I’m skeptical about creating new naming conventions. I don’t even think every organization that publishes 1st party intel should have their own convention.
For readers to understand the context properly, you end up having to list a bunch of aliases anyway
My approach is usually to use an existing name unless that name doesn’t match how you cluster the activity. This is something I spend too much time thinking about and I’m on a mission to convince people to take more care when it comes to attribution and naming
For example, the attribution around Salt Typhoon and friends was a mess, so we kept using FamousSparrow and explained the links and non-links in the article instead of using the most popular name.
I’ll try to write “FamousSparrow (aka FUNKY BOOBSWEAT)” in my next report but I doubt the reviewers will let it through