Google overhauls hacker-group naming to simplify tracking and attribution
Google has replaced its old alphanumeric hacker-group labels with a new system that pairs a random first name with a country-specific suffix.
Google has introduced a streamlined naming scheme for hacking collectives, discarding the long-used APT numbers that originated with Mandiant. Under the new model, a group’s label consists of a random first name followed by a second term whose initial denotes its presumed country, for example Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia. Shane Huntley, chief technology officer of the Google Threat Intelligence Group, explained that the overhaul was needed to bring clarity as the number of identified threat groups has exploded.
Google now tracks more than 5,000 activity clusters across multiple nations, according to analyst John Hultquist. By standardising names, the firm hopes security teams can more readily identify attacker behavior, improve incident response, and share intelligence. Huntley noted that while state-backed groups are easier to follow than fluid cyber-criminal outfits, no organization has complete visibility into all operations. The new system reduces one layer of complexity, leaving other naming lists for reference.
Why it matters
A clear naming system helps organizations identify and defend against cyber threats more efficiently.
In this story