When we get a new virus/worm/trojan sample we need to name it. If we recognize that the new sample is just the next one in a family, that is a modification of a virus we already know, we just add a new letter to the existing name. If the program is named wrongly (a company or a virus expert can explain why it is wrong) the name is changed by voting in AV experts email lists. In every case there is a specific reason for choosing the name for a malicious program. For example, Skybag has this name because its a mix of NetSky and Bagle worms.”]
Source: https://securelist.com/more-on-malware-classification/29879/