Every major cybersecurity report seems to introduce another unfamiliar threat actor with a dramatic name: APT29, Volt Typhoon, Scattered Spider, Sandworm, Lazarus, Mustang Panda, Salt Typhoon, Charming Kitten, or Fancy Bear. To outsiders, the naming conventions can appear confusing or even arbitrary. Why do security companies keep inventing different names for what sometimes appears to be the same hacking group?
According to Google’s leading threat intelligence experts, the answer is both practical and surprisingly simple: the names are not intended to create mystery—they exist because attributing cyberattacks is extraordinarily difficult, and researchers need a structured way to discuss adversaries before they fully understand who they are.
The issue has become increasingly important as cyber espionage, financially motivated cybercrime, and state-sponsored hacking operations continue growing in both sophistication and scale.
Unlike conventional criminal investigations, cyber operations rarely provide immediate certainty regarding the attacker’s identity. Threat intelligence teams typically begin with fragments of evidence: malware samples, infrastructure, phishing domains, command-and-control servers, behavioral patterns, victim profiles, and technical techniques observed during an intrusion.
At the beginning of an investigation, researchers rarely know who is responsible.
Instead, they identify clusters of related activity.
If multiple intrusions use similar malware, infrastructure, tactics, operational habits, or victim selection, analysts begin treating them as the work of the same unknown actor. That cluster receives a temporary codename, allowing researchers to discuss, investigate, and track future activity without prematurely assigning responsibility to a specific country or criminal organization.
In other words, the codename represents observed behavior—not confirmed attribution.
This distinction is fundamental to modern threat intelligence.
Cyber attribution is rarely binary. Analysts often operate across varying degrees of confidence, gradually combining technical evidence, intelligence reporting, geopolitical context, operational history, infrastructure reuse, language artifacts, working hours, malware evolution, and victim targeting to determine whether separate incidents belong to the same campaign.
Codenames provide stability throughout that process.
Without standardized labels, every new investigation would require researchers to repeatedly describe the same collection of indicators using lengthy technical explanations. A short identifier becomes a convenient shorthand for a much larger body of intelligence.
Different security companies, however, often develop those investigations independently.
This explains why a single threat actor frequently acquires multiple names.
Microsoft, Google, CrowdStrike, Palo Alto Networks, Mandiant, Recorded Future, Secureworks, and numerous other intelligence teams each maintain their own internal tracking systems. Researchers may discover the same campaign at different times, observe different aspects of the operation, or classify activity according to their own analytical frameworks before realizing another organization has already documented it.
The result is a fragmented naming landscape.
One vendor may refer to an actor as APT29, another as Midnight Blizzard, while a third uses Cozy Bear. All three names may describe essentially the same Russian intelligence operation, yet each reflects an independent research methodology rather than disagreement about the underlying activity.
Google has deliberately developed its own taxonomy.
Rather than assigning names implying nationality or political affiliation too early, Google’s threat intelligence teams increasingly use neutral designations that classify actors according to observed behavior until sufficient evidence supports broader attribution.
This approach reduces the risk of prematurely connecting technical activity to governments or criminal organizations before investigators possess high-confidence evidence.
The distinction has become increasingly valuable.
Modern cyber operations often involve overlapping infrastructure, shared malware families, leaked offensive tools, rented hosting services, commercial malware, and criminal marketplaces where multiple unrelated actors purchase identical capabilities.
Infrastructure alone rarely proves attribution.
Two independent groups may use the same malware builder.
One nation-state may deliberately imitate another.
Criminal organizations may lease identical command-and-control platforms.
Researchers therefore avoid relying on any single technical indicator when assigning responsibility.
Threat actor naming ultimately serves a broader intelligence function.
Cybersecurity is less concerned with identifying individual hackers than understanding persistent operational groups. Personnel inside an espionage organization may change over time, infrastructure may evolve, malware families may be rewritten, yet the strategic objectives, victim selection, operational discipline, and broader mission often remain consistent.
Tracking the organization rather than the individuals provides greater long-term analytical value.
This mirrors intelligence practices used outside cybersecurity.
Military units, intelligence agencies, organized crime groups, and terrorist organizations are generally monitored as operational entities even though their individual members constantly change.
Cyber threat intelligence follows the same principle.
The increasing complexity of naming also reflects the evolution of cyber operations themselves.
Early hacking groups often consisted of relatively small teams pursuing straightforward objectives such as website defacement or financial theft. Modern threat actors frequently operate as sophisticated organizations employing malware developers, infrastructure specialists, exploit researchers, operational planners, linguists, social engineers, financial coordinators, and intelligence analysts.
Some state-sponsored groups resemble small technology companies in terms of organizational complexity.
Tracking those operations requires structured intelligence methodologies capable of documenting years of evolving activity.
The challenge extends beyond technical investigation.
Governments increasingly rely upon private cybersecurity companies to provide early warning regarding espionage campaigns targeting critical infrastructure, elections, cloud providers, software vendors, telecommunications companies, and defense contractors.
Consistent naming allows intelligence to be shared rapidly across organizations.
Even when vendors use different labels, mapping frameworks increasingly help analysts translate between naming systems so governments, enterprises, and researchers can recognize that separate reports may describe the same adversary.
The proliferation of names has occasionally generated criticism.
Some observers argue that dramatic branding may inadvertently sensationalize cyber threats or complicate public understanding. Security researchers generally acknowledge the confusion but emphasize that the alternative—attempting immediate attribution without sufficient evidence—would be considerably more dangerous.
Precision matters.
Incorrect attribution can influence diplomatic relations, public policy, criminal investigations, sanctions, and international responses. Conservative naming conventions therefore reflect scientific caution rather than marketing.
Ultimately, threat actor names are best understood as organizational labels for evolving intelligence investigations.
They allow researchers to follow campaigns across years of activity while new evidence gradually improves understanding of who is responsible, how they operate, what infrastructure they control, and which organizations they target.
The names themselves are far less important than the intelligence they represent.
Whether an operation is tracked as Salt Typhoon, Volt Typhoon, APT29, Scattered Spider, or another designation, the underlying objective remains the same: helping defenders recognize recurring adversaries before those adversaries strike again.
As cyber operations continue growing in scale and sophistication, standardized threat tracking has become one of the foundations of modern cybersecurity. The codename attached to a hacking group may appear unusual, but behind every label lies years of technical analysis, intelligence collection, and collaborative investigation aimed at answering one of cybersecurity’s most difficult questions—not simply what happened, but who is likely behind it, and what will they do next?