Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Microsoft and CrowdStrike have not created a universal threat-actor naming standard. On June 2, 2025, they announced an analyst-led collaboration to map their existing names for the same or overlapping adversary activity. The companies said they had deconflicted more than 80 adversaries, including Microsoft’s Volt Typhoon and CrowdStrike’s VANGUARD PANDA.
The goal is practical: help security teams recognize when different reports may describe related activity without forcing every vendor to abandon its own taxonomy.
Why one threat group can have several names
Threat-intelligence vendors do not see exactly the same attacks. They draw on different customer telemetry, incident investigations, geographic and industry coverage, analytical methods and attribution thresholds. One research team may identify a new activity cluster before it can confidently connect it to a known group; another may later assess that the activity overlaps with an existing actor.
That is why Microsoft may call a group Midnight Blizzard while other researchers use names such as Cozy Bear, APT29 or UNC2452. These labels can describe substantially overlapping activity, but they do not automatically mean that every organization assigns precisely the same scope to each name.
#1 Best Overall
An alias may represent a high-confidence identity match, probable overlap, shared infrastructure or tooling, similar targeting and tradecraft, a broader or narrower cluster definition, or a historical name that remains in circulation after a taxonomy changes.
What Microsoft and CrowdStrike announced
The June 2, 2025 announcement described a shared reference effort, not a merger of the companies’ threat-intelligence products. Analysts from both organizations worked to harmonize names and map corresponding aliases in their respective taxonomies. Microsoft said the initial effort covered more than 80 adversaries.
The companies said the mapping would expand and that other organizations, including Google/Mandiant and Palo Alto Networks’ Unit 42, were identified as potential contributors. Microsoft described the initiative as a starting point and explicitly said it was not intended to create one naming standard for the entire industry.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteIn other words, this is best understood as a cross-vendor translation layer—a resource that helps an analyst translate one vendor’s label into another vendor’s terminology.
What “deconfliction” means
Deconfliction is the process of determining that labels used by separate research teams refer to the same—or sufficiently overlapping—adversary activity.
It is not necessarily a declaration that every historical campaign under each name was conducted by exactly the same operators. Nor does it prove that attribution to a country or government is certain. Groups change, operators share tools and infrastructure, and criminal ecosystems may involve access brokers, malware developers, affiliates and contractors that do not form one fixed organization.
Rank #3
Identity mapping and attribution should therefore remain separate. A mapping can indicate that two names refer to related activity while the underlying sponsorship, organizational relationship or confidence level remains an assessment.
Recommended Free Tools
Three examples of the naming problem
| Microsoft label | CrowdStrike or other aliases | How to interpret it |
|---|---|---|
| Volt Typhoon | VANGUARD PANDA; BRONZE SILHOUETTE | The companies presented these as mapped names for a Chinese state-sponsored actor. Microsoft continues to maintain dedicated reporting on Volt Typhoon. |
| Secret Blizzard | VENOMOUS BEAR; Uroburos; Snake; Blue Python; Turla; Wraith; ATG26; Waterbug | Microsoft’s current documentation lists these as associated aliases. The list illustrates that an alias reference can extend beyond the two names in a joint announcement. |
| Midnight Blizzard | Cozy Bear; APT29; UNC2452 | Microsoft used this as an example of how different researchers can use different labels for overlapping activity. The names may not have identical scope in every source. |
These relationships should be read as mappings or assessments, not as permission to erase the original vendor’s wording. The relevant sources are Microsoft’s announcement, CrowdStrike’s release and Microsoft’s maintained alias documentation.
How Microsoft’s weather names work
Microsoft introduced its weather-based taxonomy in 2023. Its broad families include:
Rank #4
- Typhoon: China-associated nation-state actors
- Sandstorm: Iran-associated nation-state actors
- Rain: Lebanon-associated actors
- Sleet: North Korea-associated actors
- Blizzard: Russia-associated actors
- Hail: South Korea-associated actors
- Dust: Turkey-associated actors
- Cyclone: Vietnam-associated actors
- Tempest: financially motivated actors
- Tsunami: private-sector offensive actors
- Flood: influence operations
- Storm: groups still under development
The adjective distinguishes groups that Microsoft considers different based on observed tactics, techniques, procedures, infrastructure, objectives or other patterns. It remains Microsoft’s taxonomy, however—not an industry-wide language. CrowdStrike’s Panda naming system and other vendors’ conventions remain active.
Why the mapping matters to security teams
Unresolved aliases create operational friction. An analyst may fail to connect two reports about the same adversary, a detection engineer may search a threat-intelligence platform using only one vendor’s label, or an incident responder may incorrectly treat two campaigns as unrelated.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →The result can be fragmented threat-hunting rules, case-management tags and executive briefings. During an active intrusion, time spent translating names is time not spent validating telemetry, containing accounts or investigating infrastructure.
Best Value
Better naming alignment can improve correlation and reduce ambiguity. It does not, by itself, stop attacks or create better detections. Prevention still depends on telemetry, identity controls, patching, segmentation, behavior-based detections and response capability.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How defenders should handle aliases
- Keep a preferred identifier and all known aliases. For example:
Microsoft: Volt Typhoon; aliases:CrowdStrike: VANGUARD PANDAandBRONZE SILHOUETTE. - Record provenance. Store the vendor, publication date, source link and stated confidence for every mapping.
- Separate actor, campaign, malware, infrastructure and technique. Shared malware or a common technique is not proof of a shared actor.
- Use stable identifiers where available. MITRE ATT&CK group IDs, vendor IDs and internal intelligence-object IDs can supplement names.
- Search every known alias. Include aliases when reviewing reports, SIEM records, case notes and detection repositories.
- Preserve the original label. Normalize names for searching, but do not overwrite the wording used in the source report.
- Do not make automatic correlation decisions from a name alone. Require campaign-specific evidence before merging incidents.
- State scope and confidence in executive reporting. “Assessed as likely associated with” is materially different from “confirmed to be.”
A simple internal alias dictionary may be enough for a smaller team. Larger organizations may integrate versioned alias mappings into a threat-intelligence platform or case-management system, provided the changes remain auditable.
What the collaboration cannot solve
- It is not a universal standard. Microsoft explicitly rejected that description.
- Participation is voluntary. The mapping becomes more useful as more vendors contribute and maintain compatible information.
- Attribution remains uncertain. A shared name does not establish government control or precise organizational identity.
- Groups evolve. Operators can split, merge, retool, imitate others or reuse infrastructure.
- Vendor scopes differ. One provider may group activity that another separates.
- Mappings can become stale. New evidence can change an assessment or introduce new aliases.
- Names can encode assumptions. A country-associated label may reflect an intelligence assessment rather than proven command relationships.
These limitations are why a useful mapping should include source names, scope notes, confidence language, stable identifiers, underlying research links and an update date.
The bottom line
Microsoft and CrowdStrike are reducing a real source of confusion, but they are not replacing the industry’s competing threat-actor taxonomies. Their work gives defenders a way to translate names such as Volt Typhoon and VANGUARD PANDA while preserving the uncertainty that comes with cyber attribution.
For security teams, the practical answer is to normalize aliases for search and correlation—but retain the original label, source, date, scope and confidence. That approach captures the benefit of the collaboration without treating an intelligence assessment as absolute fact.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

