Over the past decade, the cybersecurity industry has developed a practice of assigning codenames to various hacking groups. Some of these names, such as Fancy Bear, have gained recognition beyond industry circles due to their involvement in high-profile cyberattacks. However, the sheer number of these groups and the differing naming conventions used by various organizations have led to confusion, even among professionals.
To address this issue, Google has recently overhauled its system for naming hacking groups. Moving away from the previous numerical designations like APT1 or APT41, Google’s new approach assigns each group a unique, memorable first name, followed by a second word indicating the group’s country of origin. For instance, ‘Castle’ denotes China, ‘Ion’ represents Iran, ‘Neptune’ signifies North Korea, and ‘Relic’ stands for Russia.
Shane Huntley, Chief Technology Officer of Google’s Threat Intelligence Group, explained that this change aims to bring clarity to both internal researchers and the broader cybersecurity community. He noted that in the early 2010s, when companies began publishing reports on cyberattacks and naming the perpetrators, the industry did not anticipate the proliferation of threat groups observed today. Google now monitors over 5,000 distinct ‘activity clusters’ across various nations, reflecting the widespread development of cyber capabilities.
The primary purpose of naming these groups is to establish a baseline understanding of their activities and methodologies. This knowledge enables organizations to recognize threats more swiftly, bolster their defenses, and respond effectively to incidents. By consistently tracking and naming these actors, defenders can better anticipate and mitigate potential attacks.
Huntley emphasized that understanding a hacker group’s behavior, objectives, and affiliations is crucial for effective incident response and threat coverage. For example, familiarity with the tactics of North Korean government-affiliated hackers, such as the Lazarus Group, provides valuable insights for defenders.
While tracking state-sponsored hackers presents challenges, it is generally more straightforward than monitoring cybercriminal organizations or hacker-for-hire groups. State actors tend to have more consistent targets and activities, whereas cybercriminal groups are often more fluid, with members frequently joining or leaving, and their operations evolving over time. Additionally, hacker-for-hire groups and spyware vendors often serve a diverse clientele, complicating efforts to track their activities.
Despite the benefits of a standardized naming system, a common critique is the lack of uniformity across different organizations. Various companies and agencies have developed their own naming conventions, leading to discrepancies and potential confusion. This fragmentation underscores the need for greater collaboration and standardization within the cybersecurity community to enhance collective understanding and response to cyber threats.
In conclusion, Google’s revamped naming system represents a significant step toward improving clarity and consistency in the identification and tracking of hacking groups. By adopting a structured and intuitive approach, Google aims to facilitate better communication and coordination among cybersecurity professionals, ultimately strengthening global defenses against cyber threats.