Why APT Group Names Include Animals (Bear, Panda, etc.)
2 min readDec 30, 2021
Have you heard names like Fancy Bear, Cozy Bear, and Vixen Panda and wondered why animals are part of some APT (advanced persistent threat) group names?
Different organizations have different ways of naming APT groups. Some (such as CrowdStrike) use animals that are associated with the nations that the APT groups are associated with. Here are a few:
- Bear: Russia
- Panda: China (CrowdStrike)
- Dragon: China (non-CrowdStrike)
- Kitten: Iran
- Chollima (mythical horse): DPRK (North Korea)
- Spider: ecrime (not region-specific or state-sponsored)
- Jackal: hactivist (not region-specific or state-sponsored)
- Buffalo: Vietnam
- Crane: Republic of Korea
- Leopard: Pakistan
- Tiger: India (CrowdStrike) or China (non-CrowdStrike)
- Lynx: Georgia
- Wolf: Turkey
- Ocelot: Colombia
- Hawk: Syria