Threat Picture
Latest Cybersecurity News

Dmitri Alperovitch: Naming Hackers, Building CrowdStrike

Operation Aurora and the DNC intrusion made attribution central to his career. Leaving CrowdStrike took that work into foreign policy.
By Charles Joseph · Updated
Share
Share
Copy URL

In January 2010 a McAfee researcher told the world that Google had been hit by something new, and gave it a name: Operation Aurora. In 2016 the same man announced that Russian intelligence was inside the Democratic National Committee.

Dmitri Alperovitch has spent a career naming the enemy. He discovered and christened Shady RAT, co-founded CrowdStrike and turned "attribution" from a dirty word into the industry's business model.

Then, at the top, he walked away from a company about to be worth billions to start a think tank. The Moscow-born kid who arrived in Tennessee at 15 had decided the next fight wasn't about malware at all.

Dmitri Alperovitch at a Glance

  • Alperovitch was born in Moscow in 1980, the son of a nuclear physicist. His father won a visa to Canada in 1994, and a year later the family settled in Chattanooga, Tennessee.
  • He studied computer science at Georgia Tech, worked at an anti-spam company and, as a teenager, built an encryption business with his father.
  • As McAfee's vice president of threat research he named Operation Aurora in January 2010 and, in 2011, unveiled Operation Shady RAT, a five-year espionage campaign he'd traced since 2009.
  • In September 2011 he co-founded CrowdStrike with George Kurtz and became its chief technology officer.
  • On June 14, 2016, he published the CrowdStrike analysis that put two Russian intelligence groups, Cozy Bear and Fancy Bear, inside the DNC's network.
  • He left CrowdStrike in February 2020 to co-found Silverado Policy Accelerator, a nonpartisan nonprofit, and became a founding member of the government's Cyber Safety Review Board in 2022.
  • His 2024 book World on the Brink, written with Garrett M. Graff, argues that the United States and China are already in a second Cold War with Taiwan as the flashpoint.
  • In 2026 he was still on television and in print arguing about chips, AI and China, and still hosting his podcast, Geopolitics Decanted.
Sponsored

The Life of Dmitri Alperovitch

Alperovitch's Soviet Childhood

Dmitri Alperovitch was born in Moscow in 1980, in what he's described as an era when people were afraid to discuss politics inside their own homes. His father, Michael, was a nuclear physicist who narrowly avoided being sent to Chernobyl on a rescue mission.

In 1994 Michael was granted a visa to Canada, and a year later the family moved to Chattanooga, Tennessee, where he took a job at the Tennessee Valley Authority. The work was dull enough that he began studying cryptography on the side.

Father and son started an encryption-technology business while Dmitri was still in high school. He went on to study computer science at Georgia Tech, then joined an anti-spam software firm.

"A lot of people who are born here don't appreciate the freedoms we have, the opportunities we have, because they've never had it any other way," he told Esquire in 2016. "I have."

Naming Aurora

By 2010 Alperovitch was vice president of threat research at McAfee, and in January of that year Google disclosed it'd been hacked from China. McAfee's researchers were brought in by victim companies, and Alperovitch became the public face of the analysis.

The attackers had targeted at least 34 companies with nearly a dozen pieces of malware and several layers of encryption. "We have never ever, outside of the defense industry, seen commercial industrial companies come under that level of sophisticated attack," he told Wired. "It's totally changing the threat model."

McAfee called it Operation Aurora, after a folder name the compiler had left inside the malware. The name stuck, and so did the habit: from then on, Alperovitch's campaigns would have names.

Sponsored

Shady RAT

The next one had been building for years. In early 2009 a McAfee client, a US defense contractor, found suspicious programs on its network, and Alperovitch picked up a trail that led back to a single command-and-control server.

When he went public in August 2011, Operation Shady RAT turned out to be a five-year campaign against dozens of governments, companies and organizations, including Olympic committees. Alperovitch believed it was state-sponsored, and said the data loss amounted to "an unprecedented transfer of wealth in the form of trade secrets and I.P."

Some victims didn't want to hear it. "Victims don't want to know they're victims," he told Vanity Fair. "I guess that's just victim psychology: if you don't know about it, it's not really happening."

Building CrowdStrike

In September 2011 Alperovitch co-founded CrowdStrike with George Kurtz, McAfee's former chief technology officer, and took the CTO job himself. The company's premise came straight from his McAfee years.

Playing defense with technology alone wasn't enough, he argued. "Otherwise the adversary will scale up and it becomes a game of numbers, which they will win." The answer was to identify who was attacking, name them, and raise their costs.

CrowdStrike gave its adversaries animal code names by country: bears for Russia, pandas for China. It was marketing, but it was also a worldview, and Alperovitch was its author.

Bears in the Midst

On June 14, 2016, Alperovitch published a post titled "Bears in the Midst." CrowdStrike had been called into the Democratic National Committee and found two separate Russian intelligence operations living on the same network.

Cozy Bear had been inside since the summer of 2015, Fancy Bear since April 2016, and neither appeared to know about the other. Cozy Bear's "tradecraft is superb, operational security second to none," he wrote, with the odd admiration of a man who'd been chasing them for a decade.

Within weeks the stolen emails were public. Within months Esquire was calling Alperovitch "Putin's worst nightmare," and the word attribution had moved from security conferences to cable news.

Sponsored

Walking Away

In February 2020, eight months after CrowdStrike's stock market debut, Alperovitch announced he was leaving. Michael Sentonas took over as CTO, and Alperovitch said he wanted to apply the same ingenuity to policy that he'd applied to the industry.

The vehicle was Silverado Policy Accelerator, a nonpartisan nonprofit he co-founded with Maureen Hinman, where he's chairman. In February 2022 the Department of Homeland Security named him a founding member of the Cyber Safety Review Board, alongside Rob Joyce of the NSA and Google's Heather Adkins.

He'd also become a geopolitical forecaster with a podcast, Geopolitics Decanted, and a following. In the run-up to February 2022 he was explaining on air why Vladimir Putin planned to invade Ukraine, and in Foreign Affairs that March he wrote about the dangers of Putin's paranoia.

World on the Brink

In April 2024 PublicAffairs published World on the Brink: How America Can Beat China in the Race for the Twenty-First Century, which Alperovitch wrote with Garrett M. Graff. Its argument is blunt: the United States and China are already in Cold War II, and Taiwan is where it could turn hot.

The book became a national bestseller and put him on the opinion pages of Time and The Washington Post. By 2026 he was arguing that the US shouldn't sell advanced chips to China, comparing it to "selling rockets to the Soviet Union to win the space race."

On AI, he's calmer than many in his old field. "I'm not worried about the HAL 9000 from Space Odyssey taking over the world," he told PBS in October 2026; he worries about the humans running the attacks.

Dmitri Alperovitch: The Man Who Named the Bears

Alperovitch's great idea was simple and, at the time, heretical: you can't defend a network without knowing who's attacking it, and you should say their name out loud.

Aurora, Shady RAT, Cozy Bear and Fancy Bear are all household names in security because he made them so, and the company he co-founded turned that philosophy into one of the industry's biggest businesses.

Now he applies the same instinct to countries instead of hacking crews. The names have changed. The habit hasn't.

QUOTE:

"Amateurs hack systems, professionals hack people."