LAS VEGAS — When faced with malicious acts, there’s a natural tendency to focus on the perpetrators and their motives. However, for organizations dealing with cyberattacks, this focus may be counterproductive.
According to Andy Piazza, senior director of threat intelligence at Palo Alto Networks Unit 42, obsessing over the identities and methods of threat actors can distract from more crucial strategic measures. In an interview at Black Hat, Piazza emphasized that defenders should prioritize enhancing their ability to detect and respond to cyber threats rather than getting bogged down by the specifics of threat groups.
The allure of names like Scattered Spider, Midnight Blizzard, and Fancy Bear often overshadows the practicalities of cybersecurity. Piazza pointed out that such mythologizing can weaken the effectiveness of defensive strategies. Cybersecurity vendors and threat intelligence teams have diverse approaches to naming threat groups—some use numerical designations, while others, like Microsoft and CrowdStrike, opt for more evocative names.
Jen Easterly, director of the Cybersecurity and Infrastructure Security Agency, criticized the tendency to dramatize cybercriminals. During her keynote at Black Hat, she lamented how these adversaries are often depicted as formidable and almost mythical figures. Instead of names like “scrawny nuisance” or “feeble ferret,” attackers are portrayed with grandiose titles, which can inflate their perceived capabilities.
Threat groups are dynamic and their structures often change. For instance, Unit 42 tracked 53 active ransomware groups in the first half of 2024, with a few groups responsible for a significant portion of attacks. Despite some groups developing new exploits, many rely on known vulnerabilities, and their methods tend to be repetitive.
CrowdStrike’s approach to personifying threat groups through large-scale statues at conferences, such as Wizard Spider at RSA and Scattered Spider at Black Hat, aims to symbolize their mission to combat cyber threats. However, this portrayal is meant to highlight their adversarial intent rather than glamorize the attackers themselves.
Ultimately, experts advise focusing on practical risk reduction strategies like vulnerability management, network security, and multifactor authentication, rather than delving into the identities of attackers. Piazza noted that while incident responders and law enforcement can concern themselves with the specifics of threat actors, defenders should concentrate on implementing effective security measures.
Disclosure: Both Black Hat and Cybersecurity Dive are part of Informa, but Black Hat does not influence Cybersecurity Dive’s reporting.



