DMR News

Advancing Digital Conversations

Google Changes How It Names Hacking Groups to Simplify Threat Tracking

ByJolyen

Aug 11, 2026

Google Changes How It Names Hacking Groups to Simplify Threat Tracking

Google has introduced a new naming system for hacking groups as the number of cyber threat actors it tracks continues to grow. The company says the system is intended to make it easier for researchers and organisations to identify groups consistently across Google’s own threat intelligence operations.

The change replaces older naming conventions inherited from Mandiant, including labels such as APT1 and APT41. Google acquired Mandiant in 2022 and has now unified the naming systems previously used by Mandiant and Google’s former Threat Analysis Group.

Under Google’s updated cyber threat actor naming system, each group receives a memorable first word followed by a second word linked to its country of origin. China-linked groups use “Castle,” Iran-linked groups use “Ion,” North Korea-linked groups use “Neptune,” and Russia-linked groups use “Relic.”

Google Now Tracks Thousands of Threat Clusters

Shane Huntley, chief technology officer of Google Threat Intelligence Group, told TechCrunch that researchers did not expect the number of tracked hacking groups to grow as much as it has since companies began publicly naming threat actors in the early 2010s.

Google now tracks more than 5,000 activity clusters across several countries, according to John Hultquist, chief analyst at Google Threat Intelligence Group. Huntley said few developed countries now lack their own cyber capabilities or associated hacking groups.

Naming those groups helps defenders maintain a record of their previous targets, methods and behaviour. That information can help organisations identify attacks more quickly and investigate incidents using what is already known about the suspected group.

For example, the Lazarus Group is associated with North Korea and has been active since at least 2009, according to MITRE ATT&CK. Knowing its previous operations and objectives gives security teams a reference point when investigating similar activity.

Different Companies Still Use Different Names

Google’s change does not solve the wider problem of different cybersecurity companies assigning different names to the same or overlapping groups. MITRE ATT&CK maintains a directory of tracked threat groups that links many of those aliases and notes where organisations may define the same activity differently.

Huntley said a universal naming system remains difficult because every security company sees different evidence based on its own customers, products and telemetry. As a result, researchers can reach different conclusions about whether particular activity belongs to one group or several.

State-sponsored groups are generally easier to track because their targets and objectives tend to remain more consistent. Cybercriminal organisations can change membership, split into smaller groups or reorganise, while hacker-for-hire operations and spyware providers may work for multiple customers across different countries.

Google said its new taxonomy will standardise threat actor tracking across its platforms and public reporting. The consolidation at least removes the need for researchers to keep separate naming systems for Google’s former Threat Analysis Group and Mandiant.


Featured image credits: Wikimedia Commons

For more stories like it, click the +Follow button at the top of this page to follow us.

Jolyen

As a news editor, I bring stories to life through clear, impactful, and authentic writing. I believe every brand has something worth sharing. My job is to make sure it’s heard. With an eye for detail and a heart for storytelling, I shape messages that truly connect.

Leave a Reply

Your email address will not be published. Required fields are marked *