The names of the threat actors may seem simple: LockBit, Fancy Bear, BlackCat, etc. Each name gives the impression of a clearly identified group with a defined identity.
In the field of threat intelligence, the names of threat actors rarely tell their whole story. Some names are chosen by the attackers. Others are assigned by researchers, security vendors, governments or public databases. The same name can refer to a ransomware brand, a hacktivist identity, a search label, a campaign, a malware family or a cluster of activity observed across different incidents.
For security professionals, this distinction is important. Confusing identities created by attackers with labels assigned by researchers can cause teams to overestimate their certainty, miss connections between different aliases, or focus on the name rather than the behavior it denotes.
Who has the power to name a threat actor?
Assigning a name to a threat actor generally stems either from a desire for visibility or from an investigative approach.
When a group seeks attention, it may present itself publicly through a data leak site, a Telegram channel, a ransom note, a cybercriminal forum, or a public claim. This is common among ransomware groups and hacktivist collectives because notoriety serves their goals. The name then becomes a tool of communication, recruitment, intimidation or demands.
The names assigned by researchers come from a different logic. Analysts may observe recurring malicious activity across different victims, environments, tools, infrastructure, or techniques, and need a way to track it. The label allows incidents to be linked together, observations to be compared, and the risk to be communicated to defense teams. The MITER ATT&CK framework describes groups as clusters of activity tracked under a common name within the security communityand notes that different organizations may use different names to refer to similar activity.
In other words, the names chosen by attackers often correspond to public identities. The names assigned by researchers are more analytical shortcuts intended to track behavior.
When the name becomes a brand
For ransomware groups, a name can have real commercial value. It allows the group to be recognized by its victims, affiliates, journalists and other cybercriminals. A short, memorable name can help a group build credibility in a highly competitive criminal economy.
Reputation also strengthens the pressure campaign. If victims believe a group has already leaked data, disrupted large organizations, or followed through on threats, the name can increase fear during negotiations. The brand then becomes an integral part of the extortion strategy.
Hacktivist groups use names differently. Their names often refer to a cause, a region, an ideology or a target. The goal is not just technical disruption, but also public visibility. A name helps present the attack as a political or social statement, and gives supporters, media, and targets a clear identity to follow.
This is why the names chosen by attackers must be understood as a message, and not just as an identification. The name tells defense teams how the group wants to be perceived, but it is the behavior behind the name that truly reveals its modus operandi.
Names assigned by researchers and activity clusters
The names assigned by researchers follow a different logic. Analysts use it to turn scattered clues into pieces that defense teams can track, compare and discuss.
A group’s name can be based on recurring infrastructure, shared tools, malware families, command and control schemes, IOCs (indicators of compromise), particular targeting, victimology or TTPs (tactics, techniques and procedures). The name allows analysts to connect new observations to previous activity and communicate those findings to defense teams.
This does not mean, however, that researchers know the real identities of the people involved. In many cases, the name denotes a set of behaviors rather than a confirmed organization.
Different publishers also use different naming systems. One company may group activity by presumed origin, while another may use themes such as animals, weather, or other internal classifications. The result is a threat intelligence landscape where names help organize activity, while generating confusion through aliases and overlapping labels.
APT29 shows how naming can quickly become complex. A single activity cluster can accumulate labels from publishers, public reports, incident response investigations, and threat intelligence databases. Some names refer to the actor in the broad sense, others to campaigns, malware or related activities subsequently attached to the same cluster.