Why APT Group Names Include Animals (Bear, Panda, etc.)

Chad Warner
2 min readDec 30, 2021

--

Have you heard names like Fancy Bear, Cozy Bear, and Vixen Panda and wondered why animals are part of some APT (advanced persistent threat) group names?

Photo by mana5280 on Unsplash

Different organizations have different ways of naming APT groups. Some (such as CrowdStrike) use animals that are associated with the nations that the APT groups are associated with. Here are a few:

  • Bear: Russia
  • Panda: China (CrowdStrike)
  • Dragon: China (non-CrowdStrike)
  • Kitten: Iran
  • Chollima (mythical horse): DPRK (North Korea)
  • Spider: ecrime (not region-specific or state-sponsored)
  • Jackal: hactivist (not region-specific or state-sponsored)
  • Buffalo: Vietnam
  • Crane: Republic of Korea
  • Leopard: Pakistan
  • Tiger: India (CrowdStrike) or China (non-CrowdStrike)
  • Lynx: Georgia
  • Wolf: Turkey
  • Ocelot: Colombia
  • Hawk: Syria

Additional Resources

--

--

Chad Warner
Chad Warner

Written by Chad Warner

Web Strategist at OptimWise. Cybersecurity & privacy enthusiast. Bookworm. Fan of Tolkien & LEGO.

No responses yet