Google Threat Intelligence Group recently overhauled its global cyber-threat naming system in a bid to simplify how security researchers track and defend against more than 5,000 active hacking clusters worldwide.
Deciphering the Chaos of Cyber-Threat Names
For over a decade, the cybersecurity sector has assigned distinct codenames to various hacking collectives. Whilst some groups, such as Fancy Bear, have entered mainstream public awareness due to high-profile breaches, many others remain obscure, known only to specialised analysts.
Even industry veterans struggle to keep pace with the sheer volume of designations. This confusion stems from the fact that different security firms employ their own proprietary naming conventions. To mitigate this, industry professionals, policymakers, and journalists frequently rely on central repositories, such as this database, to cross-reference and identify threat actors.
Inside Google’s New Naming Formula
To streamline this fragmented landscape, Google recently launched a revamped naming system for threat actors. This update marks a significant departure from legacy frameworks.
The tech giant is phasing out alphanumeric codes like APT1 or APT41—a system originally pioneered by Mandiant, the cybersecurity firm acquired by Google. In its place, Google has introduced a more intuitive, two-word classification structure:
- First Name: A random, memorable word.
- Second Name: A specific geographic indicator representing the state of origin.
Under this new methodology, Chinese threat groups are designated as “Castle”, Iranian actors as “Ion”, North Korean groups as “Neptune”, and Russian collectives as “Relic”.
Why Naming Hackers is Critical for Global Defence
According to Shane Huntley, Chief Technology Officer of Google Threat Intelligence Group, the transition was essential to establish clarity for both internal and external security researchers. When firms began publishing cyber-threat intelligence in the early 2010s, analysts did not anticipate the exponential growth of state-sponsored and criminal groups operating today.
The scale of the threat is immense. Google now actively tracks over 5,000 distinct “activity clusters” globally. John Hultquist, Chief Analyst at Google Threat Intelligence Group, notes that almost every developed nation now possesses offensive cyber capabilities.
Tracking and naming these groups serves a highly practical purpose. By establishing a consistent baseline of threat intelligence, organisations can rapidly identify incoming attacks, prepare defences, and accelerate incident response times.
Understanding the historical behaviour and tactical patterns of specific actors—such as North Korea’s notorious Lazarus Group—provides defenders with a critical head start when mitigating active intrusions.
State-Sponsored Actors vs Cybercriminals
While monitoring state-sponsored threat actors is highly complex, Huntley points out that they are often easier to track than financial cybercriminals. Government-backed hackers typically operate under structured mandates with consistent objectives. In contrast, cybercriminal syndicates and hackers-for-hire are highly fluid; their members constantly disperse, reform, and target diverse victims globally, making telemetry collection far more difficult.
The Challenge of a Universal Naming Standard
A frequent question within the cybersecurity community is why all defensive firms do not simply adopt a single, universal naming standard. However, Huntley explains that this is practically impossible because every security firm has a unique perspective of the threat landscape, shaped by its own proprietary data and network telemetry.
Because no single entity possesses total visibility over the entire internet, different organisations will inevitably construct varying models of the same threat groups. By merging the naming systems of Google’s Threat Analysis Group (TAG) and Mandiant, the company has at least reduced the number of competing taxonomies. For those seeking to map the wider landscape, researchers can still refer to this gargantuan list of threat actors.
