft team wanted to give customers more context about hackers in the names, Lambert says, immediately identifying their nationality and motive. (Instances that are not yet fully attributed to a known group are given a temporary classifier, he notes.)

Microsoft’s team was also just running out of elements—there are, after all, only 118 of them. “We liked weather because it’s a pervasive force, it’s disruptive, and there’s a kindred spirit because the study of weather over time involves improvement in sensors, data, and analysis,” says Lambert. “That’s cybersecurity defenders’ world, too.” As for the adjectives preceding those meteorological terms—often the real source of the names’ inadvertent comedy—they’re chosen by analysts from a long list of words. Sometimes they have a semantic or phonetic connection to the hacker group, and sometimes they’re random. “There’s some origin story to each one,” Lambert says, “or it could just be a name out of a hat.”

There’s a certain, stubborn logic behind the cybersecurity industry’s ever-growing sprawl of hacker group handles. When a threat intelligence firm finds evidence of a new team of network intruders, they can’t be sure they’re seeing the same group that another company has already spotted and labeled, even if they do see familiar malware, victims, and command-and-control infrastructure between the two groups. If your competitor isn’t sharing everything they see, it’s better to make no assumptions and track the new hackers under your own name. So Sandworm becomes Telebots, and Voodoo Bear, and Hades, and Iron Viking, and Electrum, and—sigh—Seashell Blizzard, as every company’s analysts get a different glimpse of the group’s anatomy.

But, sprawl aside, did these names have to be quite so on-their-face ridiculous? To some degree, it may be wise to give names to hacker gangs that rob them of their malevolent glamour. Members of the Russian ransomware group EvilCorp, for instance, are not likely to be happy with Microsoft’s rebranding them as Manatee Tempest. On the other hand, is it really appropriate to label a group of Iranian hackers that seeks to penetrate crucial elements of US civilian infrastructure Mint Sandstorm, as if they’re an exotic flavor of air freshener? (The older name given to them by Crowdstrike, Charming Kitten, is certainly not any better.) Did the Israeli hacker-for-hire mercenaries known as Candiru, who have sold their services to governments targeting journalists and human rights activistsreally need to be renamed Caramel Tsunami, a brand befitting a Dunkin’ beverage, and one that’s already taken by a strain of cannabis?

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Nove tehnologije čišćenja i održavanja spomenika kulture čuvaju tragove istorije od zaborava! thumbnail

Nove tehnologije čišćenja i održavanja spomenika kulture čuvaju tragove istorije od zaborava!

Spomenici su važan deo kulturnog identiteta jednog društva. Pri njihovom čišćenju, održavanju i restauriranju neophodna je velika pažnja, mnogo vremena, truda i znanja. Bilo da je reč o statuama, kraljevskim dvorcima ili sivim betonskim blokovima – vrednost jednog spomenika određuje mnogo više faktora od njegovog samog izgleda. Mnogi stručnjaci za očuvanje kulturnih baština svakodnevno govore o…
Read More
Waymo gets approval to deploy its robotaxi service in Los Angeles thumbnail

Waymo gets approval to deploy its robotaxi service in Los Angeles

The California Public Utilities Commission (CPUC) has given Waymo permission to expand its robotaxi operations to Los Angeles and more locations in the San Francisco Peninsula despite opposition from local groups and government agencies. "Waymo may begin fared driverless passenger service operations in the specified areas of Los Angeles and the San Francisco Peninsula, effective
Read More
Orquesta Adalberto Álvarez y su Son plays again thumbnail

Orquesta Adalberto Álvarez y su Son plays again

La orquesta de ‘Adalberto Álvarez y su Son’ vuelve a retomar su trabajo, luego de casi un mes del fallecimiento del líder de la agrupación a causa del coronavirus.“No hay día en que me levante y no piense todo el tiempo en ti.  Aquí estoy trabajando ya para continuar tu obra y todos los proyectos…
Read More
List of phones to be released in January 2022 thumbnail

List of phones to be released in January 2022

Resmi olarak 2022'deyiz ve yılın ilk ayı olan Ocak ayı başladı. Bu ay dünya çapında birçok akıllı telefonun piyasaya sürülmesini bekliyoruz. İşte o cihazlar. 03.01.2022 12:00 03.01.2022 12:00 2022 Ocak ayında gelecek cihazlardan bazıları belli oldu. Onaylanan telefon lansmanlarından bazıları Samsung, OnePlus, Xiaomi, Realme, Vivo ve Oppo gibi büyük markalardan. Ayrıca Lenovo'dan oyuncu odaklı telefonlar,…
Read More
How generative AI is already changing the workplace: Oracle just added it to HR software thumbnail

How generative AI is already changing the workplace: Oracle just added it to HR software

David Paul Morris/Bloomberg via Getty Images"Nothing is certain," Benjamin Franklin once said, "except death and taxes." With unwavering certainty, I can say that artificial intelligence will be entrenched in our future work lives -- it's only a matter of who embraces it and how. Oracle, for one, is embracing it.The company is adding generative AI capabilities to its Oracle
Read More
Index Of News
Total
0
Share