Google’s New Threat Actor Codenames Show Why Cybersecurity Still Can’t Agree on a Name
Google has renamed hundreds of the hacking groups it tracks with a new two-word codename system, and the reasoning behind it reveals why the security industry still cannot settle on one name per...
For more than a decade, cybersecurity vendors have assigned their own private codenames to the hacking groups they track, and for almost as long, those names have rarely matched from one company to the next. Google just added a new entry to that pile. On July 24, Google Threat Intelligence Group (GTIG) began replacing its two legacy naming systems, inherited from Mandiant and Google’s own Threat Analysis Group, with a single scheme built from two-word cryptonyms. A little over two weeks later, GTIG’s chief technology officer walked TechCrunch through the reasoning in an interview that doubles as a case study in why the broader industry still cannot agree on what to call the same attacker.
Table Of Content
Two Systems Become One
Google’s threat intelligence operation is really two older teams stitched together. Mandiant, the incident-response firm Google acquired in 2022, built its reputation partly on popularizing sequential APT numbers, APT1, APT28, APT41, as public shorthand for hacking crews. Separately, Google’s in-house Threat Analysis Group (TAG) tracked its own set of actors under its own conventions. When the two were folded into a single Google Threat Intelligence Group, GTIG inherited two parallel, incompatible lists describing what was often the same threat landscape.
GTIG’s announcement is blunt about why that had to change: sequential identifiers like APT1 don’t hand a defender any usable context on their own, and remembering which number maps to which country or motive is exactly the kind of overhead a security team doesn’t have time for during an incident.
How the New Codenames Work
The replacement is a cryptonym system built from two words. The first word is a unique, memorable label for a specific group, drawn from names already used in public reporting where one exists, or generated at random and vetted by GTIG analysts to remove bias if it doesn’t. The second word is a fixed category suffix that encodes where GTIG believes the group operates from, or what motivates it:
- CASTLE: People’s Republic of China
- ION: Iran
- NEPTUNE: North Korea
- RELIC: Russia
- COMET: financially motivated cybercriminal groups
GTIG says it prioritized renaming several dozen of its most actively tracked groups first and will keep working through the rest on a rolling basis. None of the old identifiers disappear: previous names stay indexed and searchable inside the Google Threat Intelligence platform, cross-referenced against MITRE ATT&CK mappings and the aliases other vendors use for the same actors. Clusters too new to categorize keep the existing UNC, for uncategorized, prefix until GTIG has enough data to assign a full cryptonym.
What Actually Got Renamed
GTIG published a table of initial renamings alongside the announcement. A few examples show how the formula plays out:
- APT41, a Chinese group, becomes SPIRE CASTLE.
- APT28 (also previously tracked as FROZENLAKE), a Russian group, becomes LAKE RELIC.
- APT33, an Iranian group, becomes BLEAK ION.
- FIN7, a financially motivated cybercriminal group, becomes WILD COMET.
- APT44 (also previously tracked as FROZENBARENTS), the Russian military unit widely known in public reporting as Sandworm, becomes SANDWORM RELIC.
The Case Google Makes for Fewer Names
In the TechCrunch interview, Shane Huntley framed the problem as one of scale that caught even Google off guard. “We were not expecting to have as many threat groups as we do today,” he told reporter Lorenzo Franceschi-Bicchierai. John Hultquist, GTIG’s chief analyst, put a number on that scale: Google now tracks more than 5,000 distinct “activity clusters” across multiple countries.
Huntley’s argument is that naming isn’t a branding exercise, it’s operational. A consistent codename gives a security team a place to attach everything already known about an attacker: its usual targets, its tools, what it did the last time it showed up, so that recognizing the name again means recognizing the playbook. “If you actually get hacked by them or you’re dealing with some incident, knowing how that actor behaves, what they do, what they’ve done in the past, all of these details become critically important to help the response and also work out your coverage against these threats as well,” Huntley said.
That logic holds up better for some attackers than others, Huntley added. State-sponsored groups are comparatively easy to track because they tend to keep consistent targets and objectives over time. North Korea’s Lazarus Group is the example he pointed to: years of consistently documented behavior give defenders a starting point the moment the name comes up again. Financially motivated cybercriminal crews are messier, since their membership comes and goes and sometimes splinters, and hacker-for-hire outfits and spyware makers tend to serve customers scattered across multiple countries, which makes any single group harder to pin down long enough to track consistently.
Why the Rest of the Industry Still Speaks a Different Language
Google’s overhaul fixes a Google-specific problem: two internal naming systems becoming one. It does not fix the larger problem TechCrunch’s story opens with, that every major vendor names the same hacking groups differently, and researchers often cannot tell whether two reports describe the same attacker without cross-referencing alias lists by hand.
Pandas, Blizzards, and Now Castles
Google’s cryptonyms join a field where every major vendor already picked its own theme. CrowdStrike pairs a descriptive first word with an animal that signals origin or motive: PANDA for China-linked groups, BEAR for Russia, SPIDER for cybercriminals. Microsoft switched to weather terms in April 2023: Typhoon for China, Blizzard for Russia, Sandstorm for Iran, Tempest for financially motivated actors. The scheme drew plenty of public mockery. CyberScoop reported that some of Microsoft’s combinations struck researchers as sounding more like a dessert menu than a hacking crew, pointing to names such as Strawberry Tempest, Pumpkin Sandstorm, and Pistachio Tempest.
Google is candid about the limits of its own fix. Its announcement acknowledges there are “many threat actor tracking schemas in the industry” already, and says GTIG tried to keep its own system simple in order to “facilitate mapping to other naming taxonomies.” But it also concedes the harder problem underneath: “because no two organizations have the exact same visibility into the threat landscape, direct, apples-to-apples comparisons between threat actors are rarely possible.” Simplifying GTIG’s own convention, the post argues, is “a practical step toward managing a highly intricate tracking problem,” not a claim that the problem is solved.
A Coordination Effort That Didn’t Stick
The industry already tried to solve this once. In June 2025, Microsoft and CrowdStrike announced a joint project to map their respective naming systems to each other’s, with Google, Mandiant, and Palo Alto Networks’ Unit 42 contributing alias data of their own, according to CyberScoop’s reporting at the time. Both companies were careful to frame it as a translation layer between existing systems rather than a push toward one shared standard.
Google’s new taxonomy suggests that effort didn’t carry over. The Register reported that sources familiar with the original 2025 initiative said Google and Mandiant were “keen to adopt the Microsoft-led scheme” when it launched, but that the arrangement “either wasn’t consummated or didn’t last.” Instead of folding its aliases into the existing Microsoft-CrowdStrike map, GTIG built another parallel vocabulary of its own.
The Register’s example of what that costs in practice is the Russian military unit GTIG’s own table now lists as SANDWORM RELIC, previously tracked internally as APT44 and FROZENBARENTS. Widely reported elsewhere simply as Sandworm, the same unit is also Microsoft’s Seashell Blizzard. Counting every name still in active use across vendors, researchers can end up with as many as ten different labels for what is, as far as anyone can tell, a single group. Google renaming its own two internal identifiers to one new one doesn’t reduce that count anywhere outside Google’s own platform. It just adds one more name to a list that was already too long.
What It Means for Security Teams
For a security team that doesn’t run on Google’s threat intelligence platform exclusively, this rename changes less than the announcement suggests. The underlying groups haven’t changed, only GTIG’s label for them, and GTIG says the old identifiers remain searchable rather than retired. The more durable takeaway is the one Huntley stated plainly to TechCrunch: no vendor’s naming scheme is the authoritative one, because “no one has perfect visibility.” Each company builds its taxonomy from its own telemetry, he said, and that gap “can’t be avoided just by sharing more information among companies and groups of researchers.”
That means the cross-referencing work doesn’t go away just because one vendor’s list got tidier. A SOC pulling in reporting from GTIG, Microsoft Defender, and CrowdStrike Falcon still has to maintain its own mapping between codenames, or risk treating one attacker’s activity as three unrelated incidents because three vendors gave it three different names. Community-maintained alias lists, the kind TechCrunch pointed to in its own reporting, remain the practical workaround unless the industry’s naming systems actually converge rather than simply multiply.
Google’s stated goal is to replace memorization with intuition, which is reasonable enough for its own platform. But intuition only works when everyone is reading from the same list, and for now, GTIG’s newly renamed threat actors are fluent in a language only Google speaks.








No Comment! Be the first one.