Google Rolls Out Two-Word Naming System for Threat Actors

Google two-word threat actor naming system encoding suspected origin and motivation into memorable aliases for tracked hacker groups

Google is introducing a unified naming system for the hacker groups its specialists track. Instead of labels like APT1 and a jumble of unrelated identifiers, attackers will now receive memorable two-word aliases. The transition began on 24 July, and it will gradually reach Google Threat Intelligence Group data, public reports, and the Google Threat Intelligence platform.

Why the Change Was Needed

The overhaul followed a merger of analytical capabilities. Mandiant and the Threat Analysis Group had joined forces, yet each team previously tracked attacks on its own and used different naming rules. After the creation of Google Threat Intelligence Group, those parallel systems began to hinder the matching of information. Google explained the shift in its updated naming-system announcement.

How the New Names Work

Each new name consists of two English words. The first serves as a unique name for a specific group. Where possible, Google will keep recognisable labels that already appear in public research. If no suitable option exists, a word is chosen at random and then checked by analysts, so the name carries no unwanted associations or biased judgement.

The second word signals origin, motivation, or activity type at a glance. As a result, an analyst no longer has to remember which country or category each numeric identifier belongs to. The name itself carries part of the information needed for a first assessment of the threat.

The Origin Suffixes

The second word maps to a suspected source or motive. China-linked groups receive the suffix CASTLE. Suspected Iranian operations take ION, North Korean ones NEPTUNE, and Russian ones RELIC. Financially motivated cybercriminals, regardless of country, are marked with COMET.

The logic is easy to read. For instance, two different groups that Google ties to Russia will get different first words but the same ending, RELIC. That lets an analyst spot the suspected origin instantly, without opening a separate reference or consulting an alias table.

No Single Industry Standard Yet

Other companies already use similar systems, yet no unified industry reference exists. The same activity may carry different names at Google, Microsoft, CrowdStrike, Palo Alto Networks, and elsewhere. Moreover, different researchers may merge several operations into one group or, conversely, split them into separate clusters.

The cause is not merely terminology. Each company has its own telemetry sources, clients, and available data sets. Some specialists see malicious files and network infrastructure, while others hold the results of investigations inside breached organisations. Therefore, two vendors’ labels do not always describe exactly the same set of actors and operations.

Google stresses that the new system should ease work with this mass of data, but it will not erase differences between vendors’ classifications. Within the Google Threat Intelligence platform, it will keep the old names, other vendors’ aliases, and mappings to the MITRE ATT&CK base. Users will be able to search for a group by either the new or the old label.

A Gradual Transition

First, the company will rename a few dozen of the most active groups. The remaining labels will update gradually, as accumulated information is verified. This approach avoids swapping hundreds of familiar identifiers at once, and it gives specialists time to adapt internal reports, detection rules, and incident-management systems.

Labels with the UNC prefix will remain for now. Mandiant uses it for as-yet-unclassified activity clusters at an early investigative stage. Such a number does not necessarily correspond to a stable hacker organisation. It may describe a limited campaign, a set of related tools, or activity for which data is still insufficient.

Later, if analysts establish the origin, goals, and stable characteristics of such a cluster, it can receive a permanent name under the new scheme. Until then, the old label lets teams track the activity without drawing premature conclusions about the identity or state affiliation of those behind it.

Clearer Threat Reporting, but Not Final Attribution

Abandoning sequential numbers alone should make threat reports clearer, not only for analysts but also for the staff responsible for incident response. From the end of a name, they can immediately see whether an adversary is tied to a particular state or acts for financial gain.

However, the new aliases should not be taken as final proof of attribution. A link to a state or criminal milieu rests on a combination of technical and intelligence indicators, and it may be refined as new data appears. The name reflects Google’s current assessment, not an officially established identity for every participant in an attack.

Above all, the unified scheme removes the internal divergence between Mandiant and the former Threat Analysis Group. Now Google’s reports, investigations, and platform data will rest on one classification, while the retained aliases help match new names to APT, FIN, UNC, and other vendors’ labels.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply