If you are a CISO, you may be familiar with the challenge of keeping track of various hacker groups and their respective names. Recently, Google Threat Intelligence Group has joined the effort to simplify this process by introducing a new naming system. This system replaces the previous split naming systems used by Google, which had grown apart over the years.
Background and Motivation
The change was motivated by the need to merge two systems that had been used within Google: Mandiant, a security firm acquired by Google in 2022, and its in-house Threat Analysis Group. The combination of these units resulted in overlapping names for the same hacking groups, leading to confusion and difficulties in tracking threats.
According to Google, the new system aims to make threat tracking more intuitive, rather than an exercise in memorization. Each tracked group will now receive a two-word name, with the first word being a distinct term meant to be easy to recall, often pulled from names already used in past reporting on a specific group.
Structure of the New Naming System
The second word in the name sorts each group by category, such as country of origin or motive. For example, CASTLE pairs with groups tied to China, ION with Iran, NEPTUNE with North Korea, RELIC with Russia, and COMET with financially motivated threat actors not tied to a nation-state. This approach is similar to the one used by CrowdStrike, which pairs a specific term with an animal tied to a country or motive.
Google's system swaps the animals for words like CASTLE and NEPTUNE, but follows the same basic structure. The argument for this approach is that a two-part name carries more information than a bare country label or number and can change as attribution is fine-tuned.
Industry Context and Comparison
Microsoft had previously overhauled its naming system in April 2023, dropping a system built on chemical elements, trees, and volcanoes in favor of weather terms. However, this change was met with criticism from industry experts, who argued that the new names compared threat groups to ice cream flavors or cocktails.
In response to the growing complexity and confusion in threat actor naming, Microsoft and CrowdStrike announced a joint mapping effort in June 2025. This effort aimed to pair Microsoft's weather names with CrowdStrike's animal names for the same tracked groups, with Google, Mandiant, and Palo Alto Networks Unit 42 also contributing to the project.
Implementation and Future Plans
Google's rollout of the new naming system starts with several dozen of the most actively tracked hacking groups, with more to follow over time. Older names will remain searchable within Google's threat intelligence platform, alongside mappings to the MITRE ATT&CK framework and to the naming systems used by other vendors.
The company has also stated that groups will continue to carry the label 'UNC' (for uncategorized) if it is still too early to identify exactly where a group fits in this taxonomy. As the threat landscape continues to evolve, it will be important to monitor the effectiveness of this new naming system and its impact on the industry as a whole.
Source: CyberScoop