AI News

Google Overhauls Threat Actor Names for Clarity

Quick answer

Google Threat Intelligence Group launches a unified, intuitive naming system for threat actors, replacing cryptic APT numbers with memorable two-word cryptonyms.

Google Threat Intelligence Group (GTIG) is ditching confusing APT numbers for a fresh, intuitive naming system. Think of it as clearing the swamp so defenders can spot the caimans faster.

Why the Change?

Mandiant and Google TAG used separate naming schemes that grew like tangled water weeds. The new unified system uses two-word cryptonyms—memorable and descriptive—so you don’t need a cheat sheet to know who’s who.

How It Works

  • First word: A unique term (often from past reports) or a random, vetted word to identify the actor.
  • Second word: A category label like CASTLE (China), ION (Iran), NEPTUNE (North Korea), RELIC (Russia), or COMET (cybercriminals).

This makes tracking intuitive: “Oh, that’s a RELIC group—Russian state-sponsored.” No more memorizing APT1 vs. APT37.

What’s Staying?

Old names remain searchable in Google Threat Intelligence, with MITRE ATT&CK mappings and vendor aliases preserved. New UNC (uncategorized) tags still apply to emerging clusters. The system is a work in progress, with dozens of active groups renamed first.

For more on Google Cloud’s security tools, check our Google Cloud Review.

Original announcement published on Google Cloud.