IFIN Adversary Naming Convention

I think we should consider a naming convention for threat actors we discuss in IFIN.

Some ideas:

  • Pokemon: “I had a really exhausting day negotiating with the Caterpie ransomware operators today”
  • Favorite Linux distros: “These dang Fedora operatives won’t stop saying m’lady!”
  • Wingdings: “I got got by ❄︎♏︎♋︎❍︎🏱︎👍︎🏱︎ today”

What do y’all think?

I’ve said before I’m pretty allergic to creating yet another naming convention. Plus, we can’t improve on perfection.

In all seriousness though, tagging with common TA names is important and useful.

Okay this is my new favorite and official TA naming schema

I’m skeptical about creating new naming conventions. I don’t even think every organization that publishes 1st party intel should have their own convention.
For readers to understand the context properly, you end up having to list a bunch of aliases anyway :person_shrugging:

My approach is usually to use an existing name unless that name doesn’t match how you cluster the activity. This is something I spend too much time thinking about and I’m on a mission to convince people to take more care when it comes to attribution and naming :sweat_smile:
For example, the attribution around Salt Typhoon and friends was a mess, so we kept using FamousSparrow and explained the links and non-links in the article instead of using the most popular name.

I’ll try to write “FamousSparrow (aka FUNKY BOOBSWEAT)” in my next report but I doubt the reviewers will let it through :smile:

I should be clear - I am totally joking about this post and agree with most of ya’ll about your aversion to adversary names.