惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
IT之家
IT之家
博客园 - Franky
Stack Overflow Blog
Stack Overflow Blog
宝玉的分享
宝玉的分享
Recent Announcements
Recent Announcements
Engineering at Meta
Engineering at Meta
S
SegmentFault 最新的问题
V
Visual Studio Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Last Week in AI
Last Week in AI
H
Help Net Security
V
V2EX
H
Hackread – Cybersecurity News, Data Breaches, AI and More
量子位
博客园 - 叶小钗
J
Java Code Geeks
博客园 - 【当耐特】
月光博客
月光博客
爱范儿
爱范儿
人人都是产品经理
人人都是产品经理
酷 壳 – CoolShell
酷 壳 – CoolShell
小众软件
小众软件

Check Point Blog

Reading the Signals in the OWASP LLM Top 10 2026 - Check Point Blog Ransomware Didn't Slow Down in Q2 2026. It Just Spread Out. - Check Point Blog July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure Widens - Check Point Blog State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit - Check Point Blog Lazarus Hackers Exploit Windows Zero-Day in Fake Job Scam Native AI Security Comes to Claude: Why Anthropic's Inference Hooks Matter - Check Point Blog Claude AI Security: How Anthropic Inference Hooks Enable Real-Time Protection The Top Exposure Management Questions Security Leaders Ask (Part 1) - Check Point Blog Black Hat 2026: Check Point Research Takes the Stage - Check Point Blog Check Point Joins the Open Secure AI Alliance to Advance Open, Measurable and Enterprise-Ready AI Security - Check Point Blog Three AI security disclosures, fourteen days: what the warnings signs are telling us - Check Point Blog When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context - Check Point Blog Your VLAN Isn’t an Air Gap: Six Hard Truths From the New CI Fortify Guidance - Check Point Blog Check Point Named a Visionary Leader in the 2026 Frost Radar™ for Enterprise Risk Mitigation and Management Platforms - Check Point Blog AI Escaped a Sandbox. That is Not What Should Worry You - Check Point Blog Introducing the Industry's First AI Network Firewall - Check Point Blog Attackers Are Turning Microsoft's Trusted Login System Into Their Latest Phishing Weapon - Check Point Blog AI Agent Security Just Had Its Catalyst Moment - Check Point Blog Your AI Governance Policy Should Survive Your Next Model Change - Check Point Blog Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report - Check Point Blog Security Advisory - Action Required - July 2026 Security Update - Check Point Blog What the 2026 Exposure Gap Report Reveals About Remediation - Check Point Blog Inline Email Security and Microsoft 365: A Practical View of Mail Routing, Risk, and Prevention - Check Point Blog The State of Hybrid SASE: Built-In vs. Bolted-On - Check Point Blog AI Appreciation Day: Let's Be Honest About What We're Appreciating - Check Point Blog AI Security Is Never Finished: Building the Continuous Red Teaming Loop  - Check Point Blog AI Security Threats in 2026: Annual Insights from Check Point Research - Check Point Blog AI Agents are Only As Effective as Their Harness - Check Point Blog Email Agent Hijacking: The Hidden Threat That Breaks Post-Delivery Security - Check Point Blog How Check Point Email Security Stopped a Student Job Scam Before It Reached the Inbox - Check Point Blog Redefining the CISO Contract: From Securing the Business to Securely Doing Business - Check Point Blog A New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide
The Branding and Attribution Behind Cybercrime - Check Po...
Shmuel Gihon, Security Research Manager, Exposure Management · 2026-07-27 · via Check Point Blog

Threat actor names can sound simple. LockBit. Fancy Bear. BlackCat. Scattered Spider. Anonymous Sudan. Each name gives the impression of a clear group with a defined identity. 

In threat intelligence, however, the name is rarely the whole story. 

Some names are chosen by attackers. Others are assigned by researchers, security vendors, governments, or public databases. One name may represent a ransomware brand, a hacktivist identity, a research label, a campaign, a malware family, or an activity cluster observed across different incidents. 

For security professionals, this distinction is important. Confusing attacker created identities with researcher assigned labels can lead teams to overestimate certainty, miss relationships between aliases, or focus on the name instead of the behavior behind it. 

Who Gets to Name a Threat Actor? 

Threat actor naming usually starts with either visibility or investigation. 

When a group wants attention, it may introduce itself publicly through a leak site, Telegram channel, ransom note, cybercrime forum, or public claim of responsibility. This is common among ransomware groups and hacktivist collectives because recognition can support their goals. The name becomes part of how they communicate, recruit, intimidate, or claim credit. 

Researcher assigned names start from a different place. Analysts may see repeated malicious activity across victims, environments, tools, infrastructure, or techniques and need a way to track it. The label helps connect incidents, compare findings, and communicate risk to defenders. . MITRE ATT&CK describes groups as activity clusters tracked by a common name in the security community, and notes that different organizations may use different names for similar activity. 

In other words, attacker chosen names are often public identities. Researcher assigned names are often analytical shortcuts for tracking behavior. 

When the Name Becomes the Brand 

For ransomware groups, a name can carry business value. It can make the group recognizable to victims, affiliates, journalists, and other criminals. A short, memorable name can help a group build credibility in a crowded criminal economy. 

Reputation also supports the pressure campaign. If victims believe a group has leaked data before, disrupted large organizations, or followed through on threats, the name can increase fear during negotiations. The brand becomes part of the extortion strategy. 

Hacktivist groups use names in a different way. Their names often point to a cause, region, ideology, or target. The goal is not only technical disruption, but public visibility. A name helps frame the attack as a political or social statement and gives supporters, media, and targets a clear identity to follow. 

This is why attacker chosen names should be read as messaging, not just identification. The name tells defenders how the group wants to be seen, but the behavior behind the name is what shows how the group operates. 

Researcher Assigned Names and Activity Clusters 

Researcher assigned names follow a different logic. Analysts use names to turn scattered evidence into something defenders can track, compare, and discuss. 

A group name may be based on repeated infrastructure, shared tools, malware families, command and control patterns, IOCs (indicators of compromise), targeting, victimology, or TTPs (tactics, techniques, and procedures). The name gives analysts a way to connect new observations to older activity and communicate those findings to defenders. 

This does not always mean researchers know the real people behind the activity. In many cases, the name describes a cluster of behavior rather than a confirmed organization. 

Different vendors also use different naming systems. One company may group activity by suspected origin. Another may use themes such as animals, weather, or other internal classifications. The result is a threat intelligence landscape where names help organize activity, while aliases and overlapping labels can create confusion. 

APT29 shows how quickly naming can become complicated. A single activity cluster can collect labels from vendors, public reporting, incident response investigations, and threat intelligence databases. Some names refer to the broader actor. Others refer to related campaigns, malware, or activity later connected to the same cluster. 

Explore how Check Point Exposure Management helps security teams identify exposed assets, exploitable weaknesses, and attack paths before attackers can use them. 

Why One Group Can Have Many Names 

A single threat actor can appear under several names because different teams see different parts of the same picture. One vendor may observe phishing infrastructure. Another may analyze malware samples. Another may investigate incident response data. Public databases then attempt to map these aliases so defenders can understand when different names may refer to related activity. 

Rebrands add another layer. Ransomware groups may change names after law enforcement attention, sanctions, leaks, internal conflict, or damage to their reputation. The new name can create distance from the old brand while allowing the group to continue using familiar tools, partners, or tactics. 

Ransomware analysis often includes profiling a group’s ideology, leadership, technologies, TTPs, infrastructure, tool quality, and relationships with other groups. Cross checking code samples can also help analysts assess whether overlap points to a rebrand, an offshoot, or leaked code reused by several groups. 

Rebrand, Offshoot, or Reused Code? 

Shared code does not automatically prove that two groups are the same. Malware can be sold, leaked, reused, modified, or shared through affiliate programs. The same applies to infrastructure, ransom note templates, negotiation styles, and tooling. 

Analysts need context. If a new group uses code linked to an older ransomware operation, researchers may compare timing, infrastructure, victim patterns, affiliates, language, behavior, and public claims. A leaked builder used by several unrelated actors tells a different story than a private toolset carried from one brand to another. 

This is where naming becomes careful judgment. The goal is to avoid treating every overlap as proof while still recognizing when a new name is connected to older activity. 

From Threat Actor Name to Action 

Threat actor names help security teams organize intelligence, follow campaigns, understand targeting, and communicate risk. The name gives defenders a starting point, while the real value comes from the evidence behind it. 

Security Professionals need to look past the label and examine the behaviors, tools, vulnerabilities, exposed systems, identities, infrastructure, and attack paths associated with that actor or cluster. A ransomware brand, hacktivist identity, or researcher assigned name becomes useful when it helps security teams understand how the activity could affect their environment. 

Exposure management brings threat intelligence into focus. It helps security professionals move from a name to the assets, weaknesses, identities, and paths that could create risk in their own environment. Threat actor names help explain who may be behind the activity. Exposure management shows whether that activity can reach the organization, where it could move next, which fixes should come first, and how to apply those fixes safely. 

Schedule a demo to see how Check Point Exposure Management turns threat intelligence into prioritized action.