H3AD-REF / REFERENCES / THREAT ACTOR NAMING

One Group.
Six Different Names.

Mandiant, CrowdStrike, Microsoft, and MITRE ATT&CK almost never agree on what to call the same intrusion set. This is the lookup table for the mapping: which vendor name points at which group, and which MITRE Group ID it resolves to, for the actors that show up constantly in reporting. Every row below is checked against current vendor and MITRE sources, not memory, because both the names and the attributions get revised.

Naming Cross-Reference

Fifteen well-documented groups, the name each vendor tracks them under, and the MITRE ATT&CK Group ID that ties the aliases together. A blank cell means that vendor has no confirmed distinct name for the group, not that one was omitted.

Mandiant Name CrowdStrike Name Microsoft Name MITRE ATT&CK ID Suspected Origin / Sponsor Notable Activity
APT29 Cozy Bear Midnight Blizzard G0016 Russia — SVR SolarWinds supply-chain compromise (2020)
APT28 Fancy Bear Forest Blizzard G0007 Russia — GRU (Unit 26165) 2016 DNC hack-and-leak, NATO credential-phishing campaigns
APT41 Wicked Panda Brass Typhoon G0096 China — MSS-linked, dual-mission Software supply-chain compromises alongside financially motivated intrusions
— (umbrella; Mandiant tracks APT38/TEMP.Hermit as sub-clusters) Labyrinth Chollima Diamond Sleet G0032 North Korea — RGB Sony Pictures breach (2014), WannaCry, cryptocurrency-exchange heists — tracked as Lazarus Group / Hidden Cobra (CISA)
FIN7 Carbon Spider Sangria Tempest G0046 Russia — financially motivated Point-of-sale malware against hospitality/retail, later Clop ransomware deployment
UNC3236 Vanguard Panda Volt Typhoon G1017 China — state-sponsored Living-off-the-land pre-positioning in US critical infrastructure networks
APT44 Voodoo Bear Seashell Blizzard G0034 Russia — GRU (Unit 74455) Ukraine power-grid blackouts (2015/2016), NotPetya wiper (2017)
UNC3944 Scattered Spider Octo Tempest G1015 Financially motivated, English-speaking collective MGM Resorts / Caesars breaches via help-desk social engineering (2023) — aka Muddled Libra (Palo Alto Unit 42)
APT1 Comment Panda — G0006 China — PLA Unit 61398 Large-scale IP theft; first public PLA-unit attribution (Mandiant's 2013 APT1 report), tracked as Comment Crew
APT32 Ocean Buffalo Canvas Cyclone G0050 Vietnam — suspected state-sponsored Surveillance of dissidents/journalists, targeting of foreign firms in Vietnam, tracked as OceanLotus
— (UNC4210 names one Mandiant sub-campaign, not the Turla umbrella) Venomous Bear Secret Blizzard G0010 Russia — FSB (Center 16) Snake/Uroburos implant; hijacks other actors' C2 infrastructure to launder attribution, tracked as Turla
APT35 Charming Kitten Mint Sandstorm G0059 Iran — IRGC-linked Long-running social-engineering campaigns against journalists, academics, dissidents
APT10 Stone Panda Purple Typhoon G0045 China — MSS (Tianjin State Security Bureau) Operation Cloud Hopper: MSP supply-chain compromise (2016-2019), tracked as menuPass
— — — G0079 Middle East-focused, no confirmed state sponsor Open-source tool-based spearphishing against Middle East government/education targets — tracked as DarkHydrus
— (FIN12 covers only the ransomware-deployment subset, not a 1:1 match) Wizard Spider Periwinkle Tempest G0102 Russia — financially motivated TrickBot/Ryuk development, operated the Conti ransomware-as-a-service brand

Why The Names Never Quite Line Up

The cross-reference above is a snapshot of public consensus, not a settled standard. Three things worth keeping in mind before quoting any single row.

CLUSTERING

Every Vendor Tracks Their Own Telemetry

A shared row name doesn't guarantee a 1:1 match
Mandiant, CrowdStrike, and Microsoft each cluster intrusions from their own visibility: incident-response engagements, endpoint telemetry, and cloud logs respectively. Two vendors "naming the same group" often means their clusters overlap heavily, not that they are identical. Lazarus Group and Wizard Spider (FIN12) in the table above are exactly this case: the popular umbrella name spans several narrower, vendor-specific clusters that don't map cleanly one-to-one.
TAXONOMY

Microsoft's Weather-Themed Naming

Family name = origin or motive, adjective = the specific cluster
Since April 2023, Microsoft names actors with a weather family plus a descriptive adjective. The family encodes attribution or motive: Blizzard (Russia), Typhoon (China), Sandstorm (Iran), Sleet (North Korea), Cyclone (Vietnam), Rain (Lebanon), Hail (South Korea), Dust (Turkey), and Tempest for financially motivated actors regardless of origin. Undetermined clusters are provisionally labeled Storm-#### until enough evidence justifies a permanent name. This is why blog posts from before 2023 still say STRONTIUM or NOBELIUM instead of Forest Blizzard or Midnight Blizzard.
CAUTION

A Snapshot, Not Gospel

Both the naming and the attribution get revised
Vendors periodically split, merge, or rename clusters as evidence changes; Mandiant carving APT44 out of what used to be lumped in with Sandworm reporting is one recent example. Treat this table as a starting point for cross-referencing terminology, not as the final word for a live investigation. When the mapping actually matters, confirm the current name and scope against the original vendor report or the MITRE ATT&CK group page directly.