TRENDING
Rows of identical brass-colored apartment mailboxes with small locks and name labels along an orange corridor wall
October 9, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
Street-level upward view of the Monetary Authority of Singapore building and neighbouring office towers under a pale sky
October 9, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
Cast-iron late Qing dynasty coin minting press with a large flywheel, displayed in a museum case
October 9, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google
Rows of closed oak library card catalog drawers, each with a brass pull and a blank label holder
October 9, 2026
How to Encrypt PII in Python and Keep It Searchable With Blind Indexes
Close-up of a vintage Western Electric manual telephone switchboard with orange lamps, red patch cords plugged into jacks, a rotary dial and a black handset
October 9, 2026
Microsoft’s Agent Lightning v1.0 Turns Agent Training Into a Sample-Accounting Problem
09 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Two orange safety relief valves on grey pressure vessels in an industrial plant
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
Yellow diamond-shaped merging traffic warning sign showing a side road joining a main road
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A lugworm lying on wet sand and mud at low tide
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 232 Posts
News 234 Posts
Learning Hub 204 Posts
Home/Articles/Google’s New Threat Actor Codenames Show Why Cybersecurity Still Can’t Agree on a Name
Articles

Google’s New Threat Actor Codenames Show Why Cybersecurity Still Can’t Agree on a Name

Google has renamed hundreds of the hacking groups it tracks with a new two-word codename system, and the reasoning behind it reveals why the security industry still cannot settle on one name per...

August 8, 2026 6 Min Read
42

For more than a decade, cybersecurity vendors have assigned their own private codenames to the hacking groups they track, and for almost as long, those names have rarely matched from one company to the next. Google just added a new entry to that pile. On July 24, Google Threat Intelligence Group (GTIG) began replacing its two legacy naming systems, inherited from Mandiant and Google’s own Threat Analysis Group, with a single scheme built from two-word cryptonyms. A little over two weeks later, GTIG’s chief technology officer walked TechCrunch through the reasoning in an interview that doubles as a case study in why the broader industry still cannot agree on what to call the same attacker.

Table Of Content

  • Two Systems Become One
  • How the New Codenames Work
  • What Actually Got Renamed
  • The Case Google Makes for Fewer Names
  • Why the Rest of the Industry Still Speaks a Different Language
  • Pandas, Blizzards, and Now Castles
  • A Coordination Effort That Didn’t Stick
  • What It Means for Security Teams

Two Systems Become One

Google’s threat intelligence operation is really two older teams stitched together. Mandiant, the incident-response firm Google acquired in 2022, built its reputation partly on popularizing sequential APT numbers, APT1, APT28, APT41, as public shorthand for hacking crews. Separately, Google’s in-house Threat Analysis Group (TAG) tracked its own set of actors under its own conventions. When the two were folded into a single Google Threat Intelligence Group, GTIG inherited two parallel, incompatible lists describing what was often the same threat landscape.

GTIG’s announcement is blunt about why that had to change: sequential identifiers like APT1 don’t hand a defender any usable context on their own, and remembering which number maps to which country or motive is exactly the kind of overhead a security team doesn’t have time for during an incident.

How the New Codenames Work

The replacement is a cryptonym system built from two words. The first word is a unique, memorable label for a specific group, drawn from names already used in public reporting where one exists, or generated at random and vetted by GTIG analysts to remove bias if it doesn’t. The second word is a fixed category suffix that encodes where GTIG believes the group operates from, or what motivates it:

  • CASTLE: People’s Republic of China
  • ION: Iran
  • NEPTUNE: North Korea
  • RELIC: Russia
  • COMET: financially motivated cybercriminal groups

GTIG says it prioritized renaming several dozen of its most actively tracked groups first and will keep working through the rest on a rolling basis. None of the old identifiers disappear: previous names stay indexed and searchable inside the Google Threat Intelligence platform, cross-referenced against MITRE ATT&CK mappings and the aliases other vendors use for the same actors. Clusters too new to categorize keep the existing UNC, for uncategorized, prefix until GTIG has enough data to assign a full cryptonym.

What Actually Got Renamed

GTIG published a table of initial renamings alongside the announcement. A few examples show how the formula plays out:

  • APT41, a Chinese group, becomes SPIRE CASTLE.
  • APT28 (also previously tracked as FROZENLAKE), a Russian group, becomes LAKE RELIC.
  • APT33, an Iranian group, becomes BLEAK ION.
  • FIN7, a financially motivated cybercriminal group, becomes WILD COMET.
  • APT44 (also previously tracked as FROZENBARENTS), the Russian military unit widely known in public reporting as Sandworm, becomes SANDWORM RELIC.

The Case Google Makes for Fewer Names

In the TechCrunch interview, Shane Huntley framed the problem as one of scale that caught even Google off guard. “We were not expecting to have as many threat groups as we do today,” he told reporter Lorenzo Franceschi-Bicchierai. John Hultquist, GTIG’s chief analyst, put a number on that scale: Google now tracks more than 5,000 distinct “activity clusters” across multiple countries.

Huntley’s argument is that naming isn’t a branding exercise, it’s operational. A consistent codename gives a security team a place to attach everything already known about an attacker: its usual targets, its tools, what it did the last time it showed up, so that recognizing the name again means recognizing the playbook. “If you actually get hacked by them or you’re dealing with some incident, knowing how that actor behaves, what they do, what they’ve done in the past, all of these details become critically important to help the response and also work out your coverage against these threats as well,” Huntley said.

That logic holds up better for some attackers than others, Huntley added. State-sponsored groups are comparatively easy to track because they tend to keep consistent targets and objectives over time. North Korea’s Lazarus Group is the example he pointed to: years of consistently documented behavior give defenders a starting point the moment the name comes up again. Financially motivated cybercriminal crews are messier, since their membership comes and goes and sometimes splinters, and hacker-for-hire outfits and spyware makers tend to serve customers scattered across multiple countries, which makes any single group harder to pin down long enough to track consistently.

Why the Rest of the Industry Still Speaks a Different Language

Google’s overhaul fixes a Google-specific problem: two internal naming systems becoming one. It does not fix the larger problem TechCrunch’s story opens with, that every major vendor names the same hacking groups differently, and researchers often cannot tell whether two reports describe the same attacker without cross-referencing alias lists by hand.

Pandas, Blizzards, and Now Castles

Google’s cryptonyms join a field where every major vendor already picked its own theme. CrowdStrike pairs a descriptive first word with an animal that signals origin or motive: PANDA for China-linked groups, BEAR for Russia, SPIDER for cybercriminals. Microsoft switched to weather terms in April 2023: Typhoon for China, Blizzard for Russia, Sandstorm for Iran, Tempest for financially motivated actors. The scheme drew plenty of public mockery. CyberScoop reported that some of Microsoft’s combinations struck researchers as sounding more like a dessert menu than a hacking crew, pointing to names such as Strawberry Tempest, Pumpkin Sandstorm, and Pistachio Tempest.

Google is candid about the limits of its own fix. Its announcement acknowledges there are “many threat actor tracking schemas in the industry” already, and says GTIG tried to keep its own system simple in order to “facilitate mapping to other naming taxonomies.” But it also concedes the harder problem underneath: “because no two organizations have the exact same visibility into the threat landscape, direct, apples-to-apples comparisons between threat actors are rarely possible.” Simplifying GTIG’s own convention, the post argues, is “a practical step toward managing a highly intricate tracking problem,” not a claim that the problem is solved.

A Coordination Effort That Didn’t Stick

The industry already tried to solve this once. In June 2025, Microsoft and CrowdStrike announced a joint project to map their respective naming systems to each other’s, with Google, Mandiant, and Palo Alto Networks’ Unit 42 contributing alias data of their own, according to CyberScoop’s reporting at the time. Both companies were careful to frame it as a translation layer between existing systems rather than a push toward one shared standard.

Google’s new taxonomy suggests that effort didn’t carry over. The Register reported that sources familiar with the original 2025 initiative said Google and Mandiant were “keen to adopt the Microsoft-led scheme” when it launched, but that the arrangement “either wasn’t consummated or didn’t last.” Instead of folding its aliases into the existing Microsoft-CrowdStrike map, GTIG built another parallel vocabulary of its own.

The Register’s example of what that costs in practice is the Russian military unit GTIG’s own table now lists as SANDWORM RELIC, previously tracked internally as APT44 and FROZENBARENTS. Widely reported elsewhere simply as Sandworm, the same unit is also Microsoft’s Seashell Blizzard. Counting every name still in active use across vendors, researchers can end up with as many as ten different labels for what is, as far as anyone can tell, a single group. Google renaming its own two internal identifiers to one new one doesn’t reduce that count anywhere outside Google’s own platform. It just adds one more name to a list that was already too long.

What It Means for Security Teams

For a security team that doesn’t run on Google’s threat intelligence platform exclusively, this rename changes less than the announcement suggests. The underlying groups haven’t changed, only GTIG’s label for them, and GTIG says the old identifiers remain searchable rather than retired. The more durable takeaway is the one Huntley stated plainly to TechCrunch: no vendor’s naming scheme is the authoritative one, because “no one has perfect visibility.” Each company builds its taxonomy from its own telemetry, he said, and that gap “can’t be avoided just by sharing more information among companies and groups of researchers.”

That means the cross-referencing work doesn’t go away just because one vendor’s list got tidier. A SOC pulling in reporting from GTIG, Microsoft Defender, and CrowdStrike Falcon still has to maintain its own mapping between codenames, or risk treating one attacker’s activity as three unrelated incidents because three vendors gave it three different names. Community-maintained alias lists, the kind TechCrunch pointed to in its own reporting, remain the practical workaround unless the industry’s naming systems actually converge rather than simply multiply.

Google’s stated goal is to replace memorization with intuition, which is reasonable enough for its own platform. But intuition only works when everyone is reading from the same list, and for now, GTIG’s newly renamed threat actors are fluent in a language only Google speaks.

Tags:

CybersecurityGoogleIncident ResponseMandiantThreat Intelligence

Share

Natural gas power plant turbines and cooling infrastructure at the Sand Hill Energy Center in Texas
Previous Post

Amazon’s New Texas Data Center Plant Could Become the Country’s Single Largest Emissions Source

A cluster of physical keys on a keyring, representing the many permission scopes available versus the one a workflow actually needs
Next Post

How to Scope GitHub Actions Permissions to Least Privilege With actionlint

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
08 Oct
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
08 Oct
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
Trending
October 8, 2026
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
October 8, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
October 8, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google

Related Posts

Blue-lit server racks in a modern data center, illustrating the compute infrastructure behind the AI boom.
Articles

The AI Boom Is Spending Real Money Before Proving Real Returns

June 7, 2026
Rows of server racks in a data center representing network infrastructure targeted by botnets
News

C0XMO Botnet Shows Why Old Router Firmware Still Matters

June 7, 2026
Technician working with a laptop beside server racks, representing enterprise AI retrieval infrastructure
Articles

Google’s Agentic RAG Push Makes Enterprise AI Less of a One-Shot Guess

June 7, 2026
Close-up of a USB flash drive, representing physical data-theft risk in office security incidents
News

Fake IT Support Is Now Walking Through the Front Door

June 7, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026