
Google has introduced a new naming system for hacking groups as the number of cyber threat actors it tracks continues to grow. The company says the system is intended to make it easier for researchers and organisations to identify groups consistently across Google’s own threat intelligence operations.
The change replaces older naming conventions inherited from Mandiant, including labels such as APT1 and APT41. Google acquired Mandiant in 2022 and has now unified the naming systems previously used by Mandiant and Google’s former Threat Analysis Group.
Under Google’s updated cyber threat actor naming system, each group receives a memorable first word followed by a second word linked to its country of origin. China-linked groups use “Castle,” Iran-linked groups use “Ion,” North Korea-linked groups use “Neptune,” and Russia-linked groups use “Relic.”
Google Now Tracks Thousands of Threat Clusters
Shane Huntley, chief technology officer of Google Threat Intelligence Group, told TechCrunch that researchers did not expect the number of tracked hacking groups to grow as much as it has since companies began publicly naming threat actors in the early 2010s.
Google now tracks more than 5,000 activity clusters across several countries, according to John Hultquist, chief analyst at Google Threat Intelligence Group. Huntley said few developed countries now lack their own cyber capabilities or associated hacking groups.
Naming those groups helps defenders maintain a record of their previous targets, methods and behaviour. That information can help organisations identify attacks more quickly and investigate incidents using what is already known about the suspected group.
For example, the Lazarus Group is associated with North Korea and has been active since at least 2009, according to MITRE ATT&CK. Knowing its previous operations and objectives gives security teams a reference point when investigating similar activity.
Different Companies Still Use Different Names
Google’s change does not solve the wider problem of different cybersecurity companies assigning different names to the same or overlapping groups. MITRE ATT&CK maintains a directory of tracked threat groups that links many of those aliases and notes where organisations may define the same activity differently.
Huntley said a universal naming system remains difficult because every security company sees different evidence based on its own customers, products and telemetry. As a result, researchers can reach different conclusions about whether particular activity belongs to one group or several.
State-sponsored groups are generally easier to track because their targets and objectives tend to remain more consistent. Cybercriminal organisations can change membership, split into smaller groups or reorganise, while hacker-for-hire operations and spyware providers may work for multiple customers across different countries.
Google said its new taxonomy will standardise threat actor tracking across its platforms and public reporting. The consolidation at least removes the need for researchers to keep separate naming systems for Google’s former Threat Analysis Group and Mandiant.
Featured image credits: Wikimedia Commons
For more stories like it, click the +Follow button at the top of this page to follow us.
