Google revamps hacking group naming system with country-based codenames
Original: Google’s top hacker hunter explains why hacking groups get codenames
Why This Matters
Standardized threat-actor naming directly improves incident response speed and cross-industry threat intelligence sharing.
Google's Threat Intelligence Group has overhauled its hacking group naming system, replacing the old APT-number format inherited from Mandiant with memorable first names paired with country-indicator second words: Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia.
Google has introduced a new naming convention for hacking groups tracked by its Threat Intelligence Group. The previous system, inherited from Mandiant — the security firm now part of Google — used numerical designations such as APT1 and APT41. Under the new scheme, each group receives a memorable random first name and a second word whose initial letter indicates national origin: Castle (China), Ion (Iran), Neptune (North Korea), and Relic (Russia).
Shane Huntley, CTO of Google Threat Intelligence Group, told TechCrunch the overhaul was needed because the old system had become difficult to navigate. 'We were not expecting to have as many threat groups as we do today,' he said. Google now tracks more than 5,000 'activity clusters' across multiple countries, according to chief analyst John Hultquist.
Huntley emphasized the practical value of naming and consistently tracking threat actors: 'If you actually get hacked by them... knowing how that actor behaves, what they do, what they've done in the past, all of these details become critically important to help the response.' He noted that virtually every developed nation now maintains some form of cyber capability.