One Group.
Six Different Names.
Mandiant, CrowdStrike, Microsoft, and MITRE ATT&CK almost never agree on what to call the same intrusion set. This is the lookup table for the mapping: which vendor name points at which group, and which MITRE Group ID it resolves to, for the actors that show up constantly in reporting. Every row below is checked against current vendor and MITRE sources, not memory, because both the names and the attributions get revised.
Naming Cross-Reference
Fifteen well-documented groups, the name each vendor tracks them under, and the MITRE ATT&CK Group ID that ties the aliases together. A blank cell means that vendor has no confirmed distinct name for the group, not that one was omitted.
| Mandiant Name | CrowdStrike Name | Microsoft Name | MITRE ATT&CK ID | Suspected Origin / Sponsor | Notable Activity |
|---|---|---|---|---|---|
| APT29 | Cozy Bear | Midnight Blizzard | G0016 | Russia — SVR | SolarWinds supply-chain compromise (2020) |
| APT28 | Fancy Bear | Forest Blizzard | G0007 | Russia — GRU (Unit 26165) | 2016 DNC hack-and-leak, NATO credential-phishing campaigns |
| APT41 | Wicked Panda | Brass Typhoon | G0096 | China — MSS-linked, dual-mission | Software supply-chain compromises alongside financially motivated intrusions |
| — (umbrella; Mandiant tracks APT38/TEMP.Hermit as sub-clusters) | Labyrinth Chollima | Diamond Sleet | G0032 | North Korea — RGB | Sony Pictures breach (2014), WannaCry, cryptocurrency-exchange heists — tracked as Lazarus Group / Hidden Cobra (CISA) |
| FIN7 | Carbon Spider | Sangria Tempest | G0046 | Russia — financially motivated | Point-of-sale malware against hospitality/retail, later Clop ransomware deployment |
| UNC3236 | Vanguard Panda | Volt Typhoon | G1017 | China — state-sponsored | Living-off-the-land pre-positioning in US critical infrastructure networks |
| APT44 | Voodoo Bear | Seashell Blizzard | G0034 | Russia — GRU (Unit 74455) | Ukraine power-grid blackouts (2015/2016), NotPetya wiper (2017) |
| UNC3944 | Scattered Spider | Octo Tempest | G1015 | Financially motivated, English-speaking collective | MGM Resorts / Caesars breaches via help-desk social engineering (2023) — aka Muddled Libra (Palo Alto Unit 42) |
| APT1 | Comment Panda | — | G0006 | China — PLA Unit 61398 | Large-scale IP theft; first public PLA-unit attribution (Mandiant's 2013 APT1 report), tracked as Comment Crew |
| APT32 | Ocean Buffalo | Canvas Cyclone | G0050 | Vietnam — suspected state-sponsored | Surveillance of dissidents/journalists, targeting of foreign firms in Vietnam, tracked as OceanLotus |
| — (UNC4210 names one Mandiant sub-campaign, not the Turla umbrella) | Venomous Bear | Secret Blizzard | G0010 | Russia — FSB (Center 16) | Snake/Uroburos implant; hijacks other actors' C2 infrastructure to launder attribution, tracked as Turla |
| APT35 | Charming Kitten | Mint Sandstorm | G0059 | Iran — IRGC-linked | Long-running social-engineering campaigns against journalists, academics, dissidents |
| APT10 | Stone Panda | Purple Typhoon | G0045 | China — MSS (Tianjin State Security Bureau) | Operation Cloud Hopper: MSP supply-chain compromise (2016-2019), tracked as menuPass |
| — | — | — | G0079 | Middle East-focused, no confirmed state sponsor | Open-source tool-based spearphishing against Middle East government/education targets — tracked as DarkHydrus |
| — (FIN12 covers only the ransomware-deployment subset, not a 1:1 match) | Wizard Spider | Periwinkle Tempest | G0102 | Russia — financially motivated | TrickBot/Ryuk development, operated the Conti ransomware-as-a-service brand |
Why The Names Never Quite Line Up
The cross-reference above is a snapshot of public consensus, not a settled standard. Three things worth keeping in mind before quoting any single row.
Every Vendor Tracks Their Own Telemetry
Microsoft's Weather-Themed Naming
Blizzard (Russia), Typhoon (China), Sandstorm (Iran), Sleet (North Korea), Cyclone (Vietnam), Rain (Lebanon), Hail (South Korea), Dust (Turkey), and Tempest for financially motivated actors regardless of origin. Undetermined clusters are provisionally labeled Storm-#### until enough evidence justifies a permanent name. This is why blog posts from before 2023 still say STRONTIUM or NOBELIUM instead of Forest Blizzard or Midnight Blizzard.