Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

Confused by Threat-Group Names? Microsoft and CrowdStrike Are Building a Translation Layer

By TheFinanceBase Team5 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Microsoft and CrowdStrike have not created a universal threat-actor naming standard. On June 2, 2025, they announced an analyst-led collaboration to map their existing names for the same or overlapping adversary activity. The companies said they had deconflicted more than 80 adversaries, including Microsoft’s Volt Typhoon and CrowdStrike’s VANGUARD PANDA.

The goal is practical: help security teams recognize when different reports may describe related activity without forcing every vendor to abandon its own taxonomy.

Why one threat group can have several names

Threat-intelligence vendors do not see exactly the same attacks. They draw on different customer telemetry, incident investigations, geographic and industry coverage, analytical methods and attribution thresholds. One research team may identify a new activity cluster before it can confidently connect it to a known group; another may later assess that the activity overlaps with an existing actor.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That is why Microsoft may call a group Midnight Blizzard while other researchers use names such as Cozy Bear, APT29 or UNC2452. These labels can describe substantially overlapping activity, but they do not automatically mean that every organization assigns precisely the same scope to each name.

An alias may represent a high-confidence identity match, probable overlap, shared infrastructure or tooling, similar targeting and tradecraft, a broader or narrower cluster definition, or a historical name that remains in circulation after a taxonomy changes.

What Microsoft and CrowdStrike announced

The June 2, 2025 announcement described a shared reference effort, not a merger of the companies’ threat-intelligence products. Analysts from both organizations worked to harmonize names and map corresponding aliases in their respective taxonomies. Microsoft said the initial effort covered more than 80 adversaries.

The companies said the mapping would expand and that other organizations, including Google/Mandiant and Palo Alto Networks’ Unit 42, were identified as potential contributors. Microsoft described the initiative as a starting point and explicitly said it was not intended to create one naming standard for the entire industry.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In other words, this is best understood as a cross-vendor translation layer—a resource that helps an analyst translate one vendor’s label into another vendor’s terminology.

What “deconfliction” means

Deconfliction is the process of determining that labels used by separate research teams refer to the same—or sufficiently overlapping—adversary activity.

It is not necessarily a declaration that every historical campaign under each name was conducted by exactly the same operators. Nor does it prove that attribution to a country or government is certain. Groups change, operators share tools and infrastructure, and criminal ecosystems may involve access brokers, malware developers, affiliates and contractors that do not form one fixed organization.

Identity mapping and attribution should therefore remain separate. A mapping can indicate that two names refer to related activity while the underlying sponsorship, organizational relationship or confidence level remains an assessment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Three examples of the naming problem

Microsoft label CrowdStrike or other aliases How to interpret it
Volt Typhoon VANGUARD PANDA; BRONZE SILHOUETTE The companies presented these as mapped names for a Chinese state-sponsored actor. Microsoft continues to maintain dedicated reporting on Volt Typhoon.
Secret Blizzard VENOMOUS BEAR; Uroburos; Snake; Blue Python; Turla; Wraith; ATG26; Waterbug Microsoft’s current documentation lists these as associated aliases. The list illustrates that an alias reference can extend beyond the two names in a joint announcement.
Midnight Blizzard Cozy Bear; APT29; UNC2452 Microsoft used this as an example of how different researchers can use different labels for overlapping activity. The names may not have identical scope in every source.

These relationships should be read as mappings or assessments, not as permission to erase the original vendor’s wording. The relevant sources are Microsoft’s announcement, CrowdStrike’s release and Microsoft’s maintained alias documentation.

How Microsoft’s weather names work

Microsoft introduced its weather-based taxonomy in 2023. Its broad families include:

  • Typhoon: China-associated nation-state actors
  • Sandstorm: Iran-associated nation-state actors
  • Rain: Lebanon-associated actors
  • Sleet: North Korea-associated actors
  • Blizzard: Russia-associated actors
  • Hail: South Korea-associated actors
  • Dust: Turkey-associated actors
  • Cyclone: Vietnam-associated actors
  • Tempest: financially motivated actors
  • Tsunami: private-sector offensive actors
  • Flood: influence operations
  • Storm: groups still under development

The adjective distinguishes groups that Microsoft considers different based on observed tactics, techniques, procedures, infrastructure, objectives or other patterns. It remains Microsoft’s taxonomy, however—not an industry-wide language. CrowdStrike’s Panda naming system and other vendors’ conventions remain active.

Why the mapping matters to security teams

Unresolved aliases create operational friction. An analyst may fail to connect two reports about the same adversary, a detection engineer may search a threat-intelligence platform using only one vendor’s label, or an incident responder may incorrectly treat two campaigns as unrelated.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The result can be fragmented threat-hunting rules, case-management tags and executive briefings. During an active intrusion, time spent translating names is time not spent validating telemetry, containing accounts or investigating infrastructure.

Better naming alignment can improve correlation and reduce ambiguity. It does not, by itself, stop attacks or create better detections. Prevention still depends on telemetry, identity controls, patching, segmentation, behavior-based detections and response capability.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How defenders should handle aliases

  1. Keep a preferred identifier and all known aliases. For example: Microsoft: Volt Typhoon; aliases: CrowdStrike: VANGUARD PANDA and BRONZE SILHOUETTE.
  2. Record provenance. Store the vendor, publication date, source link and stated confidence for every mapping.
  3. Separate actor, campaign, malware, infrastructure and technique. Shared malware or a common technique is not proof of a shared actor.
  4. Use stable identifiers where available. MITRE ATT&CK group IDs, vendor IDs and internal intelligence-object IDs can supplement names.
  5. Search every known alias. Include aliases when reviewing reports, SIEM records, case notes and detection repositories.
  6. Preserve the original label. Normalize names for searching, but do not overwrite the wording used in the source report.
  7. Do not make automatic correlation decisions from a name alone. Require campaign-specific evidence before merging incidents.
  8. State scope and confidence in executive reporting. “Assessed as likely associated with” is materially different from “confirmed to be.”

A simple internal alias dictionary may be enough for a smaller team. Larger organizations may integrate versioned alias mappings into a threat-intelligence platform or case-management system, provided the changes remain auditable.

What the collaboration cannot solve

  • It is not a universal standard. Microsoft explicitly rejected that description.
  • Participation is voluntary. The mapping becomes more useful as more vendors contribute and maintain compatible information.
  • Attribution remains uncertain. A shared name does not establish government control or precise organizational identity.
  • Groups evolve. Operators can split, merge, retool, imitate others or reuse infrastructure.
  • Vendor scopes differ. One provider may group activity that another separates.
  • Mappings can become stale. New evidence can change an assessment or introduce new aliases.
  • Names can encode assumptions. A country-associated label may reflect an intelligence assessment rather than proven command relationships.

These limitations are why a useful mapping should include source names, scope notes, confidence language, stable identifiers, underlying research links and an update date.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The bottom line

Microsoft and CrowdStrike are reducing a real source of confusion, but they are not replacing the industry’s competing threat-actor taxonomies. Their work gives defenders a way to translate names such as Volt Typhoon and VANGUARD PANDA while preserving the uncertainty that comes with cyber attribution.

For security teams, the practical answer is to normalize aliases for search and correlation—but retain the original label, source, date, scope and confidence. That approach captures the benefit of the collaboration without treating an intelligence assessment as absolute fact.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.