Best Tech & Security Platform
Followed by 1000+

GEANTECHNOLOGY

IT & Tech News, tutorials on system, networking, and cybersecurity.

Google Just Overhauled How Threat Actors Are Named — Here’s What Changed

Jul 29, 2026 ahmed mokdad 4 min read

If you’ve spent any time in the SOC trenches, you know the pain: one vendor calls a threat group “APT41,” another calls the same crew “Winnti,” a third has some internal codename nobody outside their building has ever heard of. Cross-referencing a single intrusion set across five different reports can feel like translating a language that keeps changing its own alphabet.

That’s the mess Google’s Threat Intelligence Group (GTIG) is trying to clean up with a freshly unified naming system for the actors it tracks.

The Backstory: Two Teams, Two Dictionaries

Before GTIG existed as a single unit, Mandiant and Google’s Threat Analysis Group (TAG) each ran their own tracking operations — built up over years, with their own internal logic and their own growing lists of identifiers. That made sense when the teams were separate. Once they merged, though, it left behind two parallel naming systems that didn’t talk to each other cleanly. Combining the intel meant combining the vocabulary too.

Rather than just bolting one system onto the other, GTIG used the merger as a reason to rethink naming from scratch.

Ditching the Alphanumeric Soup

The old standby — sequential codes like “APT1,” “APT28,” and so on — has a real weakness: it’s practically unmemorable. Analysts end up keeping a personal cheat-sheet just to remember which number maps to which behavior. GTIG’s argument is that defenders shouldn’t have to memorize a spreadsheet in the middle of an incident; recognition should be instant, almost reflexive.

Their fix is a cryptonym system built from two words:

  • Word one is a distinctive, sticky label for the specific actor — often pulled straight from names the security community has already been using informally, so institutional memory isn’t thrown out. When there’s no existing nickname to borrow, GTIG generates one at random and has analysts review it, which keeps the naming process free of unconscious bias.
  • Word two signals the category the group falls into — where they’re based, who they work for, or what kind of activity they run — chosen based on whatever context matters most for how defenders should actually respond.

Here’s a taste of how the categorization word maps to origin or motive:

Origin / TypeCategory Word
China-linked (nation-state)CASTLE
Iran-linkedION
North Korea-linkedNEPTUNE
Russia-linkedRELIC
Financially motivated crimeCOMET

So a name doesn’t just identify who — it hints at why, at a glance.

It Won’t Solve Everything, and That’s Fine

GTIG is upfront that this doesn’t magically create industry-wide consistency. Every vendor sees a different slice of the threat landscape depending on their telemetry, their customer base, and their sensors — so a clean, one-to-one match between “our threat actor” and “their threat actor” is still often impossible, no matter how tidy the naming looks on paper. What this system does promise is something more modest but genuinely useful: a naming convention that’s easier to remember, easier to reason about, and easier to map against other vendors’ taxonomies when you need to cross-reference.

Rolling Out, Not Flipping a Switch

This isn’t a day-one, rip-the-band-aid-off change. GTIG is starting with a few dozen of the most actively tracked groups and expanding from there over time. Crucially, nothing old gets thrown away — legacy names stay fully searchable inside the Google Threat Intelligence platform, complete with their MITRE ATT&CK mappings and cross-vendor aliases, so historical reports and existing detection rules don’t suddenly go stale.

Why This Matters for Your Team

If your org leans on threat intel feeds, expect to see these new two-word cryptonyms start showing up alongside — not instead of — the identifiers you already know. Worth updating your internal wikis and playbooks proactively rather than getting caught flat-footed when “RELIC” shows up in a report and nobody on shift knows it’s the same actor they’ve been tracking under an old alias for years.

Naming conventions rarely make headlines, but they quietly shape how fast a team can pattern-match during an active incident — and that’s exactly the kind of unglamorous infrastructure work worth paying attention to.

Leave a Reply

Your email address will not be published. Required fields are marked *