Google’s Threat Intelligence Group (GTIG) has unveiled a new, standardized naming system for cyber threat actors, aiming to streamline threat identification and enhance communication among cybersecurity professionals. This initiative replaces the previously disparate naming conventions used by Mandiant and Google’s Threat Analysis Group (TAG), which had evolved independently prior to their integration into GTIG.
The updated taxonomy assigns each threat actor a two-word cryptonym. The first word serves as a unique identifier for the group, often retaining terms already associated with the actor in public reports. If no established name exists, a randomly generated term is assigned and reviewed to prevent bias. The second word categorizes the actor based on factors such as motivation, attribution, or activity type. For instance, ‘CASTLE’ denotes groups linked to the People’s Republic of China, ‘ION’ represents those associated with Iran, ‘NEPTUNE’ pertains to North Korea, ‘RELIC’ is used for Russia, and ‘COMET’ signifies cybercriminal activities.
This approach aims to provide immediate context about a threat actor’s origin and intent, facilitating quicker and more informed responses from security teams. By moving away from sequential numbers or disconnected identifiers like ‘APT1’, the new system offers clearer insights into the nature of the threat.
During the transition, GTIG will prioritize renaming several dozen of the most active groups, with plans to expand this system over time. Previous names will remain indexed and searchable within Google’s threat intelligence platform, ensuring continuity and ease of reference. Additionally, MITRE ATT&CK mappings and aliases from other vendors will be preserved to assist analysts in cross-referencing old and new identifiers.
It’s important to note that this naming convention does not replace the need for thorough attribution work. Analysts must continue to assess attacker behavior, infrastructure, and targets before linking a group to a specific nation-state or criminal operation. The new system serves as a navigational aid, providing a common language that simplifies threat communication while accommodating uncertainty and new evidence.
By adopting this unified naming schema, Google aims to reduce confusion and improve collaboration among cybersecurity professionals. This initiative reflects a broader industry trend towards standardization, which is crucial for effective threat intelligence sharing and coordinated defense strategies.