Skip to content

Threat groups

The Sophos Counter Threat Unit™ (CTU) is responsible for maintaining an understanding of the threat landscape and using that understanding to protect and inform customers. Threat group names track clusters of activity that we assess to be related. Threat groups are intrusion sets or clusters of observed activity. They exist in cyberspace, and we see them attempting to cause harm to our customers or see reports of them causing harm to others.

That's different from threat actors, which are real-world people and organizations with physical locations. Threat groups map to threat actors, but the mapping isn't necessarily one-to-one. A subcontractor might acquire a new contract, groups might share infrastructure, or a foreign intelligence service might operate multiple teams with the same objective but that look and feel very different in their targeting, techniques, and infrastructure.

Understanding threat groups helps us determine which customers might be at risk from which threat actors and identify applicable playbooks. The information can also help a target or victim understand the who, which could lead to the how and the why. Those insights can drive security investment, training, and controls. If the worst happens, they can also drive the focus, speed, and scale of the response.

Understanding threat actors is also important because it might enable a better assessment of the why beyond what we can infer from observed activity. However, it's also harder to do reliably, and it arguably offers less direct security value than focusing on threat groups. Sophos CTU reporting and detections in the platform regularly refer to named threat groups.

To explore detailed information about specific threat groups, including their tactics, techniques, procedures, and associated malware families, see Threat Group.

Threat group naming convention

Every time the CTU identifies a new threat group, they assign a name selected randomly from a list. If the CTU attributes that threat group to a specific country or thematic area, such as financially motivated cyber criminals, they assign a prefix that denotes that attribution. As the understanding of a threat group evolves, the CTU may merge it into another existing group or split it into two or more groups.

As an illustrative example, let's say that analysis of a network intrusion leads Sophos CTU researchers to conclude that the observed set of tools and behaviors can't be associated with any existing threat group. It's therefore a new threat group and is assigned the random name HILLTOP. If Sophos CTU researchers subsequently assess that HILLTOP operates on behalf of the Chinese government, then it's given the prefix BRONZE, used to denote Chinese government-backed threat groups, and becomes BRONZE HILLTOP.

The full list of thematic prefixes assigned to threat groups is as follows:

Origin or theme Metal or alloy
Palestine ALUMINUM
China BRONZE
Iran COBALT
Pakistan COPPER
Cybercrime GOLD
Russia IRON
Lebanon LITHIUM
North Korea NICKEL
United States PLATINUM
Red Team RADIUM
Singapore SILVER
United Kingdom STEEL
Vietnam TIN
South Korea TUNGSTEN
India ZINC

Naming convention history

In November 2016, Sophos CTU researchers began to transition from a numeric threat group identification format, such as TG-1234, to a word-based naming convention. The new names reflect the threat's origin or category and are easier for clients to recognize and remember.

You may occasionally see references to these older threat group names. For example, BRONZE UNION is a prolific Chinese threat group that was previously known as TG-3390. This threat group designation became publicly known through pioneering research by the Sophos CTU, which they've since expanded upon with a series of public and customer-facing reports on BRONZE UNION. Maintaining the relationship between the two can help you understand that it's the same group and only the name changed.

For a list of threat group profiles, see Sophos CTU Threat profiles.