Cutting Through the Chaos: Microsoft and CrowdStrike Unite to Standardize Threat Actor Naming


# Microsoft and CrowdStrike Join Forces to Streamline Threat Actor Identification

Microsoft and CrowdStrike have launched a collaborative initiative to align their threat actor taxonomies through a joint mapping system. This partnership aims to help security professionals connect insights faster and make more confident decisions when identifying cyber threats.

“By mapping where our knowledge of these actors align, we will provide security professionals with the ability to connect insights faster and make decisions with greater confidence,” explained Vasu Jakkal, corporate vice president at Microsoft Security.

The initiative addresses the confusing array of nicknames assigned to hacking groups by different cybersecurity vendors. These threat actors are typically categorized as nation-state, financially motivated, influence operations, private sector offensive actors, or emerging clusters.

For instance, the Russian state-sponsored threat actor known to Microsoft as Midnight Blizzard (formerly Nobelium) is also tracked as APT29, Cozy Bear, and The Dukes by other organizations. Similarly, Forest Blizzard (previously Strontium) is known by multiple names including Fancy Bear, Sofacy, and BlueDelta.

Microsoft transitioned from chemical element-inspired naming to weather-themed nomenclature in April 2023. This new unified mapping system will make tracking overlapping threat activities easier and reduce confusion in attribution, which often complicates analysis and delays response.

While currently a two-party effort, Google’s Mandiant and Palo Alto Networks’ Unit 42 are expected to join, with more cybersecurity companies likely to participate in the future. Importantly, the collaboration doesn’t aim to create a single naming standard but rather serves as a “Rosetta Stone” for correlating threat actor aliases.

CrowdStrike’s Adam Meyers noted that the alignment has already successfully deconflicted more than 80 adversaries. He added, “Where telemetry complements one another, there’s an opportunity to extend attribution across more planes and vectors — building a richer, more accurate view of adversary campaigns that benefits the entire community.”

Share This Article